Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I noticed this two years ago, and eventually had to stop using Chrome (and Chromium browsers) as it would result in my ISP blocking all DNS requests from my IP (for a seemingly random amount of time). Even requests to public DNS would fail. It took awhile to identify Chrome as the culprit, and I wasn't convinced after seing the bogus DNS requests in TCP traps. So I started a cycle of using/not using Chrome, and it became obvious.

The easy solution was to stop using Chrome. The hard solution was to move. I've done both, but have yet to start using Chrome again.



I don't understand. Why would your ISP block your IP for bogus DNS requests? And why are they monitoring your traffic to public DNS servers? I presume this means they have to look at all traffic that goes over port 53. Is there a security concern?


This is common practice if the queries appear to be originating from worms like Conficker, etc. Others have reported that this behavior of Chrome's can set off false IDS alarms for the same reason.


And it's also common practice to send all bad DNS queries to an ad-ridden search page. Go figure.


I have no idea why they would want to block it, unless they considered it an attack vector for some reason. It was automatic - after a few of the bogus DNS requests, all DNS/port 53 traffic was dropped. Everything else worked, only DNS failed.


Can you name the ISP?


It was originally SBC DSL (resold Yahoo!, resold etc...). The Chrome-induced resolution failures weren't the only issue - their primary DNS server never worked, always went to the failover.

Things didn't improve under AT&T.


Time for 8.8.8.8?


I put in a vote for the easyDNS public DNS service (205.210.42.205 and 64.68.200.20). No NXDOMAIN monkeying or anything of that nature.


I would rather go with 208.67.222.222 and 208.67.220.220 from http://opendns.com


But opendns is one of the servers that gives you bogus results instead of NXDOMAIN.


Really?? That's disappointing to hear.


It's their primary monetisation vector from what I can see.


By default, the free service that anyone can use, they redirect nonexistent domains to a search page they control. If you pay (and register your IP address), you can turn that off. But the main reason for paying is to control which domains are blocked. You can choose categories, and/or maintain your own white or black list. http://www.opendns.com/web-filtering/ and http://www.opendns.com/internet-security/


You can also filter without paying, including black or whitelisting domains. Works effectively to curb reddit addictions.


Your ISP sucks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: