:-)
Edit: Here it is: http://blog.opendns.com/2009/12/03/opendns-google-dns/
:-)
Edit: Here it is: http://blog.opendns.com/2009/12/03/opendns-google-dns/
davidu,
You have excellent points but you could have made them without bashing your competitor.
This response makes me think that you are afraid of your competition and using fear to convince people to use OpenDNS.
Is the fear justified? Is it plausible enough that people should take it into account when picking a DNS service?
Google's self-interest is a legitimate factor to consider.
Not mentioned was OpenDNS sends failed requests be default to a search page full of ads... Google appears to not be monetizing this.
Google Analytics falls into the same category. You're not paying currency to use the service; you're paying with your metrics. When you think about it in terms of scale, this is way worse. Google is great at taking this data and using it to generate revenue in a number of other ways. Any smart advertiser who uses Google Adwords to buy traffic knows to stay away from Google Analytics. Why would you let the company you're buying traffic from know how that traffic behaves?
The DNS project takes this a step further by giving Google a world of new data. Now you don't have to use Google or be on a site with Google Analytics for Google to know where you're going.
Seems harmless, but I bet they can't wait for this to be adopted by the masses.
With all that being said, 8.8.8.8 is a damn cool IP address and I'm sure my Google-powered Droid already uses it. /rant
I'm perfectly happy to have my DNS data be collected (which I assume my ISP is already collecting) in exchange for ad-free, fast name resolution. Plus, now I don't ever need to look up a DNS server again, Google's is 8.8.8.8. Sweet.
EDIT: looks like Google's not collecting so much information anyway. http://code.google.com/speed/public-dns/privacy.html
My DNS servers have been 4.2.2.[1-4] for a long time. They aren't that hard to remember.
Anyone know why?
Just a wild guess. I can't remember off the top of my head if nslookup or dig, when specifying an alternate server, use TCP or UDP. But, if it uses TCP for those, then it's possible that your ISP is blocking UDP DNS traffic that's not destined for their DNS servers. It wouldn't be the first time.
The only data analysis that would benefit from keeping identifying information would be to create a model for how users go about the internet, and google already has some very good models of that. This is just conjecture, but I would assume that being able to create geographic based models is far more useful than per-user models, which is something they keep.
One thing I like about Google is that they research and share infrastructure technologies. Why is there any reason to think that they would not be interested in improving DNS if it makes the Internet a better place for applications?
They would likely benefit if more applications are moved to the Internet but that does not make this an "evil" or deceptive tactic. What other company today would improve an Internet protocol or create a new protocol (Wave) and release it openly in an effort to move the Internet forward?
Sure you need to be mindful of how data is used and the services you sign up for but that applies to any service, including OpenDNS.
OpenDNS: It's neither 'open' nor DNS!
[bcl@lister tmp]$ dig www.google.com
; <<>> DiG 9.6.1-P2-RedHat-9.6.1-7.P2.fc11 <<>> www.google.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33790
;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.google.com. IN A
;; ANSWER SECTION:
www.google.com. 603958 IN CNAME www.l.google.com.
www.l.google.com. 300 IN A 74.125.53.106
www.l.google.com. 300 IN A 74.125.53.103
www.l.google.com. 300 IN A 74.125.53.147
www.l.google.com. 300 IN A 74.125.53.105
www.l.google.com. 300 IN A 74.125.53.99
www.l.google.com. 300 IN A 74.125.53.104
;; Query time: 52 msec
;; SERVER: 192.168.101.20#53(192.168.101.20)
;; WHEN: Thu Dec 3 16:44:24 2009
;; MSG SIZE rcvd: 148
Here is what opendns serves up: [bcl@lister tmp]$ dig www.google.com @208.67.222.222
; <<>> DiG 9.6.1-P2-RedHat-9.6.1-7.P2.fc11 <<>> www.google.com @208.67.222.222
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54658
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.google.com. IN A
;; ANSWER SECTION:
www.google.com. 30 IN CNAME google.navigation.opendns.com.
google.navigation.opendns.com. 30 IN A 208.67.216.230
google.navigation.opendns.com. 30 IN A 208.67.216.231
;; Query time: 26 msec
;; SERVER: 208.67.222.222#53(208.67.222.222)
;; WHEN: Thu Dec 3 16:47:25 2009
;; MSG SIZE rcvd: 104
All your queries are belong to us.At the top of the page, he shows the exact text that appears on the "horrible" search results page. That text explains exactly how to remove that functionality:
"This program can be uninstalled from the Control Panel "Add/Remove Programs" in Windows XP or "Control Panel > Program > Programs and Features" in Windows Vista. Look for the application named "Browser Address Error Redirector". Older versions may be called "GoogleAFE" or "URL Assistant"."
He says this statement is "ambiguous". I have no idea how it is ambiguous, but ok. He then goes on to say the software is "hard to remove", and later that "users can't get rid of it!", both of which are outright lies. Installing and uninstalling software is a normal part of owning a computer, and as you can see above, Google's message tells users exactly what to uninstall. The entire process could be completed in 30 seconds.
But I have to ask myself every time I read this article: why is this guy going to so much effort to spread inaccuracies that demonize Google for trapping search results and presenting ads?
Well, because that is exactly how OpenDNS makes money, and Google threatened their business model. The entire first portion of the post, attacks and all, is present to justify this:
"we’ve stretched a bit beyond DNS itself to work around Google’s mis-directed efforts."
By going on the offensive, he now tries to justify providing a DNS service that OpeDNS doesn't just resolve hostnames anymore...instead, OpenDNS makes moral judgments about the domains you visit, and, as they trumpet so loudly, "we have a fix which does not require more client software". What this means to me is that whatever OpenDNS is doing, I can't uninstall it, because they own it -- it's not on my machine, it's on theirs.
Listen, when I use DNS, there's a contract I expect DNS to fulfill: I give you a name, and you resolve it to an IP or tell me it can't be resolved. It is an outright violation of the contract to resolve a hostname I give you to an address other than that with which it is associated, which is exactly what OpenDNS is doing.
I don't own a Dell or run with any toolbars. I would find the "Browser Address Error Redirector" and remove it if I faced that warped experience.
So for me, this unrequested proxying isn't help, it's collateral damage from two competing typosquatters/querysquatters each trying to one-up the other.
A harder, but classier, way for OpenDNS to escalate their battle with Google would have been to offer a different set of DNS server IP addresses for customers who may want OpenDNS to trump Google/Dell.
ns[1-4].everydns.net, the first thing I do to a domain name that comes under my control.
I think it’s a little naive to think it is a good thing for you. How are you going to compete with Google’s infrastructure and get your response times down to Google DNS’? I would expect many people will switch away as I just have until you can roll out an extremely expensive upgrade.
Update: I approved your comment.
Learn something new every day.
And so does every other DNS provider so long as the pages are public and if your ISP is your DNS provider then they can directly sniff your (non-encrypted) traffic too.
Not sure if their privacy policy lets them exercise their power fully in this field, though.
(i.e. If I go to sws.example.com which hosts a Secret Warez Stash, unless it's password-protected everyone has access to it, not just Google.)
But now you're adding yet another party in the mix -- Google, who already have a lot of information about your interests and habits. At the very very least, you're inviting an interested third party to have a look at your traffic.
Most of davidu's response was kind of a waste of time, but the one thing that made an impression on me was when he referred to Google as an advertising company. He's right; they're the most technologically advanced advertising company in the world.
So if this conversation was about "an unnamed technologically savvy advertising company", instead of Google, would you still be interested in giving them your DNS traffic?
So... you're saying that reputation counts for nothing? Google sort of evolved into an advertising company because of the position that they held as the most popular search engine.
Most advertising companies are companies that started out trying to be an advertising company. Most of them probably had to be cut-throat to make it out of obscurity.
This isn't to say that anyone should place blind trust in Google, but if -- as you're implying -- reputation counts for nothing, then what's the point in trying to maintain a reputation at all?
See my other reply in this thread too. You completely misinterpreted my post (or just used it as a soapbox to insert your views into the discussion). The post I was replying too said nothing about Google pulling all the information on you together. The poster seemed to be irked that your DNS provider also had access to the content of the pages you were using DNS lookups to view. I was pointing out that this is true of any DNS provider.
Google does not have a spotless track record in customer privacy issues, nor is there any reason to believe that because they're behaving in a particular way now, they'll behave the same later.
It's as simple as this: while I'm a fan of most of Google's products and services, I also think there's a point at which it's no longer smart to put all of your eggs into one internet company's basket, and I think we've reached that point.
True, but most of the records are deleted after 48 hours, meaning that they no longer exist for Google to decide to mine years later once they change their policy. Other than that, this only becomes an issue if the entire internet starts pointing their DNS queries at GoogleDNS, which I doubt will happen.