Mark Andrews
Fri May 18 21:55:10 UTC 2007

> * David Conrad:
> >> but the solution is in our hands -- us, the people who
> >> deploy infrastructure.  registrants, sign your zones!
> >
> > Why?  Isn't the solution to run your own caching server and not rely  
> > on your ISP's?
> Some ISPs route 53/UDP (and probably 53/TCP) to their own servers.
> This is especially common if you use a shared media access network
> with pretty weak authentication. 8-/

	And in the process break local iterative servers as they
	don't look at "rd" as a pass through indicator and return
	non-authorative answers from the cache which then get
	rejected.  Hotels are notorious for this misbehaviour.

	Presumably they are trying to get you to their sign up
	page but intercepting http would be just as effective.
	DNS is not such a bandwidth hog as to be worth the effort.

Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
Mark Andrews, ISC

