Chromium cleans up its act and daily DNS root server queries drop by 60B
theregister.com
theregister.com
Anyway, in the process of doing this and putting it in my DHCP config and seeing the traffic from two smart TVs of different brands, my RIPE atlas probe, various phones and laptops, smart thermostat, etc etc, I've noticed that there is a TON of "garbage" dns requests. Like, the chart [the article] shows - where about 70% of queries result in a name error - that totally meshes with what I see on a much smaller scale. Right now, prometheus tells me that since last restart (which was about a week ago at this point?), I've answered 80437 queries with NO_ERROR, 52014 with NAME_ERROR, and 242 with SERVER_FAILURE (funnily enough, when spot checking these, 8.8.8.8 also SERVER_FAILUREs these same requests - usually devices with presumably-buggy dns libraries not correctly specifying lengths of variable-length fields).
It really surprised my initial suspicions that so many DNS requests would be coming up with what I was originally considering to be an error condition. But I guess sometimes the absence of a DNS record is just as meaningful as the presence.
Incidentally, I also noticed these chromium dns requests, and they had me worried for a bit because I wondered if they were malware trying to exploit some kind of vuln in dns servers. Took a bit of googling to figure it out. I do think they make up a decent % of the name errors I see, though I hadn't gotten around to having prometheus split them out to measure.
Buying something in bitcoin using only the protocol spec and man pages? Tweeting from a Linux from scratch install? Writing a correct tar command on the first try? Writing a quine on your favorite language without google?
My take on it was that lots of this old software was implemented by candlelight with a magnetized needle, a 512KiB HDD platter and a steady hand; so I should be able to reimplement it in a modern language with modern tooling in a lot less time, while learning a lot about the system. Like, dig command output means a lot more to me now than it did at the start, and I now appreciate what articles like the OP mean now.
https://robertheaton.com/2018/12/08/programming-projects-for...
The project goals are not as lofty as those proposed by nishanth_v's friend, but Mr. Heaton goes the extra mile to turn each project idea into a step by step mini-curriculum with lots of extension points.
Then, he goes another extra mile by allowing readers to email in their buggy projects, and running a companion series where he teaches people how to debug / fix / improve their code by refactoring reader's attempts at the "...Advanced Beginners" projects.
Recommended.
Not quite the same as I'm not following or reimplementing any established standard, but it's interesting and fun to Greenfield a c++ project using minimal dependencies to do things like:
- invent and parse a DSL - modularise components and connections between them - possibly cyclic directed graph traversal - efficient near-real-time audio processing (working in chunks within a time budget) - multithreading / parallel module processing - spit the outputs into an audio device and/or wav files - eventually put a GUI on top
If I can dream, an LDAP implementation with a similar target as GP wound be fantastic.
That’s not a short one though (:
In the same vein, I think building or designing some of the components in an OS or Systems book[1] could have a similar positive result.
[1] https://mitpress.mit.edu/books/elements-computing-systems-se...
I usually get it to run a simple loop to print hello world and do the inevitable Fibonacci generator and get bored. No fancy things like functions!
One of these things was crudely repurposed into a domain specific language for a job as well which was handy.
Dnsmasq or PowerDNS weren't suitable?
The difference is huge in other ways, though. Configuration, operations, and maintenance of the BIND cluster is 20 fold more involved, and when things break, they can break in really confusing ways. Such is the world of computing though, the better something performs, the more places it has where you can mess it up.
If you are running a properly configured PowerDNS, and 15k containers make it fall over, you don't have a properly configured PowerDNS
That sounds pretty different from the audience they said they're targeting → "impatient homelabbers/SMB".
As another commenter points out though, the load you're talking about definitely sounds like something PowerDNS should handle without much problem. Given reasonably spec-ed, hardware and software that is.
It's used by some pretty big places:
The niche I'm aiming for is for people who just want to map hostnames to IP addresses. And note this isn't a commercial offering, just something I built for myself that I'm going to put up a website for and maybe some other people will find interesting. I do think I have some product-market fit because even among my dev friends, who are all quite talented, many of them have mentioned to me "yeah I threw bind9 on a server but decided I didn't hate typing IPs enough to actually set up and operate it".
I'm aiming for zero onboarding time and zero maintenance headache. You run a docker container, map the ports, and then there's a nice web UI that takes you the rest of the way.
https://blog.apnic.net/2021/02/04/how-chromium-reduces-root-...
I suppose that's probably thanks to caching, dedicated apps for many websites, and most users sticking to a relatively small selection of websites.
It’s, I believe, those servers that hit the root DNS servers when they don’t have the data.
Plus, the answers returned by the root servers more often than not include resource records with very high TTL values (e.g., NS RRs with a TTL of two days). These then get cached for that long by the recursive resolvers that are used (directly) by end users.
The root servers aren't responding to requests for the A RR for google.com from Joe Schmoe or the MX RR for gmail.com from Outlook running on his desktop -- both of which (without checking) likely have TTLs measured in a two- or (at the most) three-digit number of seconds.
I think this is one of the key problems that emerged by merging the search functionality into the location bar. I still now always enable the separate search bar for Firefox and avoid running searches in the so-called Awesome bar. I still consider a search and host lookup very different operations in my mind.
This behaviour actually suits Google well, because their incredibly lucrative "promoted results" are shown before the real destination site. You can't charge an advertising tax on users who browse directly to their destination.
However, you can have misbehaving ISPs that replaces all NXDOMAIN responses with something (producing false positives for what constitutes "valid" hostnames), or a guest portal that is hijacking DNS responses, so Chrome will make requests for random DNS hostnames that are unlikely to exist to detect if DNS hijacking is occurring and disable the intranet detection if it is.
[0] https://blog.apnic.net/2021/02/04/how-chromium-reduces-root-...
[1] https://www.archyde.com/chromium-function-against-dns-hijack...
And when you do eventually reach any of them via manually prepending 'http://', they make the 'http://' not visible in the bar. What confusing signaling!
Hint for Chrome: if I'm appending a port and the DNS name exists I probably don't want to Google it.
For something you do dozens of times a day even a tiny gain adds up over time.
I guess I'll just accept the flaws that come with it.
Their goal is to treat the query as search, and then try to detect if a host named "internalserver" exists. If so, Chrome displays a banner saying "do you want to visit internalserver/". So they don't have to delay the search until the probe finishes, thus it never automatically make it work without another click.
Personally I don't like it either, so I usually type "internalserver/" (with a tailing slash) to skip the search.
I always assumed they didnt make this easier so my mum doesn't go to almostBank:8000
if you go to host ports a lot i.e localhost you can spend a quick search to the sqlite DB for your preferences to make l<tab>:<port> expand out.
u have to edit the SQL. they "patch" the UI so it doesn't accept just arbitrary string patterns to tab complete but only URLs.
This script is made as a reference after I'd already done the setting so assume it needs editing to work.
Keyword: l, URL: localhost:%s
Then it works how you're describing with l<tab> and input the port. I personally define all the different versions of my servers that way so v1<enter> goes to something like internalserver:9001, v2<enter> goes to internalserver:9002, etc.
This script is made as a reference after I'd already done the setting so assume it needs editing to work.
In recent versions of Chrome, you can right-click the bar and choose "Always show full URLs" to fix that particular stupidity.
> Thanks, Matt, that's great to see. Note that that's the effect of the change in comment 37, which only affects Android. The desktop change is blocked on a planned experiment in M88. A wide rollout probably won't happen until late February or early March, at which point we expect an additional reduction in root traffic. [0]
They were doing the DNS interception check on Android, but a different path of code was actually doing the checks (in a different way). Android was basically sending out useless requests.
[0] https://bugs.chromium.org/p/chromium/issues/detail?id=109098...
[1] https://www.nbcnews.com/news/us-news/senate-votes-let-isps-s...
(edit: explaining better what I felt was a privacy violation)