Would the root DNS servers ever get modified or censored as a result of court action?
My thoughts were that DNS-level censorship is essentially a dead end because the root servers are sacrosanct, and there will always be secondary DNS servers to query, who then use the root servers.
Sucks for DNS providers in authoritarian countries though.
I suspect the US would push back on this unless they were the ones doing the censoring. So far the US has not opened that door with DNS; it’s important to make sure that the door stays closed, as this would create chaos and major fragmentation.
In the meantime it might be worthwhile to develop alternatives, like some kind of DNS-over-Tor or DNS-over-DHT scheme, along with normalizing Tor onion services as an alternative access method for clearnet sites.
Yes, some kind of alternative DNS system where domain assignment is authenticated using some kind of distributed system of ownership consensus! If only such a thing has existed for years already and was well tested and performant...
All the things that crypto true believers believed would happen are slowly coming to pass. It wasn't all bored apes and gambling. There was some legitimate developing going on, and still is.
After the Samourai case, you shouldn’t be so confident in cryptocurrency-based solutions for things like this. If devs can somehow stay anonymous and out of reach, maybe.
I’m not ideologically against cryptocurrency-based solutions, but it isn’t a magic bullet by any means. I still think that the EU in particular isn’t done making life difficult for crypto users.
Not to discourage projects like ENS, I think it’s good to have alternatives, but I do think we need noncommercial fallbacks to the current system as well. Anything involving money will always have choke points.
In what way do you think ENS can be compromised if devs are not 'out of reach'? You're comparing a permissioned mixing service whose authors made it centralized on purpose to extract fees with a decentralized DNS system. There is nobody in charge. There are no master keys. There is no means by which a government can shut it down, short of shutting down the ethereum network itself, which I think they would find to be easier said than done.
This is the problem with crypto discourse - people view the guy selling snake oil on the sidewalk outside the gas station on the same level as legitimate infrastructure project that is the combined work product of hundreds of people who aren't trying to scam anyone, just make useful stuff.
The only solution to this is being willing to learn about the technology, which is a very unpopular view on HN.
Fair enough, but I’m not convinced that a significant number of DAO members, contributors, and token holders couldn’t be identified and pressured into making changes. Such a push may not be successful, as ENS is widely distributed, but that doesn’t mean that the EU wouldn’t try if ENS usage became more common. Even if unsuccessful, this attack could have a chilling effect on uptake in the place where it is most likely to be needed.
Additionally, the EU could block purchase of ENS from exchanges. This added friction, though minor, is enough to slow uptake. I look at Monero as an example. It is functional and stable and it does what it claims. Yet hardly anyone uses it, because it has been effectively fenced off through a series of very low hurdles. It is not hard to swap to Monero for privacy, so why don’t more people do it?
IMHO ordinary users are much more likely to install a resolver that doesn’t have any connection to cryptocurrency. (The media campaign against crypto has been very effective.)
I do think crypto people ought to keep trying to develop their tools: there is some utility in it, and it may be more useful as things evolve. But it’s not a panacea, and the fact that it is “digital money” makes operators legally more vulnerable to attacks and regulation under current laws and legal precedents. Distributed, digital-only, non-monetary, volunteer-run networks like Tor are legally very resilient for now, at least in the West. (That could change, but it hasn’t yet.)
No. While root servers are NOT sacrosanct, if such a court action were to occur and a root server operator were to carry it out, the change would fail DNSSEC validation in resolvers that have DNSSEC enabled (which varies depending on where you are, see https://stats.labs.apnic.net/dnssec), resulting in a SERVFAIL. In such cases, resolvers generally try another root server, until it gets a non-SERVFAIL answer, so for this to have the desired effect, you'd have to get all the root servers to implement the same change. This would be unlikely.
However, the root server operators merely publish what ICANN (via the IANA functions) produces.
If the US (either federal or perhaps even the states of California or Virginia) were to decide to "censor" a TLD in the root zone, they would simply go to ICANN, PTI (the folks who provide the IANA functions under contract to ICANN) or, more likely, Verisign (who generate and publish the root zone under contract to ICANN) and demand the root zone be modified.
As a sibling comment mentioned, the root servers are unlikely to get such order since they deal with registries and not what I would call end user domain names.
Registries do get block orders. When the Swedish registry got that for piratebay they choose to treat it like a domain dispute and gave ownership of the domain to the police, which the police in turn could treat like any other taken property and auction it out. The trouble is when the police wanted to destroy it, as there isn't a good definition on how to destroy a name so it can never be used again, and the registry was not keen on allowing the concept of a block.
You can choose not to delegate it, but then how long and who should maintain the list of names that should not be delegated? Who should pay for the work to implement it, and who should pay for the maintenance for said system, and for how long? Should there be an appeal process or some kind of oversight, and who should body those roles?
In theory the law makers could specify this in law as form of registry regulation, but no one want to do that just to address one or two court cases where this question comes up. The registrar of last resort doesn't give any direct answer to those questions either.
These cases come up far more frequently than "one or two court cases" -- many takedowns of botnet/malware (e.g., Avalanche) end up in ROLR. See "domain generation algorithms".
In general, the vast majority of registries are fine with marking particular domains as "allocated but not delegated" as long as they get paid. ISTR ICANN waiving their fees, so the costs of marking a domain as undelegatable essentially turn in lost opportunity cost, which most registries are willing to eat.
The number of times a domain ownership get turned over to the police are not that common. For malware it is much more common to just remove the registration than to keep it registered for all eternity. There are a few different procedures used for malicious registrations (got to be careful with cnc), but the absolute most common seems to be to just put the domain on hold and then remove the registration after a short period. 99.9% (likely a few more 9s) are handled like that voluntarily by the registry and also by some registrars, which mean it does not involve the courts. The number of cases where it does goes the full length to court, a guilty verdict is reached, and the ownership of a malicious domain is decided to be given over to the police are very few.
The root DNS servers basically only tell you where the registry servers are, they don't contain records themselves. If someone censored a domain at the registry level then the root servers would be no help
This is true but I can imagine where they might go after the lowest reachable branch of the tree, up to threatening to remove country-level TLDs from the root servers for noncompliance. Only the US really has the leverage to do this, and it would just fragment the internet, as additional root servers would pop up to serve the missing TLDs. So it’s unlikely but possible.
"Additional root servers" popping up that would server missing TLDs would fail DNSSEC validation unless you modified the root hints and turned off DNSSEC or resigned the root zone and updated the trust anchors in validating resolvers.
Ever since the Verisign coup in 2003, the world has had the idea of "delegation-only" and suchlike filtering on responses from superdomain servers. More recently, query minimization was invented. Both of these can militate against the root content DNS servers doing that.
Better still, one can run one's own private root content DNS server. I've been doing that (in several ways) for a couple of decades. If ICANN decided to blackhole (say) www.microsoft.com. tomorrow, my DNS lookups wouldn't be affected.
To affect them, the aforementioned "court action" would have to target Verisign.
I'm curious: how did you implement your "private root content" DNS server such that it keeps up with (valid -- and how would you know?) updates made by the TLD registries via IANA?
My thoughts were that DNS-level censorship is essentially a dead end because the root servers are sacrosanct, and there will always be secondary DNS servers to query, who then use the root servers.
Sucks for DNS providers in authoritarian countries though.