Peter Dambier peter at peter-dambier.de
Mon Mar 20 22:29:26 UTC 2006

> Then leave governments out of it, and re-phrase the question in this
> way.  If one can not run one's own DNS server on the public Internet,
> but must rely on a DNS service supplier for your DNS, and at some point
> you start to wonder about the technical competence or correct configura-
> tion of the DNS service supplier whose DNS you are configured to use,
> and all other DNS servers out there are configured to refuse recursive
> service except perhaps to their own population, than against what can
> you compare the DNS service that you are getting, to see whether it is
> giving you what "the world" should be seeing?

That is exactly what worries me.

In germany censoring is commonplace. You have to use foraign resolvers
to escape it. There is a lot collateral dammage too - governement has
provided the tools. Corrupt people use it to play tricks on their

How about alternative roots? ICANN does censor "XN--55QX5D.", "XN--FIQS8S."
and "XN--IO0A7I." already. You must use alternative roots to exchange emails
with people living in those domains.

Banning open resolvers means censoring for a lot of people, at least
if they cannot run their own servers.

