Chrome connects to three random domains at startup
mikewest.org
mikewest.org
These "random" requests look almost exactly the DGA for Murofet- a Zeus variant. This has caused some problems for us (and other vendors, I would assume) in the form of massive numbers of false positives. In short, it's been kind of a PITA.
I wish they wouldn't do this, but it is definitely a tough problem to solve and I can't think of a better approach off of the top of my head. The ultimate culprit is the ISPs that return an A record for a DNS request that really should return NXDOMAIN. These ISPs are essentially breaking the Internet, and we're all just scrambling to put band-aids in place to get it to work again.
One part of the filter is attached to our default DNS server, and it looks up novel domains to see if they ought to be blocked. This lookup is slow.
Launching Chrome first thing in the morning takes quite a while, because our DNS server/filter blocks until those 3 random domains fail to resolve.
I really wish that I could turn it off, although admittedly our "network" is barely compliant with protocols in the name of filtering.
--dns-server=8.8.8.8
But it also looks like it doesn't always work (never worked, or is a special development mode only feature). Here is the bug report on it:(thanks for pointing this out; it wasn't what i was suggesting - i had assume the laptop was the op's own).
Roaming devices might make it a bit more tricky, but some integration with OS connectivity-detection and location-awareness might help there, as well as an improved UI for actually setting it.
A really short-term bandage would be to use some less identifiable DGA, but that opens the possibility of future malware using the Chrome DGA to pretend to be legit.
Is there a technical reason why 'foo.invalid' and 'bar.invalid' (and any of the other restricted dns names) couldn't be used instead?
I suppose that the ISPs could serve those correctly to make the tests pass, but what would they gain from it except even more user irritation?
Anything I'm missing?
A flag wouldn't be enough, because Chrome also learns what records it returns when it lies, so it can recognize other lies.
Wondering why Chrome is not simply using the Google resolver on 8.8.8.8. Of course this would yet be another band aid that breaks the internet even further, when applications start implementing their own network stack.
Not a problem for me, but I'm sure a lot of people would complain.
This just seems like adding duck tape to a self-inflicted problem.
(Not that having chrome use 8.8.8.8 is a good idea either. As is often the case with hacks, either on its own works fine but the two interact poorly.)
That being said, it very well maybe time to find a better alternative :).
As for DNS, it has a very elegant hierarchical delegation system, such that organizations can control their own while also ensuring that all the world's DNS servers give consistent answers (and if you need short names for your internal systems on your own network, that's what search paths are for).
The easy solution was to stop using Chrome. The hard solution was to move. I've done both, but have yet to start using Chrome again.
Things didn't improve under AT&T.
i have all those disabled and chrome still appears fast to me.
"Your ISP (network administrator, ..) is intercepting and manipulating DNS requests. Do you want to use Google DNS instead?"
Comes in real handy when we need to have a "DnsManipulationDetector" in the future that checks if your DNS is actively censoring...
Though it's certainly worth a shot, and I suppose Chrome could probably do a test query to 8.8.8.8 before recommending the switch.
I would prefer
"Your ISP (network administrator, ..) is intercepting and manipulating DNS requests. Do you want to install a local caching DNS server and use it instead?"
Unbound [1] is a local DNS server that I have installed on all my machines. Small, fast, security-oriented, IPv6, BSD, made by NLnet Labs.
If you use Google's DNS (or anybody's DNS) you are basically telling them which sites your are visiting. If you have a local DNS resolver you will not leak all that information to a single third party.
No, not a single upstream.
When my browser asks my server on 127.0.0.1 to lookup news.ycombinator.com it will first contact the root DNS server, then `com` DNS server, then then `ycombinator.com` DNS server. Who knows about the fact that I was looking for `news.ycombinator.com`? only the `ycombinator.com` DNS server. Who knows about the fact that I was looking for `ycombinator.com`? only the `com` DNS server. Now I go to slashdot.org. Who will know about that? Only the `org` DNS server. If you use the Google DNS, Google will know that you requested both `news.ycombinator.com` and `slashdot.org`. Do you want them or any single company to have all these information?
Obviously you need an upstream, an authoritative server somewhere. But why do you need to concentrate all these requests on a single DNS server? ISP are actively tracking users and, probably, selling their DNS histories to advertiser. Nominum (makers of a widespread DNS server) is quite explicit about it: «Data gathering and measurement are a vital part of network operations and DNS data represents a rich vein to be mined that has been underutilized in the past». [1]
http://code.google.com/codesearch#OAMlx_jo-ck/src/chrome/bro...