In a CDN'd world, OpenDNS is the enemy
sajalkayan.com
sajalkayan.com
[1]: http://tools.ietf.org/html/draft-vandergaast-edns-client-ip-...
It seems that it would be in their interests to improve this. Both for a better experience for users and lower latencies from their point of view.
Or is it just that they're big, and it's a complex change?
[1] http://tools.ietf.org/html/draft-vandergaast-edns-client-sub... [2] http://news.ycombinator.com/item?id=4174512
I personally use it because I am extremely uncomfortable with my ISP catching mistyped URLs and redirecting me to a page filled with ads, searches, and other bogus things.
(Google - of course - does the technically correct thing)
That being said, I can still get behind at least choosing to let someone hijack those pages, rather than sticking with a company that does it automatically.
At some point in time I'd have said this would increase your DNS latency, but given the poor level of service that many ISP servers provide, I don't think that's true anymore. Though I have no data to back this up, I suspect many home users visit a fairly small set of websites and so DNS caching would work very well.
I have never seen an Israeli ISP do that. (Although, there were reports a few years ago that Bezeq intercepted .torrent files to add their own trackers to the file.)
Also because Comcast DNS sucks horribly and times out with upsetting regularity.
There is, as far as I know, no switch to make their DNS more reliable, though.
I take it you've logged into your comcast.net account and the box to disable it isn't there for you?
A lot of them already hijack port 80 and inject random junk in there which is why HTTPs is the way forward.
That's a pretty bold claim. Other than free wifi at hotels, I've never seen an ISP use transparent proxying to intercept pages and serve ads.
Do you have any examples?
Basically they mangle the HTML and slap in their own banner which means they must be doing some kind of stream inspection and processing to manage this. I do not have a proxy configured, and requests don't indicate that this is being done.
Unfortunately, most crappy DNS servers are with residential ISPs - and most residential users don't run anything near an usable distro on their gateways. For a user who's just competent enough to change the DNS settings, the "slow CDN access" versus "spotty DNS" tradeoff will be heavily weighted towards the first option.
In Australia, both Vodaphone and (to a lesser extent) Optus resolve all DNS queries from a server farm in a single location. It is unfortunate, because mobile clients are the perfect use-case for highly localized CDNs.
From my location Google DNS terminates within the country - so no issue there. Not sure about OpenDNS, however.
If that's correct, is there no better way to do user geolocation than the nameserver they choose to use? That seems weird to me.
The Google DNS team built the tool above, and it allows you to test your current setup against a number of DNS vendors + allows you to share the data, etc.
Or does namebench actually test the IP addresses you get in response to test their response time?
So I guess 8.8.8.8 is multihomed or however they call it. Still, the geoIP databases claim it to be in Mountain View where Google is, so I wasn't not sure exactly how this affected 'split horizon' (on which, as far as I know, the DNS decides which IP(s) to return for the requested hostname).
Google DNS uses both anycast and multihoming, so you will both be routed to the nearest google data center and then to the closest DNS server inside google's private network.