Post by @jwildeboer@social.wildeboer.net

Dr. Christopher Kunz
@christopherkunz @chaos.social

@jwildeboer Here's hoping that the operators of @riseup are listening closely, since .net (as in riseup.net) is operated by VeriSign, AFAIK.

FediThing :progress_pride:
@FediThing @chinwag.org
Unlisted en edited

@jwildeboer Are ccTLDs safe from this?

Trump burning yet more bridges, even less reason to trust US-based infrastructure.

Jan Wildeboer ๐Ÿ˜ท:krulorange:
@jwildeboer @social.wildeboer.net
Unlisted en edited

@FediThing No. But TLDs that are not owned by registrars in the US might be a bit more resilient to such unlisting demands. Ultimately though, DNS is centralised under ICANN, which is in the US.

FediThing :progress_pride:
@FediThing @chinwag.org

@jwildeboer Geez ๐Ÿ˜ž If they continue pulling plugs on foreign sites that have done nothing wrong, it's going to call into question the entire domain name system. Could we start using just IP numbers? ๐Ÿค”

Jan Wildeboer ๐Ÿ˜ท:krulorange:
@jwildeboer @social.wildeboer.net

@FediThing I for one have moved to mainly booking .eu domains through a provider in Belgium that runs its own DNS servers in Europe. That's not a complete protection, but it does give me more resilience.

@jwildeboer @FediThing Wouldnโ€™t it be nice to add interesting IP numbers and DNS names to a curated list which you can choose to add to your hosts file?

Mourioche โš
@Mourioche @mastodon.social

@FediThing @jwildeboer I suppose that you can have your own DNS ? ๐Ÿค”

Jan Wildeboer ๐Ÿ˜ท:krulorange:
@jwildeboer @social.wildeboer.net

@Mourioche That already exists since many years, the alt-root movement. But that has always stayed a niche thing. en.wikipedia.org/wiki/Alternat @FediThing

Wilfried Klaebe
@wonka @chaos.social

And DNSSEC works with exactly one root.

@jwildeboer @Mourioche @FediThing

@jwildeboer on what grounds was this done? registries typically don't do this for political reasons; the normal reasons would be for domains used for criminal activity.

Replying to @ralf@fedi.jrlenz.net
TrueNorthSpice ๐Ÿ‡จ๐Ÿ‡ฆ
@TrueNorthSpice @mastodon.world

@ralf
We need to stop thinking about "normal" and "reasons why" because we are not dealing with normal minds or reasonable people.

@jwildeboer

@TrueNorthSpice @jwildeboer

Agreed, we are not. However, there are situations in which something like this can be contested, which is why I asked what their "justification" was.

Domain suspension is typically a last resort for addressing cybercrime, cutting off hardcoded c&c being an example.

Even TPB's .org suspension didn't last indefinitely.

Replying to @ralf@fedi.jrlenz.net
TrueNorthSpice ๐Ÿ‡จ๐Ÿ‡ฆ
@TrueNorthSpice @mastodon.world

@ralf @jwildeboer

"be contested"
You're still thinking 'normal"
How effective is contesting anything with an admin that randomly blows up boats, starts illegal wars, kidnaps the leader of another country, threatens to invade its neighbour and tried to crush that neighbour's economy because it want free access to rare minerals.

Please tell me you're joking about pursuing this through legal channels

Jan Wildeboer ๐Ÿ˜ท:krulorange:
@jwildeboer @social.wildeboer.net

@TrueNorthSpice @ralf Please remove my handle from further replies in this subthread, as I don't want to be part of it. Thanks!

TrueNorthSpice ๐Ÿ‡จ๐Ÿ‡ฆ
@TrueNorthSpice @mastodon.world

@jwildeboer @ralf
Of course, consider it done but
you might find it's more effective to mute replies because I have no control over what others do.

Jan Penfrat
@ilumium @eupolicy.social

@jwildeboer I'm new to much of this, so apologies if this is obvious: Where do DNS resolvers get their information from, PIR or Gandi? Could Gandi and supportive DNS resolvers ignore those flags and continue to resolve the domain name?

Jan Wildeboer ๐Ÿ˜ท:krulorange:
@jwildeboer @social.wildeboer.net
Unlisted en edited

@ilumium Ultimately PIR is authoritative on all .org domains. Technically gandi could keep an active entry in their DNS zones, but it would be in violation of the DNS delegation rules. They risk their designated registrar status with such things.

Jan Penfrat
@ilumium @eupolicy.social

@jwildeboer Ah okay that's fair, thank you. Do you know if anyone has formally asked EUrid if they care about the SDN list or would resist pressure? Am a bit worried about their business membership:

eupolicy.social/@ilumium/11720

Jan Penfrat @ilumium@eupolicy.social

TIL that while the .eu TLD registrar #EUrid is technically a non-profit org, it is very much dominated by #business interests.

Would EUrid roll over US #sanctions and block domain names or would they resist? ๐Ÿค”

List of EUrid members including Business Europe, eCommerce Europe, IAB Europe and SME United. With text describing how members have the power to sack the Board etc.
List of EUrid members including Business Europe, eCommerce Europe, IAB Europe and SME United. With text describing how members have the power to sack the Board etc.
Jan Wildeboer ๐Ÿ˜ท:krulorange:
@jwildeboer @social.wildeboer.net

@ilumium I am not aware of any official communication or statement on this and I don't expect there will ever be. The answer will be a variant of "we respect the laws, rules and regulations and will not publicly discuss proceedings". But there are some court rulings that establish a high level of independence, so I am not too worried.

Jan Penfrat
@ilumium @eupolicy.social

@jwildeboer Thank you that's really helpful. ๐Ÿ™

Nemo_bis ๐ŸŒˆ
@nemobis @mamot.fr

@jwildeboer @ilumium One could try a more oblique question, such as "are there contingency plans for [adverse event]", from the more blatant like "being cut off SWIFT" to the more anodyne like "a temporary disruption in payment processing" to the abstract "an erosion of the reserves due to delays in receivables".

(The question is not unreasonable, for example I would make sure to not send staff travelling abroad without a backup payment method off the Visa/Mastercard/etc. circuit.)

Phil Ashby :marmite: ๐Ÿต
@phlash @mastodon.me.uk

@ilumium @jwildeboer
As ever, it depends. Your local DNS service from your ISP most likely does standard recursive resolution starting with one of the 13 root name servers across the globe. This is where a registrar can turn off the top level domain (as in this case). However, the service could use alternate root servers, or hold its own database to respond to you queries, bypassing global controls. We may see such national resolvers appearing if this sort of thing escalates.

Carlos Guerreiro
@carlos @social.perceptiveconstructs.com
@jwildeboer

All your .org are belong to US
decapitae
@decapitae @mastodon.social

@jwildeboer tRumpSSreich regime, should add themselves to the list

Hella
@unixwitch @social.tchncs.de

@jwildeboer
IMHO especially relevant for the #fediverse:

This also can happen to your ".social" domain (and similar), since these are (as far as I know) also managed by US based organisations.

en.wikipedia.org/wiki/Identity

raffaele
@raffaele @digipres.club

@jwildeboer should we talk about LetsEncrypt CA too?

Chris Lombardi
@ChrisAintMarchin @mastodon.social