https://i.pinimg.com/originals/c0/fd/c8/c0fdc8612e07d7562b25...
112 karma · joined August 4, 2016
https://i.pinimg.com/originals/c0/fd/c8/c0fdc8612e07d7562b25...
In the short term, of course, donations to the legal defense fund always help:
https://www.quad9.net/news/blog/sony-s-legal-attack-on-quad9...
Thanks.
Quad9 is special in that it's the only recursive resolver of any size that's not headquartered in the jurisdiction of the Northern District of California federal courts. All three others of the "big four" are, and Quad9 was until it moved to Switzerland so as to be bound by criminal privacy law, and to get out from under USG data-collection requirements.
But Quad9 is _not_ the only one being attacked by Sony. Sony has already won against Cloudflare in other venues, but that's a much easier target.
https://www.musicbusinessworldwide.com/italian-court-orders-...
https://dimitrology.com/cloudflare-wants-to-eliminate-moot-p...
Quad9 doesn't sell hosting services to pirate sites, so has no connection with the alleged infringers. Which is the point of all this. Quad9 is being attacked _because_ it has no relationship with infringing parties. If Sony can establish a precedent that Quad9 can be forced to censor, then that precedent is, in principle, applicable to all parties. Firewall manufacturers. Operating system publishers. Wifi hotspot manufacturers. Open-source software authors. Etc.
But Quad9 moved from that same jurisdiction in Northern California to Switzerland, and three days later, Sony attacked. Because of something called the Lugano Convention.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
The Lugano Convention is a spectacularly ill-conceived treaty that allows plaintiffs to go jurisdiction-shopping in _any_ signatory country, even though it has no connection to either plaintiff or defendant, and then have the judgment enforced in _all_ signatory countries, even if it contradicts the national laws of those countries.
Unfortunately, Switzerland is a Lugano Convention signatory, as it Germany. So although Swiss law is clear that Quad9 is in the right, and that was actually just tested and upheld by the Swiss supreme court a couple of years ago, that doesn't matter, because the Lugano Convention takes precedence over national law.
Which is why people tend to get pretty upset about these kinds of treaties. The Trans-Pacific Partnership (TPP) was a similar sort of deal, which the US did _not_ sign, since it was so widely protested.
https://en.wikipedia.org/wiki/Trans-Pacific_Partnership
But, to get back to your specific question, if Quad9 were to just ignore this, Sony would go back to the court in Germany, and get some sort of finding that Quad9 was maliciously failing to comply, it would get damages, and it would request Swiss law enforcement to extract those damages from Quad9. Swiss law would not be able to protect Quad9, and Swiss LE would be obligated to act on Sony's behalf. At that point, Quad9 could only continue to exist by relocating its headquarters to a non-Lugano-Convention signatory country. When we evaluated national legal regimes for privacy protection, Switzerland was best, the Netherlands second-best, and Iceland third-best... All three are Lugano signatories, unfortunately. I'm not sure where we'd wind up, but it would be a huge blow for privacy.
A few additional notes:
- You should keep what's un-politically-correctly generally referred to as a "hidden master" for your zone data on a machine that's somewhere that won't be targeted by a DDoS that's aimed at you or your ISP, and have an ACL that only permits zone transfers to your authorized secondary authoritative servers.
- You should probably get a few other organizations to act as public-facing authoritative servers for you, so all your authoritatives don't share any avoidable common failure modes. Different people administering them, different technology stacks on different hardware in different places.
- For servers you run, consider running DNSdist in front of them. It's a DNS load balancer which has very efficient internal caching, and which will allow you to answer a lot more queries per core than a full-fledged nameserver would. Run it in front, even on the same machine, to get more bang for your buck.
- A high TTL will indeed help a lot with DDoS against your nameservers (since everyone will cache answers rather than being dependent on getting a live connection to your nameservers. But it will also make you less nimble in responding to a DDoS against your actual content servers, since you won't be able to move them quickly to a different provider. I tend to favor high TTLs, but reasonable people support both sides of that argument.
https://media.defcon.org/DEF%20CON%2029/DEF%20CON%2029%20vid...
For now, there's the filing of objection in the Hamburg court, then the appeal to a superior court... There are many steps here, and the first have barely been taken.
None of us will be traveling to Germany until this is settled.
https://quad9.net/service/privacy
"Quad9 commits to obey the law in any country in which it operates. Therefore, it will only operate in countries with a rule of law compatible with Quad9's ethics and moral duty to protect users. If a government were to use national law to attempt to force Quad9 to act in a way that would harm users (such as collecting information that might de-anonymize an at-risk individual), Quad9 would withdraw from operations in that country. This does not mean users within that country would be prevented from using the Quad9 service (unless the country itself prevented them); the service will operate from locations in nearby countries."
https://www.reuters.com/article/swisscom-court-idUSFWN20M0KT
We'll see what happens.
We'll see what happens once the dust settles.
But more to the point, although the Swiss courts will happily tell Hamburg to get stuffed, that would leave the precedent standing, for application against literally anyone in the EU.