Pro-SOPA Comcast just implemented SOPA-incompatible DNSSEC
itworld.com
itworld.com
http://dns-opt-out.comcast.net/help-index.php
The only requirement that you need is your Comcast account information that was created when you signed up with them. If you don't know the username, to avoid the issues whichdan ran into just call them on the phone (or if you're on your home internet connection you can start a webchat with them at https://www.comcastsupport.com/ChatEntry/ and tell them you forgot the account, then once you know it, ask if they can reset the password for you).
This will reprovision your cable modem(s) with alternate DNS settings (which are actually the same DNS server settings as their DNSSEC servers: 75.75.75.75 and 75.75.76.76). If you don't want to mess with turning it on/off and you've got a router connected to the cable modem (or a computer directly connected - please never do this!), you can just manually change your DNS server settings to these values and get the same effect (effectively ignoring the ones provided through the cable modem connection).
It should trigger a reboot/update on your cable modem, which will then cause it to pull down the alternate DNS server settings. Per the documentation on their help page, you may need to reboot any attached routers so that they pull down updated DNS information (though loss of link with the cable modem should trigger that when the cable modem comes back up).
And though the parent commenter used Google DNS (which I really do like) - users that make use of the iOS App Store for their iPhones / iPods / iPads may want to consider using the Comcast DNS server settings - if not for all devices in their house, then at least manually enter them for WiFi networks served by Comcast cable modems.
In my personal experience, using the 8.8.8.8 / 8.8.4.4 Google DNS server settings resulted in rather slow downloads compared to using the Comcast DNS server settings, as I believe Apple's App Store CDN server addresses were resolving to geographically incorrect / distant servers.
CDNs can use DNS trickery to speed up delivery. When a domain server (your ISP's) looks up the IP address for a server name that's hosting content you want, the name server can return tailored IP addresses based on where in the world it thinks the request is coming from.
Google's DNS servers do their own trickery to attempt to connect you to a DNS server close to where you're at (or at least provide results quickly for where you're at), but Comcast's DNS servers are hosted on their core networks which can reach their customer base quickly. A CDN IP address result tailored for where the Comcast DNS servers are hosted will result in an IP address that your home connection will likely be able to pull down from very quickly as well.
Results may vary, and I do trust Google to do less evil with their DNS results than Comcast - but damn it, I wasn't willing to wait 20 minutes to download an app that should have taken only 2.
Just google "public DNS server" and start pinging them. For me, Verizon's name servers are the fastest; easy to remember too.
4.2.2.1 4.2.2.2 4.2.2.3 4.2.2.4 4.2.2.5
Opendns might work too but I've found it to be slow. Extra credit: set up a caching recursive resolver to serve your local net for web faster queries.
The real benefit for me was the CDN content coming through much much quicker for the App Store. iOS 5 has gotten so capable of managing content with iCloud and such that I rarely tether this to my laptop any more.
As such, quickly downloading an app while on WiFi is very important, since anything over 20MB requires you be on WiFi to do it.
I only came about this information by noticing that I was getting significantly higher download speeds from the App Store while at my parents' house on their WiFi than I was at home - yet we were both Comcast customers and I knew that I was paying for a slightly higher data package and had been able to perform 16Mbps sustained transfers on my laptop for non-App Store content routinely.
So I copied down the Comcast DNS settings that my folks had and tried them out, manually, at home on my iPhone. The speed difference was almost immediately noticeable.
Prior to that, I'd been using Google DNS servers 8.8.8.8 and 8.8.4.4. Just simply changing my DNS servers resulted in a much better performance.
I'll have to shop around to see if I can tweak it even further :)
For most of America you end up in Dallas, TX, for the UK you end up in London, and for The Netherlands I was ending up in Amsterdam.
I don't have access to more machines to do traceroutes to see what the last hops are, but you can easily check this for yourself with a traceroute and seeing what network it ends up at.
Also, I was under the impression that their DNS servers technically require payment before use (as a commercial entity when handing out over DHCP) and are technically only for Level 3 customers. Everyone and their mother has started using them because they are easy to remember.
Here is some more backstory of how the DNS server was originally set up:
Edit: Downvotes or not, they still fuck with NXDOMAIN. Check for yourself.
They are one of the first large ISPs to actually start real work on deploying IPv6.
And I remember calling during an outage and speaking to someone on the front lines (not second tier) who was actually very technically knowledgeable.
Whatever you may think of their business department (silly things like internet + cable costs less than internet by itself), the network side is really good.
You can't grow a network that large without knowing your stuff inside and out. The netops folks at comcast are fairly active in NANOG, etc. as well.
Since no one has read it, here's the relevant text: "A service provider shall take technically feasible and reasonable measures designed to prevent access by its subscribers located within the United States to the foreign infringing site (or portion thereof) that is subject to the order, including measures designed to prevent the domain name of the foreign infringing site (or portion thereof) from resolving to that domain name's Internet Protocol address." (I wonder if I am now cursed.)
If ISPs wanted to avoid this scenario, it would essentially require fracturing DNS[SEC] into something the US Govt has the authority to sign properly without effecting the rest of the world - in other words a completely divided national internet.
Or we could just all switch to using DNSSEC servers on the Barbados Islands or something in the future.
Look for other DNS resolvers.
(human and/or automated processes)
http://www.securityweek.com/dnssecs-time-here-sopa-presents-...
Some people have proposed that instead of blocking DNS, ISPs should redirect a DNS request. That would be incompatible with DNSSEC--but that requirement is not in the bill.