Shared Info: was Re: anyone know what powers "google public DNS?"
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Actually, I've been kicking around some ideas, related to spam, abuse, and other DNS, DNSBL issues. I think what we lack is automated coordination protocols. Google and Opendns milk information from DNS queries to produce marketing data. I just discovered that DNS-based blacklists have been doing the same. ISPs have enough information to run their own internal spam and abuse filters, and most do. Small companies and others don't. That's why they turn to DNSBLs and such. The anti-dote would seem to be to not use services that mine and market information. Of course, that might not be so easy. Its like asking the little company to not use _any_ DNSBLs. I have a lot of experience asking the occasional person not to use SORBS---that's hard enough, and made easier by the hundred plus other DNSBL's, some of which are more honest than others. It would probably be unreasonable to recommend against using _any_ DNSBLs unless there is an alternative. As I said, this is very easy for an ISP to run its own blacklist, but very hard for a small company. In short, DNSBLs are bad because accountability is a bitch, they are often spamming to sell their blacklist services, and they are using the incoming queries to determine who their users are talking to. So how do we share such information in a way that it can't be exploited? I guess the model that springs to mind is similar to nntp, where abuse IP information is posted with a signature of the poster, whose trustworthiness can be accounted. Feeds are hierachical, so thousands aren't downloading millions of bytes of data each day from a central site. Perhaps a similar (read: same) system could be used to distribute popular queries which we can all use to keep a primed cache. By cooperating, we can obtain the same benefits as google does, without giving information unfairly to only one party. NNTP-like hierachical message flooding enables every to get a full copy without anyone having to pay too heavy a b/w cost. DDos is also mitigated by spreading the system instead of a central site. Everyone will have a copy of the most popular queries, the current IPs sending abuse, etc. --Dean On Tue, 26 Jan 2010, Joe Baptista wrote: > You may be off topic for the conference Richard but your concerns are > shared. > > regards > joe baptista > > On Tue, Jan 26, 2010 at 3:27 PM, richard lucassen <[email protected] > > wrote: > > > On Tue, 26 Jan 2010 14:13:33 -0500 > > Mike Sands <[email protected]> wrote: > > > > > My understanding is that it is a custom application written by google > > > staff. > > > > Of course. Google creates your profile by collecting data through what > > you search. But collecting valuable dns info about what else you're > > doing on the internet can make your profile even more accurate and thus > > more valuable. > > > > Microsoft: "We Own Your Computer!" > > Google: "We Own Your Data!" > > > > Another year and "1984" is 25 years old and mature. > > > > This post probably adds another little piece of valuable information on > > who I am, what I do and what I'm thinking. > > > > Sorry for being OT. > > > > R. > > > > -- > > ___________________________________________________________________ > > It is better to remain silent and be thought a fool, than to speak > > aloud and remove all doubt. > > > > +------------------------------------------------------------------+ > > | Richard Lucassen, Utrecht | > > | Public key and email address: | > > | http://www.lucassen.org/mail-pubkey.html | > > +------------------------------------------------------------------+ > > > > > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494