HNHacker News
TopNewBestAskShowJobs

Habbie

18 karma · joined June 20, 2011

submissionscomments
Habbie··on We Built Our Own DNS Infrastructure
Hey, thanks for the PR, love that!

The wasteful SOA query is a result of our internal code flow. You can reduce wasteful queries a bit with the new `consistent-backends` setting, but the SOA query will remain.

We (no longer) have a knob to disable metadata, but there's a cache that should also remember your empty response (the default value for `domain-metadata-cache-ttl` is 60 seconds).

If you have a SOA for example.com, pdns will never return REFUSED for anything inside example.com. The zone is there, so an answer must be present - either a name with records, a name with no records for that type, or the name does not exist. (The distinction between the latter two is why you mostly see ANY queries instead of the type the client asked for).

As far as I can tell, you should never be returning 'false' to anything, as that indicates failure, which is different than 'I know I do not have what you are asking for'. Think of it like this: your SQL database does not go 'oh no' when it has zero rows for you; it just gives you zero rows. A pdns remote backend should behave the same. If you return 'empty' for those lookups into domains you have nothing for, instead of false, I expect REFUSED will come out instead of SERVFAIL.

(And, if I'm correct in the previous paragraph, your PR is correct too :-) )

Habbie··on We Built Our Own DNS Infrastructure
Hello! PowerDNS developer here. Did you spot https://doc.powerdns.com/authoritative/appendices/internals.... and https://doc.powerdns.com/authoritative/appendices/backend-wr... ?

And if not (or also if you did), can you suggest documentation additions that would have helped you here?

Habbie··on Travis CI is no longer providing CI minutes for open source projects
I can echo all of this - we also pay, we're very happy, the concurrency is nice (I believe they're bumping it to 80x soon - when my coworker asked "but what's the catch" I realised we pay by the CPU minute anyway so higher concurrency is a win for CircleCI -and- for US ;) ).

I've also hacked about the 'merge' problem but it's not entirely satisfying.

That all said, with GH actions currently being entirely free, and doing PRs better than CircleCI, we might shift our focus there.

Habbie··on On Firefox moving DNS to a third party
Can you share the domain name so we can investigate?
Habbie··on Ask HN: Anyone know what this DNS TXT record is?
I bet this was in before the SPF also went in. You should feel free to take this up with IANA, of course :)
Habbie··on Ask HN: Anyone know what this DNS TXT record is?
If you are managing your zone data in RCS or similar, why not expose that information in DNS as well? Could be useful for debugging.

Indeed, on 2015-01-01, it said "$Id: example.com 3280 2014-12-10 00:15:12Z spowell $".

It does not look like a mistake to me.

Habbie··on Show HN: Golang DNS server, including DNSSEC and DNS-over-TLS
Thank you for the kind words! - Peter van Dijk, PowerDNS
Habbie··on Show HN: Golang DNS server, including DNSSEC and DNS-over-TLS
Hello, PowerDNS developer here! Not trying to steal Tenta's thunder here, but you should know that the PowerDNS GeoIP backend can be used without a GeoIP database, in which case it might better be called the 'YAML backend'.

Additionally, if you file a feature request for JSON support in the bindbackend, we might consider it!

Habbie··on Ed25519 for DNSSEC
The .nl registry does not support algo 15 (and 16) for DS records yet. Support is expected soon.
Habbie··on iTerm2: Please disable 'Perform DNS lookups to check if URLs are valid'
You said it right - can help defend. On the other end of your dnscrypt tunnel, the queries will still go out unencrypted. They will just be harder to correlate to you specifically.
Habbie··on DNS Infrastructure at GitHub
PowerDNS developer here - any nits we should know about?
Habbie··on DNS Infrastructure at GitHub
It means that for those zones, they explicitly put the IPs of the edge servers in their resolver (Unbound) configuration, so that lookups of names in those zones don't have to go the root servers and then the TLD (like .com) servers, only to find out that the authority (the edge servers in their design) are in the next rack. Instead they will go directly to those edges. This gives them "Addtionally, public zones are completely resolvable within our network without needing to communicate with our external providers. This means any service that needs to look up api.github.com can do so without needing to rely on external network connectivity."
Habbie··on For DNSSEC
No, not in the narrowest way. You can go 'somewhere in between' at the cost of blowing up your zone size tremendously, but it's not worth it.
Habbie··on For DNSSEC
So have three online signers.
Habbie··on For DNSSEC
I.E. the way SSL/TLS is run today.
Habbie··on For DNSSEC
I don't know of any either, but there are plenty running PowerDNS in online 'white lies' signing mode. And then, of course, there is Cloudflare.

(And indeed, it cannot be done offline - although doing much narrower NSEC/NSEC3 ranges than 'normal' could be done offline).

Habbie··on DuckDuckGo: Escape your search engine filter bubble
Just add !gm to your query. If you do it a few times, DDG will remember it and make it easy to add !gm just by pushing ! to open the dropdown.