5 out of 7 .io nameservers appear to be down
pulse.turbobytes.com
pulse.turbobytes.com
"The rights for selling .io domains are held by a British company called Internet Computer Bureau (ICB), [...] The British government granted these rights to ICB chief Paul Kane back in the 1990s. ICB gets to run .io “more or less indefinitely, unless we make a technical mistake,” Kane told me. (ICB has so far run a stable .io namespace. It should be noted that Kane is a respected veteran of the infrastructure scene, and has been entrusted by ICANN with one of the 7 so-called “keys to the internet”.)"
Ooops...
The reason there are multiple DNS servers is in case one/some of them have problems. There are two other root servers for the .io. zone that are apparently functioning just fine. That means the overall system is working as intended, no?
Also, I don't think we know (yet) why five of the seven are down. If it turns out to be some "amateur hour" mistake then, sure, I could see it being used against ICB. If, however, the underlying issue is/was out of their control, then why should they be penalized?
ETA: It appears that the name servers are actually "up". They respond to ICMP echo requests but aren't answering queries:
$ ping -q -c 5 a.nic.io
PING a.nic.io (64.251.31.179): 56 data bytes
--- a.nic.io ping statistics ---
5 packets transmitted, 5 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 45.123/45.283/45.453/0.106 ms
$ dig ns docker.io @a.nic.io
; <<>> DiG 9.10.2 <<>> ns docker.io @a.nic.io
;; global options: +cmd
;; connection timed out; no servers could be reachedI've watched other companies do far worse.
The primary roles are the cryptographic officers, these are Internet community members who attend key signing ceremonies to observe use of the KSK.
Here are a list of the trusted community representatives: https://www.iana.org/dnssec/tcrs
While I realize those key signing ceremonies are probably just a bunch of people sitting around playing games on their phones, waiting around for their turn to give their keys to someone who's typing in all of the appropriate commands, I want to believe they're in some sort of dungeon, wearing black, hooded robes and chanting Gregorian chants while doing it.
I dunno, maybe I'm just weird.
Here's a good article about the ceremony itself: http://www.theguardian.com/technology/2014/feb/28/seven-peop...
https://gigaom.com/2014/06/30/the-dark-side-of-io-how-the-u-...
$ dig ns io @b.nic.ac +short
; <<>> DiG 9.8.3-P1 <<>> ns io @b.nic.ac +short
;; global options: +cmd
;; connection timed out; no servers could be reached
$ dig ns io @b.nic.ac +short +norec
b.ns13.net.
[... extracted for brevity]
ns3.icb.co.uk.But .. IIRC if RD is set when quering a non-recursive, it should respond normally with authoritative response Recursion Available (RA) flag unset. It does not mean it should drop the query totally.
That's ironic.
"The internet doesn't need another reddit, it's bad enough as it is."
Yet you insist on making comments that only belong on reddit. Can I convince you to delete your account?
Fully available on youtube, about 1h long: https://www.youtube.com/watch?v=0zhGvId4fcc
It seems that now also startup companies are (unwillingly, I presume) contributing to this lasting injustice.
Servers configured to be a source of truth are called "authoritative name servers".
There is no technical distinction between "TLDs" and "domains", they are all just domains, they are just different levels of the DNS hierarchy.
It looks like they do have multiple upstreams, though.
The latter downtimes look planned, as they are for exact periods (1 minute 0 seconds, 1 minute 30 seconds, 2 minutes 30 seconds, etc)
Here's an extract from the log with timing incase anyone's interested: https://gist.github.com/anonymous/ed37826bc66c23d6c791
Unless your monitor is attempting a connection every, e.g., one second, you're going to end up with the "exact periods" you describe (i.e., presumably your monitor is only attempting to connect once every 30s).
Also, this would be more indicative of a problem with your web host, not the .io root name servers, assuming the TTLs on your RRs are set to > 30s.
i would welcome better proposals, too.
But that doesn't make them "run by a country". .us is not run by the US government. It is run by Neustar. There is not something that says Neustar won't have poorly available/slow name servers, beyond that same statement that the .io people said.
The good of domains like .CC: * Your desired domain name likely to be more available than .COM/.NET/.ORG. * If a tech-centric business, your clients might think of you as edgy and non-conventional. * Some domains like .CC have one less character to type - ok, so its a small benefit. ;-)
The bad of domains like .CC: * Many non-tech folks still think there are only 3 or 4 TLDs in the world...so you have to specificy something like: "It's .CC not .COM"...and they usually respond with "Huh??" Its funny, in all the years I've had my domain, the only reason I've not received email is because of folks mis-typing ".COM" instaed of .CC. * Filling out forms on websites whose devs mistakenly assume - since your address does not end in .COM/.NET/.ORG - that it must be an "invalid email address". Though this occurs very, very rarely now-adays.