djbdns
[Top] [All Lists]

Re: blocking IP ranges from querying tinydns

To: Mike Jackson <mj@sci.fi>
Subject: Re: blocking IP ranges from querying tinydns
From: Dean Anderson <dean@av8.com>
Date: Mon, 14 May 2007 14:23:32 -0400 (EDT)
Cc: dns@list.cr.yp.to
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-djbdns@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list dns@list.cr.yp.to
In-reply-to: <46476E8E.8070000@sci.fi>
Mailing-list: contact dns-help@list.cr.yp.to; run by ezmlm
It was decided a long time ago that DNS data is public knowledge.  
Cyveillance is doing nothing wrong by monitoring the public web pages
and this obviously means querying the DNS servers for those web sites.  
Other search engines do the same.

I suggest that, at minimum, you should ask your customers if they wish
to block Cyveillance (and other search engines).  Being you are in
Finland, I don't know what privacy laws you have to obey. But it would
seem only ethical and proper that you should put such questions to your
customers and let them choose, rather than making the choice for them
without their knowledge or approval.

In the U.S., such unauthorized blocking would violate the Wiretap Act
and the ECPA, because it is unauthorized (ECPA), and not a 'necessary
incident to the rendition of service' (Wiretap Act).  See for example,
http://www.av8.net/IETF-watch/JohnLevine/

                --Dean


On Sun, 13 May 2007, Mike Jackson wrote:

> Hi,
>  I serve a few thousand domains from my 3 geographically dispersed
> tinydns servers, and I'm noticing that they are getting quite a lot of
> queries from Cyveillance. I don't like Cyveillance and I don't want them
> gathering info about the domains I host. I basically would like to
> either block Cyveillance or even better, return 127.0.0.1 for anything
> they query.
> 
>  Any ideas on how to accomplish this, other than adding a lo record to
> each of several thousand domains? I'd prefer a low-maintenance, global
> blocking solution.
> 
> Thanks,
> Mike
> 
> 

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000   



<Prev in Thread] Current Thread [Next in Thread>