Break before make, abstractions, and sleazy ISPs
rachelbythebay.com
rachelbythebay.com
Seriously. This is a huge issue with Helm templating Kubernetes resources definitions. When you make a PR on your infrastructure repository, there could be many changes underneath the hood in a Helm chart that Are invisible from changes to a values file.
We had a rule in my last job the diff of the actual resource files had to be included in the PR in order to be approved because we were bit by the same.
Ideally, I'd want something like Propeller (with static type checking) to actually have a little confidence in my changes. We're not using Propeller due to the fact that it requires/installs GHC on the target machines -- I wish there was a GHC-to-bash compiler...
Turns out, it’s vendor locked to a specific ISP, iiNet, which wouldn’t be a problem if they offered static ips but they don’t. Its kinda funny because another sub company, internode, of their parent company, TPG, does offer static ips for vendor locked FTTB but it wasn’t offered in the building.
It gets weird for various other reasons (convoluted inbound tcp/25/80/443 unblocking process, static ips).
But the larger point is that ISPs largely control the internet and frequently do scummy things. in Australia it’s quickly becoming a very select vendor market and monopolising behaviour is occurring to the point where there’s very few decent ‘neutral’ isps left.
Here there’s laws to prevent complete monopolisation of media but I don’t think the same exists for networks comms, and I fear that this place is going to quickly end up owned by a few select companies that will effectively be able to do what they want, without intervention.
Maybe this sounds grim but I needed the rant
It helps the average user who is using their own internet connection or public internet connections.
Probably 90% of users will never be on a corporate network where they have control over their own browser configuration.
But all the detractors are like "I lose control over my network"
Whilst seemingly not having the skills to block all public DoH providers in their network. Not even going into DPI or MITM style web security products.
DNS isn't security. It's just an address book.
I’ll start by saying I’ve setup DoH on my home router just for fun.
> Whilst seemingly not having the skills to block all public DoH providers in their network.
Now with my admin hat on - maintaining a list is an unnecessary burden. It’s a matter of sensibility not skill. Time is money after all.
DoT (DNS-over-TLS) probably should have won since it uses it’s own port (853) which makes it easily manageable, does the same thing and is more mature. The “but privacy” argument for DoH looks like a red herring.
Even by hand, it would be easy to do destroy/create -- even if update would have been better -- and think that a few seconds downtime will not do much harm.
Not that this excuses the crummy ISPs
Even if I saw that the update was modeled as delete/insert, I probably would have okayed it.
ISPs doing shitty things... I mean, honestly, it's hard to believe that's even legal.
This.
Any good stories about stuff that broke?
DNS will either be blocked until you're signed in, or actually resolve correctly even prior to login.
Otherwise, the incorrect DNS record could still be cached even after signing in.
There's even a tool for routing all traffic over DNS queries, with a specialized resolver on the other end: https://code.kryo.se/iodine/
People are just trying to get stuff done. Come on.