Locking down your GitHub-hosted Domains
aaron-gustafson.com
aaron-gustafson.com
> After a lot of digging around, trying to figure out how the hijack was accomplished, it turns out it was via GitHub Pages.
This is not what responsible domain ownership looks like. It shouldn’t take a lot of digging around to find out why a subdomain of yours resolves.
When I was a kid, blog posts like this one helped me understand things.
DNS is one of the most notoriously cumbersome systems around, even for advanced engineers. Most people spend very little time (less than 1 hour per year) dealing with it, which isn't not long or often enough to commit learning to long-term memory, and the opacity of the different layers, plus tiers of caching, make it difficult to diagnose and debug problems when they arise.
Even professional network engineers frequently trip over "basic" problems with DNS. It's a system with virtually zero guardrails and so many potential hazards that it's completely understandable for almost anyone to find themselves in these situation.
There's a reason this haiku is so famous:
> It’s not DNS
> There’s no way it’s DNS
> It was DNS
Does this extend to any cloud provider?
For example if I have a domain pointed to Digital Ocean's servers and manage my records there, could this same issue happen if I have wildcard domains on DO?
If it's a server on your DO account, then that counts as a server you control. They do recycle IPs eventually if you delete something but the solution there is to update your DNS.
[0] https://help.ns1.com/hc/en-us/articles/360020248973-About-CN...
It goes beyond that -- "ALIAS" isn't a DNS record at all; it does not exist as an entity within the DNS protocol. It's a directive used by some DNS servers (primarily at large providers) which causes the DNS server to synthesize A/AAAA records.