grandkaiser

joined 1 year ago
[–] grandkaiser 11 points 1 year ago

Most decent ad blockers already don't load ads

[–] grandkaiser 2 points 1 year ago

11 years. Had to use an extension to manually block Reddit to stop myself from automatically going to Reddit for the first two months.

[–] grandkaiser -1 points 1 year ago* (last edited 1 year ago)

Except In this specific case, it's about measurements for tools. Fractional is far more practical for construction than decimal for tooling.

[–] grandkaiser 7 points 1 year ago (2 children)

Except WTF is the next size up or down from 15/64??!!!

There's lots of great reasons to switch to metric. Inability to do basic fractions isn't one of them...

For the record, it would be 16/64, or, 1/4

[–] grandkaiser 4 points 1 year ago

Is that not what the title says? Like, i'm new to Lemmy so maybe i'm confused? Didn't OP write "He got no money from it :(" in the title?

[–] grandkaiser 13 points 1 year ago

If you decide to use Akamai, hmu. I'm not an Alamai guru, but I do it professionally.

[–] grandkaiser 2 points 1 year ago

They don't know unless the DNS server tells them. For example, a very popular webhost Akamai uses a complex DNS + web hosting suite (DNS edgesuit to be exact) to send that type of data to the web servers. It can also allow for many many other features.

[–] grandkaiser 2 points 1 year ago

Well, it's not just a money issue. There's also the "are you knowledgeable, responsible, and have DNS engineers on staff" problem. If you own your own TLD, it means you can talk directly to the root zone. You could theoretically DDOS the root zone servers and cause them to crash. They would, of course, just revoke your TLD permanently & it wouldn't really cause any noticeable disruption to the rest of the internet. You could also allow attack domains or shady websites. Maybe it could be used to pretend to be another site. Imagine owning ".conn" that would be a premium attack site TLD because it looks like "com". There's lots of other issues too.

[–] grandkaiser 3 points 1 year ago* (last edited 1 year ago)

If you initiate a zone transfer, you can now claim to be authoritative for a zone. That means you can be a 'bad actor' DNS server that serves fake records. In practice, this means that you can redirect people to an attack site.

Let's say you're Joe the Random Internet User and you want to go to lemmy.world This is what happens in a non-attack (we're skipping caching & non-authoritative answers for brevity):

  1. You type "lemmy.world" into your browser
  2. Your computer initiates a stub resolution for lemmy.world. (the trailing dot here isn't a period. It's the "true" FQDN)
  3. Computer looks at hosts file and doesn't see anything
  4. DNS packets are sent to your configured DNS server. If you don't have one configured, DHCP already configured it for you
  5. Your DNS server performs a recursive search for world by asking the root zone where the "world" Name Serer is
  6. root zone resolves world as:

world. 3600 IN NS v0n0.nic.world.

world. 3600 IN NS v0n1.nic.world.

world. 3600 IN NS v0n2.nic.world.

world. 3600 IN NS v0n3.nic.world.

world. 3600 IN NS v2n0.nic.world.

world. 3600 IN NS v2n1.nic.world.

  1. Your DNS server reaches out to one of those Name Server's (That's what the NS record is for) and asks it where "lemmy" is
  2. world Name Server responds with:

lemmy.world. 300 IN A 172.67.218.212

lemmy.world. 300 IN A 104.21.53.208

  1. Your DNS server contacts your computer and serves it those IP addresses. (A record's are domain name to IP Address)

Now lets say there's a DNS spoof attack:

  1. Before the "world" server can get back to your DNS server, the hackers server interjects with it's own authoritative claim that lemmy is here:

lemmy.world. 300 IN A [attack site IP]

  1. Your DNS server contacts your computer and serves it that IP address. Your computer then contacts the attack site and you get a virus.
[–] grandkaiser 3 points 1 year ago

Companies don't/can't sell TLD's. Only IANA can decide those. When the internet first started, .org, .net, .com etc. were handed out to non-profit organizations and the costs were purely to keep the servers running. Eventually though, when IANA decided to hand out country codes like .io (Indian Ocean), .cat (Catalonia) or .tv (Tuvalu), those countries rent their "desirable" names to private organizations that sell domain registrations for lots of money. In 2013, IANA decided to enact the gTLD auctions to help raise more money. Basically, if you wanted to (and had a lot of money & DNS engineers on staff), you could register any TLD you want provided you were willing to make a large donation to IANA. If someone else wanted it, they had to go into an action war over it. That's how we ended up with things like .party or .sport or .world cough Now-a-days, if you want a TLD, you'd have to convince IANA to give you one.... But good luck with that. They won't give you one unless you're some major corporation that can actually handle it. They also just don't give them out. Usually it's only when they really feel like more TLD's are needed. It's a very serious responsibility and mismanagement could accidentally DDOS a DNS root zone & impact the internet.

[–] grandkaiser 5 points 1 year ago (2 children)

Friday I was doing a zone transfer! What are the odds?

A zone transfer is like moving houses, except for an authoritative zone.

In DNS, we have what's called an authoritative zone. That means the device hosting the "resource records" (all the data that DNS passes around) is the "ultimate" answer. I.e, it's not cached data. It's not a hosts file. It's not a recursive answer. It's the real deal.

When you want to move the authoritative zone to another server, you do a "zone transfer" that means the new server will copy all the resource records over TCP from current authoritative zone. The reason you may want to do this instead of manually hand-jamming it is that many large organizations have, sometimes, hundreds of resource records (last month I coordinated a zone transfer that was over 1000 records!).

[–] grandkaiser 5 points 1 year ago
  1. Yes. Unless there's some kind of crazy domain-level hi-jinks involved with Lemmy (I am not versed in Lemmy), pointing directly to the IP will work if you bypass it by spoofing your DNS (Hosts file, for example).
  2. I don't know how Lemmy federation works, sorry :(
  3. See #2

Sorry that I couldn't answer more of your questions.

view more: ‹ prev next ›