NameCoin is a pretty interesting solution as well.
But let's question for a moment whether this is actually an engineering problem. The DNS system is pretty bad; I'm sure that a few of us can come up with a better system in an afternoon. However, these competitors have failed to take hold.
It's probably mostly a social or political issue. One of the things that I think is important is to start making internet architecture issues the subject of conversation at the dinner table, at town hall meetings, and just in everyday life. We need to ignite a social consciousness around the internet and its ways. We need strong, determined will to do better.
I mean if we really wanted to DDOS Cloudflare, we just exhaustively gather all the raw APEX/Naked IPs of their edge nodes then stress them, but I imagine Cloudflare doesn't advertise their list of IPs and they're closely guarded, so attackers are left in the dark. But such an attack is plausible.
What we do need are antifragile protocols like BitTorrent/IPFS/Bitcoin which infact reward swarm behavior, instead of punish it.
The issue comes when you have to depend on a single service. When you're using traffic management from NS1 or content delivery from CloudFlare, then you have no choice but to use a single DNS provider. Unless they have some special service for whoever pays enough.
I’m not using CloudFlare, either. That’s the point. If I use CloudFlare CDN, then I depend on CloudFlare’s DNS servers.
The way it works is that DNS servers often have a master/slave relationship. The master sends all the records to the slave once in a while. What you’re supposed to do is list your own server and another server as two separate NS records, and then any client can contact either server for any record. What I’m doing is a hidden master setup. Neither NS record refers to the master, but both point to separate slaves.
There are some downsides. You must assume that any record is public, not private. DNSSEC white lies[0] (and black lies[1]) are not available. And it’s more difficult to use a CDN. But I’m not running a web site right now, so that doesn’t matter to me.
[0] https://blog.cloudflare.com/dnssec-complexities-and-consider...
Browsers still support dated protocols like FTP[2], which shows you how much browsers need to catch up.
[1] https://blog.acolyer.org/2015/10/05/ipfs-content-addressed-v...
I wrap Route53 via git at https://dns-api.com/ and I'm in the process of supporting other back-ends to help automate this process.
Each machine could have a file listing all other hosts. We could put it in the /etc directory.
/etc/hosts
That would totally fix the DNS problem. But I think we should wait till Flag Day (June 14, 2017) to make the change.