Quad9 Files Official Objection Opposing Sony Music’s German Court Ruling
quad9.net
quad9.net
If you are an individual: Quad9 relies entirely on sponsorship and support from individuals and companies who believe in our mission, and who benefit from our protection of end users. We need resources to fight this ruling, and to continue our mission of providing security and privacy to end users. Your comments on social media to amplify the awareness of this issue and engage in civil discussion on the topic are welcome. Please help by donating via Paypal.
IMHO they went after quad9 because they advertise that they already block some domains, based on some lists. They'll probably argue that it's simple to add to their system.
Google's 8.8.8.8 / 8.8.4.4 offering is actually very forgiving. Most pirate sites now have multiple TLDs and advertise the latest TLD in use on social media. New TLDs usually arrive when there is pressure by Google or even LEAs to censor specific domains.
https://media.defcon.org/DEF%20CON%2029/DEF%20CON%2029%20vid...
Edit: Source: https://www.pcworld.com/article/2047227/downloading-increase...
Historically the government reaction to that was to censor the DNS protocol itself. Trouble is, by the time they got around to legislating for such things, DNS is already optionally encrypted. In Firefox for example General -> Networking Settings -> Enable DNS over HTTPS
I'm talking about obtaining the content. Sooner or later they'll just ask a techie friend where they can still get their sweet torrents and they're back in business.
They've blocked the pirate bay in the Netherlands for a long time and it was hardly effective at all. In fact it did the opposite: https://www.pcworld.com/article/2047227/downloading-increase...
And finally, don't forget: The people who are using Quad 9 are people who do know what they're doing. Otherwise they'd be simply using their provider DNS.
What about providers of phone OSes that scan for illegal files against the user's wishes?
Its impossible to prevent denial of service generally, but you can use crypto to detect when it might be happening.
(NXDOMAIN is also somewhat special in DNSSEC and not signed by default, and requires special mechanisms to handle (NSEC, NSEC3), but IMHO that's not even very relevant to the block scenario)
If you're validating then the second answer should cause you to regard the reply as invalid and retry the request, possibly using a different DNS service.
Resolvers could also just drop the connection. The only thing they can't do with DNSSEC is falsifying a NXDOMAIN result.
In DoH the HTTP error codes provide a way for the server to explain why it can't (or won't) give you the correct answer to your query, for example because you set it to block advertising, or your government obliges it to censor domains, separate from the actual DNS answer or absence of one.
This will grow even more interesting under oblivious DNS, a planned future upgrade to the DPRIVE protocols in which you'd send your questions to an intermediate (e.g. quad 9 in this case) but those questions are encrypted so they can't read the details, and the intermediate forwards them to an authoritative name server (which thus doesn't learn your IP address) that can decrypt them, before sending the response back to you without being able to read it.
This obliviousness means that on the one hand Google, Cloudflare and similar large DNS providers don't see what exactly it is you wanted to know about example.com (if www.example.com is the only thing that exists this isn't much help, but if clown-porn.example.com, adopt-a-puppy.example.com and holocaust-survivor.example.com are all under example.com then this makes a real difference to your privacy) and yet on the other the people operating example.com don't get your IP address (at least until you connect directly to their servers over plain TCP) and yet you still get the answer you wanted.