The Register® — Biting the hand that feeds IT

Feeds

OpenDNS taunts Google with real-time directory

Quick fix for missing Swedish dot

Customer Success Testimonial: Recovery is Everything

In mid-October, Sweden's net authorities managed to boot the entire country from the interwebs when a routine maintenance script accidentally removed a rather important dot from its top level domain. The period was reinstated in less than an hour, but address problems persisted for who knows how long, thanks to cached DNS records at ISPs across the globe.

Clearly, the existing Domain Name System doesn't work quite as well as it should. But two familiar DNS outfits hope to change that, unveiling a new service that seeks to minimize the fallout from outages like the one that erased Sweden. Working in tandem with OpenDNS, Neustar has built what it calls the Real-time DNS Directory, designed to rapidly update service provider caches when corrections are made to DNS records.

In essence, the Directory bypasses the "time to live" (TTL) cache settings that can slow the distribution of corrections to ISPs and other "recursive" DNS providers along the lines of OpenDNS. The TTL tells the provider how long to use cache records before going across the net for fresh info. Domains typically set long TTLs, because it decreases the latency that ensues when you go looking for an update - not to mention the likelihood of a network snafu. But it also means that bad data can linger for much longer.

"There's a constant battle that one has with TTLs," Rodney Joffe, senior vice president and chief technologist at Neustar, tells The Reg. "Domains are constantly trying to make the TTL as long as possible so there's not the need to keep looking data up... But if an IP address is changed, it doesn't get updated soon enough."

When corrections occur, Neustar's Real-time DNS Directory is designed to update a service provider's records as soon as possible. If Sweden replaces a period, the period will reappear at the provider in, well, something approaching real-time.

"If a [DNS] change gets made, resolvers can effectively override TTLs," Joffe says. "It is a fundamental change in the way the traditional DNS works."

Of course, domains must feed the Directory, and recursive providers must use it. Neustar - an authoritative DNS provider - maintains the Directory, while OpenDNS is the first recursive provider to make real live use of it. OpenDNS founder David Ulevitch tells The Reg it's been in place for "about a month," but the service wasn't publicly announced until today.

"Whenever one of their customers makes a change, regardless of what the time live is for the record, they will automatically give us a notification to go re-fetch the authoritative record, which means our caches will be up to date," Ulevitch says.

Last week, as part of its plan to run its own internet, Google unveiled a free recursive service that competes directly with OpenDNS. Ulevitch wasn't shy about questioning Google's motives, and he was quick to point out that unlike Google, his service offers a kind of online dashboard that lets you control access to sites.

Naturally, he's now touting the Real-Time DNS Directory as another way that OpenDNS trumps the Mountain View Chocolate Factory. "We can now say declaratively that our caches are more up-to-date than Google's," he boasts. Won't Google follow suit? Ulevitch doesn't think so. "Google rarely - if ever - adopts things that are out in the open like this."

Asked if Google was in talks with Neustar about the Directory, Joffe declined to comment. ®

Ensure Ease of Recovery with Asigra’s Agentless Software

404 ?

I would suggest that your knowledge is returning a 404.

If a page you request gives a 404 error then you get the 404 page that the domain has specified, exactly as you should.

Now if the domain you request does not have a valid record, then OpenDNS will by default return the IP address of their redirection service when it should return a NX Domain response.

NX Domain != 404

That said the OpenDNS service does a lot more than just the basic DNS service, so if you want those features you would register anyway, and then disable redirection and get the NX Domain response.

If you don't want to use the other features then fair enough, don't use the basics either.

4
0

can I admit that

I am a big fan of OpenDNS for home use

with a bunch of kids using god only knows how many devices to connect to the net having it configured in my router gives a parent some peace of mind

(and no, it's not locked down to paranoid levels - I'm not that uptight)

2
0

Use opendns at work? Why not roll your own?

It's far from difficult to roll your own dns server, that uses the root servers to find what you want. Then you don't depend on anyone.

1
0

More from The Register

1,000 O2 staff chose redundancy over Capita
Betrayal, or just decent terms?
Google launches broadband balloons, radio astronomy frets
A careless Loon could blind the square kilometre array
 breaking news
Pttow! Ofcom kicks hams out of MoD bands
Geet off my land, you, you ... 'secondary user'
 breaking news
Now you can use your phone instead of your wallet at the ATM, too
Blimey, these little paper towels out of the vending machine are really expensive
 breaking news
UK.gov's £530m bumpkin broadband rollout: 'Train crash waiting to happen'
Whitehall whispers of damning watchdog report next month
 breaking news
MySpace zaps millions of teens' tearful rants, causes wave of angst
'Your crappy redesign SUCKS, I wanna read my blogs' screech users
 breaking news
Microsoft Office 365 on iPhone NOW: No, we're not making this up
Word, Excel, Powerpoint for your pocket-stroker
EU signs off on eCall emergency-phone-in-every-car plan
GPS and a mobe in every car - do you suppose the NSA would fancy that?
 breaking news
White Space wonga time: White House tips $100m into next-gen comms
Empty frequencies right place for tomorrow's mics, phones and fridges