Post by @jwildeboer@social.wildeboer.net

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net
2026-09-07 DNS Root Server Addresses
Letter IPv4 address IPv6 address Operator Operator origin

A | 198.41.0.4 | 2001:503:ba3e::2:30 | Verisign | United States
B | 170.247.170.2 | 2801:1b8:10::b | usc-Ist | United States
C | 192.33.4.12 | 2001:500:2::c | Cogent Communications | United States
D | 199.7.91.13 | 2001:500:2d::d | University of Maryland | United States
E | 192.203.230 |.10 2001:500:a8::e | NASA Ames Research Center | United States
F | 192.5.5.241 | 2001:500:2f::f | Internet Systems Consortium | United States
G | 192.112.36.4 | 2001:500:12::d0d | Defense Information Systems Agency | United States
H | 198.97.190.53 | 2001:500:1::53 | U.S. Army Research Lab | United States
I | 192.36.148.17 | 2001:7fe::53 | Netnod | Sweden
J | 192.58.128.30 | 2001:503:c27::2:30 | Verisign | United States
K | 193.0.14.129 | 2001:7fd::1 | RIPE NCC | Netherlands
L | 199.7.83.42 | 2001:500:9f::42 | ICANN | United States
M | 202.12.27.33 | 2001:dc3::35 | WIDE Project | Japan
2026-09-07 DNS Root Server Addresses Letter IPv4 address IPv6 address Operator Operator origin A | 198.41.0.4 | 2001:503:ba3e::2:30 | Verisign | United States B | 170.247.170.2 | 2801:1b8:10::b | usc-Ist | United States C | 192.33.4.12 | 2001:500:2::c | Cogent Communications | United States D | 199.7.91.13 | 2001:500:2d::d | University of Maryland | United States E | 192.203.230 |.10 2001:500:a8::e | NASA Ames Research Center | United States F | 192.5.5.241 | 2001:500:2f::f | Internet Systems Consortium | United States G | 192.112.36.4 | 2001:500:12::d0d | Defense Information Systems Agency | United States H | 198.97.190.53 | 2001:500:1::53 | U.S. Army Research Lab | United States I | 192.36.148.17 | 2001:7fe::53 | Netnod | Sweden J | 192.58.128.30 | 2001:503:c27::2:30 | Verisign | United States K | 193.0.14.129 | 2001:7fd::1 | RIPE NCC | Netherlands L | 199.7.83.42 | 2001:500:9f::42 | ICANN | United States M | 202.12.27.33 | 2001:dc3::35 | WIDE Project | Japan

At the core of the global internet are the DNS root servers. These 13 go-to places are at the top of authority when it comes to making sure you can connect to any server with a domain name. What you might not know is that 10 of these 13 root servers are ultimately under US jurisdiction. Should that worry you? I guess not, the current system is quite robust. But I deal in risk assessment and probabilities. And I think this isn't an ideal setup.

en.wikipedia.org/wiki/Root_nam

#DNS #Centralisation

109 likes
Refresh interactions
97 boosts
Patrick Mevzek
@pmevzek @framapiaf.org

@jwildeboer There could be more of them... but they are all feeding themselves out of hidden primary root controlled by Verisign, a US corporation. So at the end, those public ones don't really count. Except if you consider they might, collectively, all decide to use another root than IANA one which is never impossible but quite not the highest probability. (and see previous court cases about .LY yes there were attempts to remove TLDs from root). They also all have relationships with ICANN. 1/x

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@pmevzek It's the other way around. ICANN is the master. And ICANN has so far been quite OK-ish at defending the freedom of The Net. My personal preference would be to have no centralisation at all. But knowing that is impossible in the way DNS works, the next best solution would be to put ICANN under the UN, not the US. One letter, big consequences :)

Patrick Mevzek
@pmevzek @framapiaf.org

@jwildeboer " the next best solution would be to put ICANN under the UN, not the US. " We would have to disagree on that. But there were such attempts in the past. Hence the WSIS, WGIG, IGF, etc. so that idea is 20+ years old and were the major force towards making ICANN less relient on US gov. (breakup from NTIA in 2016). ICANN just houses for now PTI (aka IANA) which technically coordinates. But companies like Verisign have their own specific contracts with US gov.

Patrick Mevzek
@pmevzek @framapiaf.org

@jwildeboer "ICANN is the master.". Technically/theoretically just a technical coordinator implementing policies discussed and decided among all stakeholders (including governments with in theory again all the same power, but also other orgs) :-) Yes, no need to point out the difference between theory and practice and who captures what and how much.

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@pmevzek It's a discussion I'd rather have over a long evening with food and drinks. 500 character messages are limiting. Could there be a more decentralised way for trust establishment? Yes. I think there is. It's what the ICAO (a UN agency) has established for travel documents. Which relies on a bilateral system of agreements, not a centralised one. See ICAO 9303 part 12 icao.int/publications/doc-seri

Patrick Mevzek
@pmevzek @framapiaf.org
Public en edited

@jwildeboer You are comparing something that is relevant only between governments (how they trust each other regarding travel documents) with something that has a public reach and needs a consensus, of not just governments but every single party online (who exactly controls .com or any other TLD?). You could mention as well how most BGP peering are set (over a beer 🙂 ?). But otherwise agree on the fact that the topic is far too broad for a thread here 🙂

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@pmevzek I come from the times where you called someone in Dortmund at the university to add your .de domain in the right way, so yes, I am old and biased. I am also one of those that understand the complexity of reliability where centralisation is the obvious choice and decentralisation is an explosion of questions. Right now we can live reasonably well with centralisation on the DNS level but my risk assessment puts doubts on this. What next? That's the question. No real answers.

Paul_IPv6
@paul_ipv6 @infosec.exchange

@jwildeboer @pmevzek

i think that summarizes well where we are. DNS decentralization is hard and we have more questions and concerns than concrete ways to fix it.

our best and easiest chance to fix this was in the 1980s :)

Carl Malamud
@carlmalamud @official.resource.org

@paul_ipv6 @jwildeboer @pmevzek time travel always the best means to a comprehensive solution.

Christian Huitema
@huitema @social.secret-wg.org

@jwildeboer @pmevzek Few organizations manage their own DNS servers. They contract with companies, mostly big American companies, as shown in this page: ithi.research.icann.org/graph-. (I helped set up that page.)

Paul_IPv6
@paul_ipv6 @infosec.exchange

@huitema @jwildeboer @pmevzek

centralization of folks running outsourced auth servers, web servers, TLS/cert providers, and email is definitely another disturbing choke point in US control of non-US entities.

not only do many companies not have the staff or expertise to do it themselves, the "big folks" make it very hard to not use one of them. email is probably the worst.

i'd had hopes that VMs and "server in a virtual box" might make that trend slow down but it doesn't seem to.

one of the things we'd need to solve for real decentralization is how to enable entities below the big tech level to do more of their own services and have it accepted by big tech.

Christian Huitema
@huitema @social.secret-wg.org

@paul_ipv6 @jwildeboer @pmevzek I think that security, and especially resilience to DoS attacks, is a big driver for concentration. The DNS server that you set in your basement can trivially be taken out by a DoS attack, so instead you contract with Cloudflare.

Paul_IPv6
@paul_ipv6 @infosec.exchange

@huitema @jwildeboer @pmevzek

though the technology is binary, the technology implementations don't need to be.

for much of the world, something local to your town or state would be fine and better than a server in a basement. those folks that need DDoS scrubbing could use more choices than cloudflare. certainly folks that don't trust the US govt would prefer a DDoS service not in thrall to the US govt.

if we all don't want to be forever controlled by a half dozen US corporations, we need to start working on viable alternatives.

Adam Shostack :donor: :rebelverified:
@adamshostack @infosec.exchange

@paul_ipv6

On behalf of the Mastodon HOA, we are concerned about your attempts to gatekeep people from shaming.

It is 100% acceptable to simply say "you should just move" even if the speaker hasn't done any research on where to move to or the desiderata of the proposed alternatives.

Please make a note of it.

@huitema @jwildeboer @pmevzek

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net
Public en edited

@huitema @paul_ipv6 @pmevzek I don’t really get the logic. When my four (2xIPv4, 2xIPv6) DNS servers I’ve configured as next step would fall over due to some attack, I switch to the next set? And for my local basement services I don’t need to reach out to the internet anyway.

@jwildeboer@social.wildeboer.net
Would be interested in your opinion about @aral@mastodon.ar.al 's take in using plain IP addresses instead of domains, via "web numbers"?

https://ar.al/2025/06/25/web-numbers/

@pmevzek@framapiaf.org

Replying to @fasnix
barbra
@barbra @vivaldi.net

@fasnix @jwildeboer @aral @pmevzek

Much easier to share a customised hosts file, with both ipv4 and ipv6 addresses (and add an ipv6 address/name for your home server so others can use it).

Replying to @barbra@vivaldi.net
Aral Balkan
@aral @mastodon.ar.al

@barbra @fasnix @jwildeboer @pmevzek Define “easier” :)

Replying to @aral@mastodon.ar.al
barbra
@barbra @vivaldi.net
Public en edited

@aral @fasnix @jwildeboer @pmevzek

1. Create hosts file (it's just a plain text file)
2. Share it with people you know

Done and done.

Doesn't matter if someone else creates one that conflicts with yours - your friends use yours. Everyone else, what do I care?

Same as blocking gmail. So what if spammers can't reach me? We all have iThingees, FaceTime and iMessage are end to end encrypted as well as encrypted on the server, and anyone who wants to email me can damn well get a paid email account (I lease server space for web hosting and email, so I'm paying for mine, so not being a hypocrite. I don't want my emails going to a Google server, period).

Replying to @barbra@vivaldi.net

@barbra@vivaldi.net
"1. Create hosts file (it's just a plain text file)
2. Share it with people you know"

You assume that everybody knows how to create a hosts file.
I don't.
And your "average internet Joe" assumably doesn't as well.

And what about people I don't know, how should they find my (small-)webspace?
Anyone who I can't share that hosts file directly with?

@aral@mastodon.ar.al @jwildeboer@social.wildeboer.net @pmevzek@framapiaf.org

Replying to @fasnix
barbra
@barbra @vivaldi.net
Public en edited

@fasnix @aral @jwildeboer @pmevzek

1) post a clickable link to the ipv6 address. It's just html, which is just text.

2) for discoverability, word of mouth is good enough. You're not looking for eyeballs or to go viral - just a way to bypass American control of the internet. Better to have a small community than a bunch of spammers, influencer shitposts, griefers, grifters, etc. Easily banned by ip when they start showing up.

Eventually set up an allow list - other ips banned, so no AI scraping. People would need a referral for access. Because YOU DON'T WANT EVERYONE AND THEIR DOG IN YOUR COMMUNITY!

No nazis, no fascists, no MAGA, no marketers, no ads (advertising eventually ruins everything it touches).

Just 10 to 1000 people with a shared interest of hobby.

Replying to @barbra@vivaldi.net
Aral Balkan
@aral @mastodon.ar.al

@barbra @fasnix @jwildeboer @pmevzek Right, so decentralised address books. That’s what I’m saying too.

Paul_IPv6
@paul_ipv6 @infosec.exchange

@jwildeboer @pmevzek

that's a bit strong. ICANN isn't the master. they are the maitre de. everyone running a registry/registrar with a new contract (not the ccTLDs) mostly follows the rules but if there were truly a revolution amongst root server operators or TLD registries, they don't have much recourse.

DNS was originally designed without much thought for politics, rogue states. they solved a lot of technical complexities by having a single coherent root. but that makes real decentralization very hard, if not impossible.

i'd love to see a complete redesign but can't even imagine the chaos and arguments and ridiculously long rollout something else would take.

i'd also much rather see that then then UN trying to take things over. what the UN should be would make sense but the UN hasn't been very effective at most of its charter.

Patrick Mevzek
@pmevzek @framapiaf.org

@jwildeboer But this is indeed also why since 20+ years various countries (China and Russia mostly) claim to work towards independence from that, in one way or another, to have their own "local/national" root. It remains unclear how that is really technically working [I only ever saw ietf.org/archive/id/draft-diao], but there are impacts as well for like which DNSSEC cryptography to use (GOST in Russia, SM2/3 in China, etc.) 2/2

Phil Ashby :marmite: 🍵
@phlash @mastodon.me.uk

@jwildeboer
Is there any research on creating a more federated, byzantine emperor tolerant dns root structure?

See also PKI root certificate lists and who authorises changes to them (Mozilla, Microsoft, Apple and various Linux distros, primarily Debian)...

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@phlash Ah, the root certificates collection. Another point of centralisation. Though mostly focused on browsers, less on operating systems, where (for now) you can add your own root certificates, even on iOS and Android. It's a complex issue. And better solutions come from understanding how the current system works. That's the discussion I hope to fire up :)

warthog9
@warthog9 @social.afront.org

@jwildeboer ISC might be US based technically, but it's not really within the exact jurisdiction the way it works.

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@warthog9 And it's only one of 13 in the root collection.

Dave Neary
@dneary @mastodon.ie

@jwildeboer There are some internationally run & managed recursive DNS resolvers like 9.9.9.9 that I would have confidence in.

Replying to @dneary@mastodon.ie
Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@dneary Do they still resolve autistici.org?

Kevin P. Fleming
@kevin @km6g.us

@jwildeboer @dneary No, recursive revolvers can't resolve anything that the root servers don't tell them about.

Replying to @kevin@km6g.us
Dave Neary
@dneary @mastodon.ie

@kevin @jwildeboer This is true. Root resolvers are king - this is a user-friendly, privacy and security-conscious option instead of 1.1.1.1, 8.8.8.8, or 8.8.4.4. @jwildeboer What is autistici.org?

Replying to @dneary@mastodon.ie
Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@dneary autistici.org was one of the main sites of A/I from Italy. The domain name was deleted from DNS without warning, raising questions about how far the US administration can and will go. See social.wildeboer.net/@jwildebo for more context. @kevin

Jan Wildeboer 😷:krulorange: @jwildeboer@social.wildeboer.net

PIR, the Public Interest Registry ("Based in Reston, Virginia, Public Interest Registry is a nonprofit organization created by the Internet Society to manage the .ORG domain."), seems to have put autistici.org on status serverHold and that is why you cannot resolve their name anymore. This is what can happen to your .org domain name when the Trump administration decides to add you to the OFAC (Office of Foreign Assets Control) list.

ximon18
@ximon18 @fosstodon.org

@jwildeboer While I appreciate that this isn’t your point, and while this is mentioned in the linked Wikipedia article, I just want to clarify that there are far more than 13 servers: “However, enabled by the use of anycast addressing, the actual number of root server instances—1954—is much larger, as of December 5, 2025.[3]”.

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@ximon18 Yes. But the way to reach them goes through the 26 public IPv4 and IPv6 addresses. Anycast and load balancing don't counter the fact that we only have 13 root servers.

Scott D. Strader 😐
@sstrader @masto.ai

@jwildeboer What We Talk About When We Talk About Autistici

AlgoCompSynth 🇺🇦
@AlgoCompSynth @mastodon.social

@jwildeboer Nothing with involvement by the current federal government of the United States of America is an ideal setup. The highest levels of our executive, legislative and judicial branches are occupied by people who are *at best* greedy folks bilking the taxpayers. Look to some states and cities if you seek sanity.

Guilherme Rios
@gasrios @floss.social

@jwildeboer honest question: how much of a difference does it make, in practice, that not all of those servers are under US jurisdiction, when ICANN itself is an organization headquartered in the US, which means it ultimately must abide by the laws of that country, and can be compelled to act by its courts?

Replying to @gasrios@floss.social
Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net
Jan Wildeboer 😷:krulorange: @jwildeboer@social.wildeboer.net
Two astronauts in space meme with one astronaut pointing a gun at the other. Astronaut without a gun: "Wait. All domain names and DNS are ultimately under control of the US through ICANN?" Astronaut with a gun: "Always has been"
Two astronauts in space meme with one astronaut pointing a gun at the other. Astronaut without a gun: "Wait. All domain names and DNS are ultimately under control of the US through ICANN?" Astronaut with a gun: "Always has been"