Or kill a lot of people if they rebel. Which is what Iran did just before the pandemic, and which the media only briefly covered. They machine-gunned people in the streets by the thousands and the West barely batted an eye.
It was as bad as Tiananmen Square in 1989, but you'd never know it going by the media coverage then or since.
Of course, Iran has parallel structures with IRGC specifically made for those situation.
Are you concerned with countries forcefully removing entries? Because there are a lot of other country TLDs where you can add your entries if you want.
With DNSSEC it is still vulnerable, but only to the kinds that you will know you are being censored, so you can try to get it from another country or another channel.
If your ISP denies DNSSEC for you, you already know you are being attacked, and can get it through some other channel. DoH is a cool channel, just make sure it has DNSSEC.
The only way around this is for local systems to do their own recursive resolution, which isn't the default configuration on any OS or distribution that I'm aware of.
What is it with DNSSEC that people have to pollute discussions saying that stupid stuff that isn't DNSSEC isn't secure?
The reason I'm describing local stub resolvers that check the dnssec bit of their upstream recursive resolver is because that's how DNSSEC is implemented in every OS/distro I'm aware of. So that configuration is what actually matters when we talk about users being protected (or not) by DNSSEC.
Are you really making FUD about it, by claiming unrelated logical fallacies in a non-boolean discussion? How does a "no true Scotsman" even applies to something that has a published standard?
I know you don't like it, yet, I have never seen any proposal that brings you the assurances DNSSEC brings. AFAIK, your favorites all wither solve different problems (relevant problems, yes, but not the same) or have strictly lower assurances (AKA, they are subject to the exact same flaws, and are either worse or not better of for each one of them).
DNSSEC defines stub resolvers, both validating and non-validating. Validating stub resolvers do their own supplemental recursive lookups to confirm DNSSEC validation. Non-validating stub resolvers do not: they strictly determine DNSSEC trust by checking for the "ad" header bit in the response from their upstream recursive resolver.
Every operating system, Linux distribution, and application that I'm aware of defaults to having a non-validating stub resolver (if it enables DNSSEC validation at all). This renders DNSSEC validation as performed by the overwhelming majority of systems vulnerable to the risk we're flagging here.
Probably I should figure out a way to have my pfsense box though dynamically generate the blocked IP's based on one of these dynamically updated lists...
The internet was built for fail-over to maintain communicatoin during a nuclear event.
The internet is less concerned about being a p2p network, which it clearly is not. A totally ad-hoc p2p network would be interesting, and more resiliant in some ways and lossy in others. It probably makes sense to entertain such a model. They aren't mutually exclusive.
Totally agree with you though. It's a big problem with the _increased amount of centralization_ in traffic flow / routing. That and BGP is wack.
Shutting down the Internet will disrupt not only people's communications but also systems' communications at various levels, including the systems of interest of the oppressive, of his/her family or political allies.
It would be so much easier and safer to the group in power to just "maneuver" bigtech instead. I remember when Facebook's general manager in the country I live was arrested[1], then blackmailed, to provide authorities means for them to access WhatsApp messages without confiscating the actual phones. Fast forward today, they are confiscating phones whenever they feel like reading private messages from anyone[2].
I liked how other folks reacted to my original comment posting their technical view. I didn't know DNS was such a weak link and a clear point of failure to the Internet. I wonder if protocols like BitTorrent could survive DNS restrictions, allowing people to communicate via shared text files thrown within a folder. My guess is that since it has survived the copyright crisis back then, it could be used for other crisis as well. Frankly, I'm just suspecting.
[1] https://jornaldebrasilia.com.br/noticias/brasil/executivo-do... [2] https://jc.ne10.uol.com.br/colunas/jamildo/2022/08/15065135-...