nanog mailing list archives

Re: [EXTERNAL] Re: Charter DNS servers returning malware filtered IP addresses


From: Michael Thomas <mike () mtcc com>
Date: Fri, 27 Oct 2023 16:02:09 -0700


On 10/27/23 2:20 PM, John Levine wrote:
It appears that Bryan Fields <Bryan () bryanfields net> said:
-=-=-=-=-=-
-=-=-=-=-=-
On 10/27/23 7:49 AM, John Levine wrote:
But for obvious good reasons,
the vast majority of their customers don't
I'd argue that as a service provider deliberately messing with DNS is an
obvious bad thing.  They're there to deliver packets.
For a network feeding a data center, sure. For a network like
Charter's which is feeding unsophisticated nontechnical users, they
need all the messing they can get.

If you're one of the small minority of retail users that knows enough
about the technology to pick your own resolver, go ahead.  But it's
a reasonable default to keep malware out of Grandma's iPad.

How does this line up with DoH? Aren't they using hardwired resolver addresses? I would hope they are not doing anything heroic.

Mike


Current thread: