I remember when I was 14 or something and first looked up what "loitering" meant and I was like... In the US cops can harass you for just being somewhere? Not even private property, just existing on a sidewalk? Still doesn't make sense
Are you ok with the future that your kids will live in if nothing changes? Or do you believe that someone else will come and save you? Genuinely asking
That is exactly what you're supposed to be fighting, dumbass. You all keep saying this as if we didn't know, but how else is it going to happen? You can't keep waiting for your white knight in shining armor.
People have left their families behind, lived in forests eating scraps for years while being actively hunted, with victory never certain. Just never in the US. When Europeans say that you can't even see how much privilege you're not willing to give up, we say it because many of us heard stories from our elders of giving up everything to follow an ideal and join the resistance.
I say this with no hate, but seriously - go watch a documentary and grow some balls.
This is not the start of the information wars, this is the peak. I think (and hope) this won't be enough to save them from being the awful company they are, but I have no doubt everyone is lining up to throw as much money as they can to influence what ChatGPT has to say about anything. "Ad business" obscures what this really is - marketing lies and political propaganda presented and sold as intelligent objective analysis
I was lurking in their IRC yesterday, their stance seems to be that they will never override an existing record, but there was some discussion about possibly overriding an NXDOMAIN. The main issue is DNSSEC - with it, negative answers are authoritative and signed, so they'd need to stop supporting DNSSEC altogether to restore the record. In general, they mirror "standard" TLD zones 1:1 from the root servers, their "libre" and "censor-free" mostly seems to apply to their own TLDs that are only available on OpenNIC.
Edit:
20:17 ohnonot: Some of you may be aware that some domains are being blocked because USA pressure. The reasoning is, of course, "AntiFa terrorism".
20:18 One of these domains is autistici.org.
20:18 But shouldn't I be able to reach it with OpenNIC? I am currently using one of your nameservers.
20:23 ohnonot: Because I cannot.
20:31 phschafft: there has been some dicussion about it so far.
20:31 I would assume, if it's gone from the parent zone (here the TLD), it's gone. end of story.
20:47 ohnonot: Thanks. I just read that OpenNIC is an "alternative DNS root" but apparently it still gets the list from somewhere - ICANN or whoever takes care of the TLD, and once the IP/name connection is lost, it's lost?
20:48 Could not such sites request to be included in OpenNICs lists, and f*** the USA-based "parents"?
20:49 BYW where can I follow OpenNIC's discussion?
21:04 phschafft: there is a mailing list.
21:05 ohnonot: it's not that simple. starting with the fact that once a zone is signed it's not possible to just edit it however you like.
21:06 this is a very much more complicated topic than most people realise.
21:08 Shdwdrgn: Just waking up here, but I wanted to point out that Openinic's root zone pretty much just points all the ICANN tld's directly to the official providers. So if an .org domain gets blocked, I cannot edit the direct response.
21:09 There IS a possible way around it... Any dns server can add their own manual entry for a domain to point back to the original dns servers of that domain
21:10 There was some heated discussion here years ago when the US similarly censored some other domains. I brought up this idea at the time and a lot of people were strongly against it because then opennic no longer faithfully resolved the ICANN domains exactly as the rest of the internet saw them
21:34 EMREOYUN: Following up after Shdwdrgn, this is why there are proxy websites, for example, the website that lists torrents. You can't simply change everyone's DNS'es but you can always register a new domain
21:35 Also supporting whytek, DNS is decentralized by design but it is extremely centralized in terms of politics & power
21:37 But I didn't expect Italy to do something like this. I know it is nowhere close to our country in terms of magnitute of cencorship but still
[snip]
22:16 whytek: And the debate over faithfully reproducing ICANN domains is of course valid. I certainly would not want to see a difference in results from one DNS provider to another. But actually servicing a domain that does not exist in the _other_ provider is not the same thing.
22:18 The way I'd see that is that ICANN server won't resolv .libre OK fine. but i will. we do this at TLD without problem, why not do it are secondary level? ICANN doesn't resolve whatver.org, ok we will.. Of course, maybe then you want to ensured monitoring to make sure that once ICANN is servicing the domain, you replicate it correctly. We DON'T want diverse results.
22:19 the once a domain is signed... argument then is not applicable.. the "upstream" domain cannot be signed, as it does not exist.
22:21 whytek: But.. in the end, you know.. I think DNS is just a problem, punkt,punto,fullstop. Over on fediverse some poeple are throwing out ideas into the mix.. the debate is always bubbling under there somewhere.
22:22 Shdwdrgn: whytek, that was actually my argument in the matter... if any government has forcefully removed a domain from the registry then that domain technically no longer exists, so by adding our own entries back into the record we're not breaking anything, we're just adding functionality that shouldnt have been removed in the first place.
22:32 whytek: Shdwdrgn, ack.
22:33 of course.. good luck getting a LE SSL cert for the domain then.. and then we are going down the road to the alternate Cert Authority.....
22:33 (again)
22:33 phschafft: whytek: maybe it can. but so far all ways I have seen people suggest had one or more of those three main flaws: 0) they did not remove the complexit but made it less visible, 1) they removed security, 2) they removed features.
22:34 more then happy to be shown a solution that does none of that.
22:34 Shdwdrgn: right, no ssl available, but the site might still be somewhat functional without it
22:37 phschafft: whytek: 'make sure that once ICANN is servicing the domain, you replicate it correctly' <- this is a HUGE complexity added. like in at least two magnitudes larger than people think.
22:38 whytek: also, the signed parent domain (here: the TLD) might provide information that specifically states that the given domain DOES NOT exist. so if it exists the signature would missmatch.
22:38 please don't ignore the negative cases. this is actially part of my 1)
22:39 and the 'we should replicate if it is there' is somewhere around my 0)
22:40 Shdwdrgn: phschafft, I don't see that as much of a barrier? Just make a query directly to the ICANN record and if that domain reappears again, stop including the local record?
22:41 phschafft: Shdwdrgn: 'someone somewhere somehow runs an undocumented cronjob that does magic to the zones'?
22:41 ;)
22:41 whytek: phschafft, (I'm not sure I'm understanding the language structure of those last two lines re 1/0) - TTL aside, I'm not seeing the complexity in answering queries for a domain as long as so other server is not doing so. I'm not saying it has to be done EVERY time there's a query.. just have some process that checks I dunno.. once a day or whatever.
22:41 phschafft: it sounds easy. but doing it so it actually works, and keeps working is hard.
22:42 Shdwdrgn: There is certainly no easy solution to modifying the signed ICANN record to slip the domain back in place, but I do know of one method
22:42 whytek: also, in terms of signature mismatch.. what's to mismatch? If I'm using openNIS servers? where am I going to see a mismatch?
22:42 *openNIC
22:43 Shdwdrgn: you can actually get access to download local copies of .com, .org, and others. If you have a full working copy, you can self-sign the root of that tld and then you're free to make any changes you want.
22:43 phschafft: if you don't see a mismatch, that may mean that you have verification disabled ;)
22:43 Shdwdrgn: but those tld files are HUGE!!!
22:43 phschafft: the large .de outage recenty kind of demonstrated that problem in the real world.
22:44 maybe reading up on it is a generally good idea for DNS related tech people. independent on today's topic.
22:45 and the enduser needs to trust another key.
22:45 for any definition of enduser.
22:45 anyway, it's movie night!
22:46 whytek: again, I'm not against things. just consider my warnings and make sure they are *actually* void. :)
22:50 whytek: phschafft, (I missed your 1st post with points 0-2) - I'll admit I have not kept up to speed with developments in areas such as DNSSEC, although I'm well aware that a huge amount of work has gone into it in recent years. not least from NGI.
22:50 I suppose I see it as adding even more dependency onto DNS, something which I have since a long long time ago felt like needs to go away.
22:51 I do agree with those who say we are better off with encryption/identification built into the protocol.
22:51 phschafft: I'm also not arguing what is right or wrong and how things should or should not be. just, if you touch it, make it better, not worse.
22:52 whytek: I'm not sure I see the absolute need for a "human" addressable internet, certainly not if this is at the cost of sovereignity and descentraliation.
I remember when I was 14 or something and first looked up what "loitering" meant and I was like... In the US cops can harass you for just being somewhere? Not even private property, just existing on a sidewalk? Still doesn't make sense