nanog mailing list archives

Re: New DNS vulnerability: political overreach


From: Barry Greene via NANOG <nanog () lists nanog org>
Date: Mon, 20 Jul 2026 07:41:26 +0800


Kevin, 

Please take this to ICANN. This is not a technical issue. If you are a business in anywhere in the world who knowingly 
ignores legal request for other parts of the world _AND_ ignore the “bottom up” community driven ICANN governance 
processes, then you are an idiot. 

www.icann.org <http://www.icann.org/>

Barry

On Jul 20, 2026, at 01:01, Kevin Tillery via NANOG <nanog () lists nanog org> wrote:

This is indeed. Politics has an annoying tendency to cause technical problems, the current one being how to protect 
the DNS from political attack.

There's nothing new about this - TLS became ubiquitous because of the Snowden leaks. Nobody said "get this TLS talk 
off my list because it's political"

That's why I'm asking if there's something similar people can do to secure DNS? Probably not at the moment and 
certainly not easily?

Although since it isn't about routing I'm not fully sure it's on-topic for NANOG and might be better suited for 
somewhere like IETF?

Kevin


On 19 July 2026 18:05:29 CEST, Jay Acuna via NANOG <nanog () lists nanog org> wrote:
On Sun, Jul 19, 2026 at 8:08 AM Andy Ringsmuth via NANOG
<nanog () lists nanog org> wrote:

"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance 
measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP 
security; and trouble ticket systems."

The technical issue would be susceptibility of All database to
tampering by any authorities
who hold legal supremacy/jurisdiction over whichever person(s) or
organizations are responsible for specific TLDs,
or even the actual org responsible for that registry, for any reason,
against the wishes of the domain holder.

Even if the domain holder exists outside that jurisdiction or can
legally operate under different rules.

While this can be a serious technical issue; I don't believe there is
anything network operators can do about it.
You could consider distributed alternatives such as IPNS of the IPFS
protocol a cryptographic-based name system,
Tor hidden services, etc.

Your best option might be to register your own domains under multiple
ccTLDs while ensuring that there
is no overlap amongst the registry operators or registrars between any
of the chosen TLDs and domains.


Andy Ringsmuth
--
-JA
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/LZL2ZERUH5FDFUM2ML7R53QRIM46Y3UZ/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/VL4QKNMCOV4MQIPRQHJOSA43Y6GWSVL4/

_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/7PIXXVN53B5J2PQZAJNJ6JAJ2WG5OP7Q/

Current thread: