Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15703

Re: DoH plugin for BIND

Path csiph.com!news.uzoreto.com!news.etla.org!nntp-feed.chiark.greenend.org.uk!ewrotcd!usenet-its.stanford.edu!usenet.stanford.edu!not-for-mail
From Reindl Harald <h.reindl@thelounge.net>
Newsgroups comp.protocols.dns.bind
Subject Re: DoH plugin for BIND
Date Sat, 2 May 2020 15:38:22 +0200
Organization the lounge interactive design
Lines 50
Approved bind-users@lists.isc.org
Message-ID <mailman.326.1588426696.942.bind-users@lists.isc.org> (permalink)
References <85af55bb-1b23-b847-3de9-ffb198bc9fb9@web.de> <20200429074035.GA91269@isc.org> <d08a148f-18f6-1972-1064-2f878b79bee2@nixmagic.com> <alpine.DEB.2.20.2004292100400.16665@grey.csi.cam.ac.uk> <8670427D-C5E5-42E3-AFEB-BA15F74E5F53@kreme.com> <39825fcf-bcd7-f38a-aeae-2fccc8df0be8@nixmagic.com> <002174a6-4025-fad1-afea-0e96f40d2ff0@thelounge.net> <20200502093032.09f4b5cf@ime1.iment.local> <c3e47052-09ca-fa93-ce1b-04aa05aa5fb9@thelounge.net>
NNTP-Posting-Host lists.isc.org
Mime-Version 1.0
Content-Type text/plain; charset=utf-8
Content-Transfer-Encoding 7bit
X-Trace usenet.stanford.edu 1588426709 23734 149.20.1.60 (2 May 2020 13:38:29 GMT)
X-Complaints-To action@cs.stanford.edu
To bind-users@lists.isc.org
Return-Path <h.reindl@thelounge.net>
X-Original-To bind-users@lists.isc.org
Delivered-To bind-users@lists.isc.org
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.7.0
In-Reply-To <20200502093032.09f4b5cf@ime1.iment.local>
Content-Language en-US
X-Spam-Status No, score=-0.7 required=5.0 tests=RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS,SPF_PASS autolearn=disabled version=3.4.2
X-Spam-Checker-Version SpamAssassin 3.4.2 (2018-09-13) on mx.pao1.isc.org
X-BeenThere bind-users@lists.isc.org
X-Mailman-Version 2.1.29
Precedence list
List-Id BIND Users Mailing List <bind-users.lists.isc.org>
List-Unsubscribe <https://lists.isc.org/mailman/options/bind-users>, <mailto:bind-users-request@lists.isc.org?subject=unsubscribe>
List-Archive <https://lists.isc.org/pipermail/bind-users/>
List-Post <mailto:bind-users@lists.isc.org>
List-Help <mailto:bind-users-request@lists.isc.org?subject=help>
List-Subscribe <https://lists.isc.org/mailman/listinfo/bind-users>, <mailto:bind-users-request@lists.isc.org?subject=subscribe>
X-Mailman-Original-Message-ID <c3e47052-09ca-fa93-ce1b-04aa05aa5fb9@thelounge.net>
X-Mailman-Original-References <85af55bb-1b23-b847-3de9-ffb198bc9fb9@web.de> <20200429074035.GA91269@isc.org> <d08a148f-18f6-1972-1064-2f878b79bee2@nixmagic.com> <alpine.DEB.2.20.2004292100400.16665@grey.csi.cam.ac.uk> <8670427D-C5E5-42E3-AFEB-BA15F74E5F53@kreme.com> <39825fcf-bcd7-f38a-aeae-2fccc8df0be8@nixmagic.com> <002174a6-4025-fad1-afea-0e96f40d2ff0@thelounge.net> <20200502093032.09f4b5cf@ime1.iment.local>
Xref csiph.com comp.protocols.dns.bind:15703

Show key headers only | View raw



Am 02.05.20 um 15:30 schrieb Paul Kosinski via bind-users:
> How many ISPs allow traffic on port 25? My impression is that even many
> (non-enterprise) business customers can't use port 25.

that can be easily answered by just look at your inbound MX and the
amount of dul.dnsbl.sorbs.net and pbl.spamhaus.org hits

until the large botnet was killed a few months ago this was majority of
*all* mail traffic which wouldn't have been possible all the years by
your conclusion

-------------------------

current month blocked at postscreen level:

[root@mail-gw:~]$ cat maillog | grep spamhaus.org | grep -P
"127.0.0.(10|11)" | wc -l
1148

until this year it was 10 times more

-------------------------

delivered: 1371
blocked by contentfilter: 134
honeypot hits: 5206

> On Sat, 2 May 2020 09:28:54 +0200
> Reindl Harald <h.reindl@thelounge.net> wrote:
> 
>> Am 02.05.20 um 09:00 schrieb Michael De Roover:
>>> That's actually my biggest concern with DoH, ISP blocking. It doesn't
>>> seem as obvious as it is with DoT, but deep packet inspection (DPI) is
>>> already a thing. Don't expect an ISP that wants to block DoT to not
>>> (want to) block DoH either. The crux of the problem at that point is not
>>> the technology, it is the ISP's incentives. If the ISP wants to block
>>> DoT for whatever reason, personally I'd consider it.. not exactly fine
>>> but at least their right to do so. That's their decision to make.   
>>
>> seriously?
>>
>> that seems to be some US attitude, no wonder what happens there with
>> user attitudes like "but at least their right to do so"
>>
>> the ISP by definition has exactly one right: get money for his service
>> which is described as "route and transfer every package, don't look at
>> it, don't mangle it, you have no business about the content of my traffic"

Back to comp.protocols.dns.bind | Previous | Next | Find similar


Thread

Re: DoH plugin for BIND Reindl Harald <h.reindl@thelounge.net> - 2020-05-02 15:38 +0200

csiph-web