[EXTERNAL] Charter DNS servers returning malware filtered IP addresses

Livingood, Jason jason_livingood at comcast.com
Mon Oct 30 14:58:42 UTC 2023


On 10/27/23, 19:01, "NANOG on behalf of Owen DeLong wrote:

> If it’s such a reasonable default, why don’t any of the public resolvers (e.g. 1.1.1.1, 8.8.8.8, 9.9.9.9, etc.) do so?
> DNS isn’t the right place to attack this, IMHO.

Are we sure that the filtering is done in the default view - I would suggest the user check to ensure they don't have a filtering service (e.g. parental controls/malware protection) turned on. In my **personal** opinion, the default view should have DNSSEC validation & no filtering; users can always optionally select additional protection services that might include DNS-based filtering as well as other mechanisms. 

JL



More information about the NANOG mailing list