-
o0x1eefyes
-
o0x1eefi have the infrastructure for it
-
o0x1eefi use a combination of unbound with dnsmasqd. Unbound by itself can't handle huge lists. So I off that work to dnsmasqd.
-
o0x1eefWas it worth it... no. I don't use any of it. I just could if I ever wanted to start implementing blocklists.
-
o0x1eefOh, my bad, I do use it, I have a blocklist for malware and porn.
-
ltsHow big of a list are you talking about? I use unbound with a 300000+ line blocklist and it has no performance hit
-
vforkperformance how- query latency, RAM, or reload time?
-
o0x1eeflet me check.
-
vforkunbound chews 300k local zones fine at query time, pays for it in memory footprint and a slow reload
-
vforkdnsmasq just reads addn-hosts and shrugs
-
vforkwhich one bites depends on how often you update the list
-
o0x1eefroot at aqua.home.network [root] # cat /var/unbound/etc/blocklists/malware.hosts | wc -l
-
o0x1eef435233
-
o0x1eefroot at aqua.home.network [root] # cat /var/unbound/etc/blocklists/porn.hosts | wc -l
-
o0x1eef500295
-
o0x1eefSo the performance hit is at boot time, and also when resolving URLs. Dnsmasqd was a consequence of that.
-
vforkboot time hit at that size is just parsing, unavoidable. but resolve time slowdown is the suspicious part
-
o0x1eefI don't know, I consider it a solved problem.
-
vforkunbound's local zone with type always_nxdomain is O(1) hash lookup
-
vforkif you were loading entries as local data lines instead, then that's where the cost usually hides
-
vforkdnsmasq still wins on memory for this volume, but it's possible the unbound side might have been misconfigured
-
o0x1eefdunno, don't care :)
-
vforkfair
-
vforki remember pulling /etc/hosts from SRI-NIC twice a week over uucp in 85
-
o0x1eefBack in the summer of ..
-
vforkjake feinler added you to it by email
-
vforkback then couple thousand entries was a busy quarter
-
vforkyour malware list alone is a hundred times bigger than the entire arpanet namespace ever was
-
vforkmockapetris built DNS specifically because that flat file wasnt going to clear 10k hosts
-
» MelanieUrsidino puts on some music she associates with retro computers
-
vfork40 years later we shipped delegation, caching, hierarchy and the first thing everyone did with a home router was build a private hosts.txt to opt back out of half of it
-
vforkunbound and dnsmasq is hosts.txt with a daemon and better PR
-
o0x1eefYep
-
vforkvixie and dave rand built MAPS RBL in 97 to fight spam
-
vforkit was briliant abuse of DNS: encode the offender ip backwards into a domain like 1.0.0.127.bl.maps.vix.com dig it, get NXDOMAIN or a hit.
-
vforkthey used the resolver itself as a free distributed kv store before kv stores were a marketing category
-
vforkit spawned an industry overnight
-
o0x1eefInteresting idea
-
vforkthen spammers started suing MAPS for libel and interference
-
vforkthey had to shut down the free tier because lawsuits cost more than the service did
-
vforkspamhaus inherited the cause and had injunctions filed against them in czech courts
-
vforkyour local blocklist is the great grandchild of that battle
-
vforkthe only reason your inbox isnt 99% viagra ads is paul vixie and a handful of lawyers who hated spam more
-
o0x1eefI used this - github.com/blocklistproject/Lists
-
amencodaJust found this DJ Ware guy on youtube, man is he good
-
o0x1eefI was expecting some dope beats so this is different...
-
wrench56hey! anyone knows the syzbot status for freebsd? It seems to be down?
-
wrench56or has it been abandoned for some reason? or am i just blind?
35 minutes ago