[aklug] Re: Google DNS

From: Mike Gonnason <gonnason@gmail.com>
Date: Sun Dec 06 2009 - 01:49:55 AKST

A commentary on Google's DNS service:
http://arstechnica.com/security/news/2009/12/google-public-dns-service-not-=
ideal-for-everyone.ars

Possible issue mentioned in the article:
"Also, despite Google's claim that it provides NXDOMAIN responses
whenever a domain name doesn't exist, its servers actually respond
with REFUSED when looking up a name that goes with a private address
(such as in the 192.168.x.x or 10.x.x.x ranges)."

-Mike G

On Fri, Dec 4, 2009 at 6:48 AM, Scott A. Johnson
<scott.a.johnson@gmail.com> wrote:
> Mike, thanks for the info on Level 3 - and Michael I knew about
> OpenDNS as well so I know that's out there.
>
> Agree that Google could use all this info for an evil purpose, but
> looking at the privacy policies for the new service they state that
> your IP address isn't kept for more than 24-48 hours and no other
> personally identifying information is kept either. =A0Of course this all
> comes down to how much you trust Google, and yes some people probably
> think 24-48 hours is too long itself. =A0Regardless, another service is
> now live and available. =A0:)
>
> Scott
>
> On Thu, Dec 3, 2009 at 23:56, Mike Gonnason <gonnason@gmail.com> wrote:
>> On Thu, Dec 3, 2009 at 11:39 PM, Scott A. Johnson
>> <scott.a.johnson@gmail.com> wrote:
>>> For those that haven't heard yet, Google has launched a free, public
>>> DNS resolver service (see
>>> http://www.pcworld.com/businesscenter/article/183638/google_launches_al=
ternative_dns_resolver.html).
>>> =A0I thought this was great as I can finally specify something other
>>> than the GCI DNS servers that are reliable and free. =A0Best, and
>>> probably the least expected part is (and sorry GCI, this is where you
>>> lost some respect from me) the servers actually return NXDOMAIN when
>>> applicable! =A0Nope, the DNS servers don't just redirect you to a Googl=
e
>>> search page.
>>>
>>> IP addresses are super easy to remember as well - 8.8.8.8 & 8.8.4.4.
>>>
>>
>> Have you tried Level3's Public DNS servers?
>>
>> =A0dig yahooisawesome.com @4.2.2.6
>>
>> ; <<>> DiG 9.5.1-P2 <<>> yahooisawesome.com @4.2.2.6
>> ;; global options: =A0printcmd
>> ;; Got answer:
>> ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 53053
>> ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
>>
>> ;; QUESTION SECTION:
>> ;yahooisawesome.com. =A0 =A0 =A0 =A0 =A0 =A0IN =A0 =A0 =A0A
>>
>> ;; AUTHORITY SECTION:
>> com. =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0645 =A0 =A0 IN =A0 =A0 =A0SO=
A =A0 =A0 a.gtld-servers.net.
>> nstld.verisign-grs.com. 1259916604 1800 900 604800 86400
>>
>> ;; Query time: 102 msec
>> ;; SERVER: 4.2.2.6#53(4.2.2.6)
>> ;; WHEN: Thu Dec =A03 23:53:20 2009
>> ;; MSG SIZE =A0rcvd: 109
>>
>>
>>
>> They are 4.2.2.1 - 4.2.2.6
>>
>> -Mike G
>>
>
>
>
> --
> Scott A. Johnson
> scott.a.johnson@gmail.com
> http://scojo.us
> mobile: +1.907.240.2483
>
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Sun Dec 6 01:50:27 2009

This archive was generated by hypermail 2.1.8 : Sun Dec 06 2009 - 01:50:27 AKST