Introducing Google Public DNS: A new DNS resolver from Google
googlecode.blogspot.com
googlecode.blogspot.com
:-)
Edit: Here it is: http://blog.opendns.com/2009/12/03/opendns-google-dns/
ns[1-4].everydns.net, the first thing I do to a domain name that comes under my control.
OpenDNS: It's neither 'open' nor DNS!
[bcl@lister tmp]$ dig www.google.com
; <<>> DiG 9.6.1-P2-RedHat-9.6.1-7.P2.fc11 <<>> www.google.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33790
;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.google.com. IN A
;; ANSWER SECTION:
www.google.com. 603958 IN CNAME www.l.google.com.
www.l.google.com. 300 IN A 74.125.53.106
www.l.google.com. 300 IN A 74.125.53.103
www.l.google.com. 300 IN A 74.125.53.147
www.l.google.com. 300 IN A 74.125.53.105
www.l.google.com. 300 IN A 74.125.53.99
www.l.google.com. 300 IN A 74.125.53.104
;; Query time: 52 msec
;; SERVER: 192.168.101.20#53(192.168.101.20)
;; WHEN: Thu Dec 3 16:44:24 2009
;; MSG SIZE rcvd: 148
Here is what opendns serves up: [bcl@lister tmp]$ dig www.google.com @208.67.222.222
; <<>> DiG 9.6.1-P2-RedHat-9.6.1-7.P2.fc11 <<>> www.google.com @208.67.222.222
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54658
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.google.com. IN A
;; ANSWER SECTION:
www.google.com. 30 IN CNAME google.navigation.opendns.com.
google.navigation.opendns.com. 30 IN A 208.67.216.230
google.navigation.opendns.com. 30 IN A 208.67.216.231
;; Query time: 26 msec
;; SERVER: 208.67.222.222#53(208.67.222.222)
;; WHEN: Thu Dec 3 16:47:25 2009
;; MSG SIZE rcvd: 104
All your queries are belong to us.At the top of the page, he shows the exact text that appears on the "horrible" search results page. That text explains exactly how to remove that functionality:
"This program can be uninstalled from the Control Panel "Add/Remove Programs" in Windows XP or "Control Panel > Program > Programs and Features" in Windows Vista. Look for the application named "Browser Address Error Redirector". Older versions may be called "GoogleAFE" or "URL Assistant"."
He says this statement is "ambiguous". I have no idea how it is ambiguous, but ok. He then goes on to say the software is "hard to remove", and later that "users can't get rid of it!", both of which are outright lies. Installing and uninstalling software is a normal part of owning a computer, and as you can see above, Google's message tells users exactly what to uninstall. The entire process could be completed in 30 seconds.
But I have to ask myself every time I read this article: why is this guy going to so much effort to spread inaccuracies that demonize Google for trapping search results and presenting ads?
Well, because that is exactly how OpenDNS makes money, and Google threatened their business model. The entire first portion of the post, attacks and all, is present to justify this:
"we’ve stretched a bit beyond DNS itself to work around Google’s mis-directed efforts."
By going on the offensive, he now tries to justify providing a DNS service that OpeDNS doesn't just resolve hostnames anymore...instead, OpenDNS makes moral judgments about the domains you visit, and, as they trumpet so loudly, "we have a fix which does not require more client software". What this means to me is that whatever OpenDNS is doing, I can't uninstall it, because they own it -- it's not on my machine, it's on theirs.
Listen, when I use DNS, there's a contract I expect DNS to fulfill: I give you a name, and you resolve it to an IP or tell me it can't be resolved. It is an outright violation of the contract to resolve a hostname I give you to an address other than that with which it is associated, which is exactly what OpenDNS is doing.
I don't own a Dell or run with any toolbars. I would find the "Browser Address Error Redirector" and remove it if I faced that warped experience.
So for me, this unrequested proxying isn't help, it's collateral damage from two competing typosquatters/querysquatters each trying to one-up the other.
A harder, but classier, way for OpenDNS to escalate their battle with Google would have been to offer a different set of DNS server IP addresses for customers who may want OpenDNS to trump Google/Dell.
I think it’s a little naive to think it is a good thing for you. How are you going to compete with Google’s infrastructure and get your response times down to Google DNS’? I would expect many people will switch away as I just have until you can roll out an extremely expensive upgrade.
Update: I approved your comment.
Learn something new every day.
And so does every other DNS provider so long as the pages are public and if your ISP is your DNS provider then they can directly sniff your (non-encrypted) traffic too.
Not sure if their privacy policy lets them exercise their power fully in this field, though.
(i.e. If I go to sws.example.com which hosts a Secret Warez Stash, unless it's password-protected everyone has access to it, not just Google.)
But now you're adding yet another party in the mix -- Google, who already have a lot of information about your interests and habits. At the very very least, you're inviting an interested third party to have a look at your traffic.
Most of davidu's response was kind of a waste of time, but the one thing that made an impression on me was when he referred to Google as an advertising company. He's right; they're the most technologically advanced advertising company in the world.
So if this conversation was about "an unnamed technologically savvy advertising company", instead of Google, would you still be interested in giving them your DNS traffic?
So... you're saying that reputation counts for nothing? Google sort of evolved into an advertising company because of the position that they held as the most popular search engine.
Most advertising companies are companies that started out trying to be an advertising company. Most of them probably had to be cut-throat to make it out of obscurity.
This isn't to say that anyone should place blind trust in Google, but if -- as you're implying -- reputation counts for nothing, then what's the point in trying to maintain a reputation at all?
See my other reply in this thread too. You completely misinterpreted my post (or just used it as a soapbox to insert your views into the discussion). The post I was replying too said nothing about Google pulling all the information on you together. The poster seemed to be irked that your DNS provider also had access to the content of the pages you were using DNS lookups to view. I was pointing out that this is true of any DNS provider.
Google does not have a spotless track record in customer privacy issues, nor is there any reason to believe that because they're behaving in a particular way now, they'll behave the same later.
It's as simple as this: while I'm a fan of most of Google's products and services, I also think there's a point at which it's no longer smart to put all of your eggs into one internet company's basket, and I think we've reached that point.
True, but most of the records are deleted after 48 hours, meaning that they no longer exist for Google to decide to mine years later once they change their policy. Other than that, this only becomes an issue if the entire internet starts pointing their DNS queries at GoogleDNS, which I doubt will happen.
Not mentioned was OpenDNS sends failed requests be default to a search page full of ads... Google appears to not be monetizing this.
Google Analytics falls into the same category. You're not paying currency to use the service; you're paying with your metrics. When you think about it in terms of scale, this is way worse. Google is great at taking this data and using it to generate revenue in a number of other ways. Any smart advertiser who uses Google Adwords to buy traffic knows to stay away from Google Analytics. Why would you let the company you're buying traffic from know how that traffic behaves?
The DNS project takes this a step further by giving Google a world of new data. Now you don't have to use Google or be on a site with Google Analytics for Google to know where you're going.
Seems harmless, but I bet they can't wait for this to be adopted by the masses.
With all that being said, 8.8.8.8 is a damn cool IP address and I'm sure my Google-powered Droid already uses it. /rant
I'm perfectly happy to have my DNS data be collected (which I assume my ISP is already collecting) in exchange for ad-free, fast name resolution. Plus, now I don't ever need to look up a DNS server again, Google's is 8.8.8.8. Sweet.
EDIT: looks like Google's not collecting so much information anyway. http://code.google.com/speed/public-dns/privacy.html
My DNS servers have been 4.2.2.[1-4] for a long time. They aren't that hard to remember.
Anyone know why?
Just a wild guess. I can't remember off the top of my head if nslookup or dig, when specifying an alternate server, use TCP or UDP. But, if it uses TCP for those, then it's possible that your ISP is blocking UDP DNS traffic that's not destined for their DNS servers. It wouldn't be the first time.
The only data analysis that would benefit from keeping identifying information would be to create a model for how users go about the internet, and google already has some very good models of that. This is just conjecture, but I would assume that being able to create geographic based models is far more useful than per-user models, which is something they keep.
One thing I like about Google is that they research and share infrastructure technologies. Why is there any reason to think that they would not be interested in improving DNS if it makes the Internet a better place for applications?
They would likely benefit if more applications are moved to the Internet but that does not make this an "evil" or deceptive tactic. What other company today would improve an Internet protocol or create a new protocol (Wave) and release it openly in an effort to move the Internet forward?
Sure you need to be mindful of how data is used and the services you sign up for but that applies to any service, including OpenDNS.
davidu,
You have excellent points but you could have made them without bashing your competitor.
This response makes me think that you are afraid of your competition and using fear to convince people to use OpenDNS.
Is the fear justified? Is it plausible enough that people should take it into account when picking a DNS service?
Google's self-interest is a legitimate factor to consider.
Level 3 Google OpenDNS
lifehacker.com 21 22 19
facebook.com 20 22 19
manu-j.com 21 44 42
reddit.com 30 73 20
tb4.fr 125 22 157
bbc.co.uk 103 22 98
The IP's used are 4.2.2.2, 8.8.8.8, and 208.67.222.222, respectively.Using the script provided here: http://www.manu-j.com/blog/opendns-alternative-google-dns-ro...
Level 3 lifehacker.com 29ms
Google lifehacker.com 20ms
OpenDNS lifehacker.com 15ms
Level 3 facebook.com 94ms
Google facebook.com 20ms
OpenDNS facebook.com 18ms
Level 3 manu-j.com 32ms
Google manu-j.com 46ms
OpenDNS manu-j.com 14ms
Level 3 reddit.com 30ms
Google reddit.com 22ms
OpenDNS reddit.com 16ms
Level 3 tb4.fr 100ms
Google tb4.fr 21ms
OpenDNS tb4.fr 14ms
Level 3 bbc.co.uk 132ms
Google bbc.co.uk 21ms
OpenDNS bbc.co.uk 15ms
Nottinghamshire, UK. OpenDNS a clear winner… Level 3 lifehacker.com 355 msec
Google lifehacker.com 37 msec
OpenDNS lifehacker.com 30 msec
Level 3 facebook.com 46 msec
Google facebook.com 40 msec
OpenDNS facebook.com 32 msec
Level 3 manu-j.com 196 msec
Google manu-j.com 37 msec
OpenDNS manu-j.com 32 msec
Level 3 reddit.com 44 msec
Google reddit.com 60 msec
OpenDNS reddit.com 29 msec
Level 3 tb4.fr 89 msec
Google tb4.fr 36 msec
OpenDNS tb4.fr 31 msec
Level 3 bbc.co.uk 47 msec
Google bbc.co.uk 37 msec
OpenDNS bbc.co.uk 30 msec
OpenDNS wins $ dig tb4.fr @208.67.222.222 | grep Query
;; Query time: 274 msec
$ dig tb4.fr @208.67.222.222 | grep Query
;; Query time: 9 msec
$ dig tb4.fr @208.67.222.222 | grep Query
;; Query time: 9 msec
$ dig tb4.fr @208.67.222.222 | grep Query
;; Query time: 36 msec
Also, query time only tells you how long the server took to respond, and doesn't include network latency.Given that the differences in query time between various DNS solutions are significant but minor, you will almost certainly find differences in performance that you hadn't thought about.
Level 3 Google OpenDNS
lifehacker.com 35 29 26
facebook.com 31 45 18
manu-j.com 30 41 38
reddit.com 42 350 17
tb4.fr 36 22 25
bbc.co.uk 45 39 26
OpenDNS has servers here in London, so they put up a fairly good showing. And obviously there's some jitter - the 350ms reddit result is an anomaly - but a few other runs turned up 216ms and 378ms - must be something odd about it.You could calculate it across a lot of domains, or calculate it with a lot of checks to one server.
Telephone support from Google? At first I thought this might be some kind of joke, but I then called and it's just automated help.
4.2.2.1... 4.2.2.6 (or thereabouts). Not sure what Google's going to have on those. Are they gonna be even more super-duper-fast? I mean, if you look at the line-up of the best DNS servers out there, they're pretty damn fast already:
http://www.dslreports.com/forum/r19982548-DNS-Fastest-DNS-Se...
Also, for what it's worth, I've never quite understood why you'd use OpenDNS when level3 have open DNS servers that don't redirect you to their own pages when there's a missing record...
Trendiness, that's what
~% whois 4.2.2.1
OrgName: Level 3 Communications, Inc.
OrgID: LVLT
Address: 1025 Eldorado Blvd.
City: Broomfield
StateProv: CO
PostalCode: 80021
Country: US
NetRange: 4.0.0.0 - 4.255.255.255
CIDR: 4.0.0.0/8
NetName: LVLT-ORG-4-8
NetHandle: NET-4-0-0-0-1
Parent:
NetType: Direct Allocation
NameServer: NS1.LEVEL3.NET
NameServer: NS2.LEVEL3.NET
Comment:
RegDate: 1992-12-01
Updated: 2009-06-19 2.2.2.4.in-addr.arpa domain name pointer vnsc-bak.sys.gtei.net.
Even though the IP space hasn't been SWIP'd to GTE/Verizon, the server(s) behind that IP are evidently theirs.Quote from "What we log": "In the permanent logs, we don't keep personally identifiable information or IP information. We do keep some location information (at the city/metro level) so that we can conduct debugging, analyze abuse phenomena and improve the Google Public DNS prefetching feature. We don't correlate or combine your information from these logs with any other log data that Google might have about your use of other services, such as data from Web Search and data from advertising on the Google content network. After keeping this data for two weeks, we randomly sample a small subset for permanent storage."
Even if without any reference to the user that actually visited those sites, mantaining information about the "cluster" of urls visited during a browsing session could form a useful source of data not only to optimize ads and searches, the most obvious use could be build something like a recommendation engine (something that some kind of internet users could like, but i admit that something like this could be useless from the google point of view).
http://code.google.com/speed/public-dns/privacy.html
In other words, your comment is anti-Google FUD.
In order to stop them from doing that their change would have to be a clear criminal violation of something. Nobody would be able to sue them, and even getting them in a clear criminal violation would be tough (in the US anyway; recall the debacle of v. Microsoft).
E.g.: Assuming your physical location is in Asia/Europe, and let's say you use Open DNS, IP anycast will map you to their London DNS servers (Last I checked that's the only location outside of N. America OPEN DNS has servers). Let's say the website you visit is delivered by a CDN, this CDN's servers in London will deliver content to you even though there might be CDN servers in your ISP.
The drawback is that you'll often lose a few ms to refreshing your cache, which will cause popular-but-non-CDN content to be slightly slower.
Then again, they are Google, so who knows what they could get if they asked...
I'm also curious who Halliburton merged with in order to get the entire 34 block. Surely they weren't around at the time those were handed out so foolishly.
The DNS service is probably hosted by Level 3.
(It's interesting because 4.2.2.[1-4] are run by Level3)
What I meant by Level3 hosting it is... Level3 is likely the single ISP in front of this service. I don't think Google can get away with multihoming this, other ISPs are just going to push 8.8.8.8 packets to Level3. I don't know how routing tables work, but I don't think they can reliably advertise ownership of the 8.8.8.* block considering it is wholly contained by another block.
So this is why I said, in my original post, that Level3 is the home of Google's DNS service. If routers are respecting Google's own advertisement, it has to somehow be done with the permission of Level3.
http://www.ris.ripe.net/cgi-bin/lg/index.cgi?rrc=RRC001&...
They're advertising 8.8.8.0/24, while Level3's route is 8.0.0.0/8 - the more specific route wins.
Google is effectively a tier 1 ISP now, so buying transit off Level3 for those blocks would be a lot more costly than routing them themselves.
Interestingly, if you can advertise a sub-block and override the bigger block's advertisement, what's stopping people from just stealing sub-blocks from ISPs?
The thief has to either be upstream of your connection, or peered at an extremely high level with others trusting their BGP advertisements. There was a hilarious incident not that long ago where the Pakistanis accidentally blackholed YouTube's IP-block globally (instead of just within the country).
The results posted are from India
How are the results from inside US ?
Google Public DNS complies with the DNS standards and gives the user the exact response his or her computer expects without performing any blocking, filtering, or redirection that may hamper a user's browsing experience.
If you use Google's DNS service, because Google has your client IP, they can serve your content the fastest from the closest POP, however by using this DNS service you are actually creating an issue called "resolver proximity" for every CDN on the planet. This will be especially evident to those of you not in North America who unwittingly point to these servers.
In most global markets your best strategy is to use your local DNS resolver so the people who deliver everything from Netflix, iTunes, Hulu, ustream, (etc, etc, etc) understand that you're not in San Jose or Northern Virginia but really in Tokyo or Malaysia. If your ISP uses a DNS server that's "far" away from you (in terms of network latency) you should complain loudly.
Even solely for the fact they are so easy to remember I bet this are going to be the most used DNS resolvers in the world in a few months.
I doubt it. I suspect a good 90% (or even more) of regular users just use the DNS servers provided to them by their ISPs when their connections come up.
Sure doesn't make DNS hijacking right, though.
<i>Disclaimer: Work for Google.</i>
A Quick comparison with OpenDNS (shameless plug) http://chanux.tumblr.com/post/267873772/googledns-vs-opendns
>> Is Google Public DNS based on open source software, such as BIND?
>> No. Google Public DNS is Google's own implementation of the DNS standards
I think I'm behind a restricted proxy or something (on some hotel WiFi), because it's not really working for me, but I'd be interested to hear others' results.
Compare to Level3's 4.2.2.2-3 and OpenDNS's 208.67.222.222 and 208.67.220.220 (they really need a more memorable IP). Any other good ones?
Mean response (in milliseconds):
--------------------------------
SBC/AT&T Global- ########### 45.11
OpenDNS-2 ############# 56.75
OpenDNS ################ 66.40
8.8.4.4 ################# 70.29
4.2.2.3 ###################### 96.20
UltraDNS-2 ######################## 104.35
UltraDNS ######################## 104.68
Level 3-2 ######################### 106.95
SYS-67.207.128.5 ########################### 114.93
SYS-67.207.128.4 ###################################################### 231.97(Level 3's DNS servers were slightly faster than Google's for me)
It has a list of several public DNS servers.
Complaining that a search engine collects information seems crazy: surely that is a sign of a good company. The important thing is choice/competition. Google is a good competitor, whether you like them or not.
I'm glad they've worked on this, but I think I'll stick with DNS as it was intended to be.
In general, the distributed aspect of DNS was to reduce latency and network traffic. While this might not keep network traffic within your ISP's internal network, it can severely reduce latency even if you're on a large ISP like Comcast/Qwest/TimeWarner. My only guess as to why this appears to be true, is that most ISPs don't really give a crap about their DNS servers just so long as it's still running and hasn't imploded.
It's not like ISPs have ever needed an excuse to try and 'cut costs' by skimping on services. The difference is a greater majority of their customers use DNS than USENET.
Small ISPs are merely resellers; if their DSL customers f'rinstance use Google's DNS servers instead of the ISPs, the ISP actually has less network traffic coming into their racks. Plus, they no longer have to admin a DNS server.
For larger ISPs, it may still be less trouble to just let their customers use Google's DNS instead.
dhcp-107:~ 66% host -t ptr 8.8.8.8.in-addr.arpa
8.8.8.8.in-addr.arpa domain name pointer any-in-0808.1e100.net.
dhcp-107:~ 67% host -t ptr 4.4.8.8.in-addr.arpa
Host 4.4.8.8.in-addr.arpa not found: 3(NXDOMAIN)Wow!
Nervous :(
(Disclaimer - I'm a Google employee, I didn't work on this and my opinions are my own.)
I wouldn't say OpenDNS is evil. Offering an ad-supported free service is how many things are allowed to continue existing.
Avoid OpenDNS and IPS's that do this.
I couldn't get the ISP to budge and the client didn't want to change ISPs, so I ended up setting everybody up on some public SBC DNS servers I know about.
With all respect due to davidu, this "functionality" in OpenDNS has caused me to feel a raging hatred for it every time its name is mentioned.
Another worrying thing I noticed the other day is that they have a "feature" which injects an HTML header into the page you're requesting if you are approaching your bandwidth limit.
We all know that our ISPs are inspecting our packets, but it's a little disconcerting to see the pages you request manipulated in such a wholesale fashion.
Still, users having choice and forcing businesses to compete to win is good for end users and I support that 100%.
Not DNS redirection.
DNS redirection affects ALL programs that are trying to access a network address (obviously unless directly by IP). So when my Jabber/XMPP client tries to contact doesnotexist.example.com, being redirected to an advertisement page doesn't help me very much, does it?
Google Toolbar and Google Chrome defaulting to Google as a 'landing page' of sorts only affects your web experience and only when using those pieces of software. This is a far cry from Comcast's DNS servers resolving ALL DNS traffic that should return 'does not exist' to their advert-filled web servers.
If a DNS server presents an IP so you can show people a web page ( like Verisign did intentionally a few years ago [1]) instead of returning 'no such domain' (NXDOMAIN), you break DNS for all apps that expect a host that's not registered to not resolve. Verisign's screwup lasted 20 days.
I doubt Google would do this.
If google decided to do something evil. ISP can easily redirect port 53 udp/tcp traffic to their own servers.