Feeds

Don't stone the DNS heretics

They only said that Anycast was good enough for Jehovah

  • alert
  • submit to reddit

Remote control for virtualized desktops

Sysadmin blog I recently asked Rodney Joffe, chief technologist at Neustar, four-decade industry veteran and chair of the Conficker working group, about why he founded UltraDNS and implemented IP Anycast.

Joffe, whose early career involved creating technologies for load balancing and fault tolerance, part of content distribution system Genuity, thought the same ideas would improve DNS. He was asking why the DNS servers of the day used round-robin instead of the closest geographic server: why couldn’t geographic load balancing be brought in to the DNS system, giving answer A to an individual located at X, and answer B to an individual located at Y?

He asked Paul Vixie, DNS guru and creator of BIND, the same question. Vixie’s position was that messing with DNS was fundamentally wrong, as it would violate the principles of network communications: if you are authoritative, you must deliver the same address to all askers, which the DNS Anycast method does not do*. This was to become the official IETF position.

But practice and theory didn’t match up. According to the IETF, when using Anycast, "one in a million DNS queries would fail." But in the late 1990s only 95 per cent of DNS queries succeeded on first request. According to Joffe, Anycast offered better practical results, but was rejected because of the ideas on which it was based.

Instead he created a beta for his friends on the North American Network Operators Group (NANOG) mailing list. Though the idea was viewed as heresy - Joffe was once marched out of an IETF working group meeting because of his ideas - many of the individuals on NANOG began to play with the code. Eventually, a few root server operators quietly incorporated the Anycast DNS technique into their operations, a decision which would shape the internet as we know it today.

On October 21, 2002, a DDoS attack was launched against the root name servers. The ones that survived were those that had quietly switched in the background to using Anycast. When a more powerful DDoS against the root servers occurred in 2007, only the two root servers that had yet to switch to Anycast were laid low.

UltraDNS would grow to become authoritative for more than 10 per cent of all TLD lookups and nearly 20 million domain names, and the customer list includes TLDs including .ca, .us and .uk. His revolutionary approach to root DNS services enabled the internet to withstand the DDoS attacks that once threatened to cripple it.

The lesson is that sometimes the white paper or entrenched rules of best practice are simply wrong. If it weren’t for heretics like Rodney Joffe, the internet wouldn’t function nearly as reliably as it does today. ®

* Editor's note - Trevor adds, by way of clarification: "While Anycast provides a method for DNS servers to offer the same information to all askers, it is also an enabling technology for both geocasting of DNS services and geolocating the requestor. In this way, Anycasting is the technology used by services such as UltraDNS to provide different responses to DNS queries based upon geographic location."

Remote control for virtualized desktops

More from The Register

next story
Azure TITSUP caused by INFINITE LOOP
Fat fingered geo-block kept Aussies in the dark
729 teraflops, 71,000-core Super cost just US$5,500 to build
Cloud doubters, this isn't going to be your best day
Want to STUFF Facebook with blatant ADVERTISING? Fine! But you must PAY
Pony up or push off, Zuck tells social marketeers
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
SAVE ME, NASA system builder, from my DEAD WORKSTATION
Anal-retentive hardware nerd in paws-on workstation crisis
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.