Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Internet will break for the people affected."

Those people may rely on the Internet for their job, studies or social life, so you shouldn't be so quick to just pull the plug because they were unfortunate enough to get infected. To add insult to injury, you would be forcing them to spend possibly significant amounts of money to get it working again, something that not everyone has ready access to.



Well, the "internet" isn't like a land line/electricity. It goes down pretty consistently where I have lived for the last 10 years (Sunnyvale CA, San Mateo CA, Redwood City CA) - on both DSL and Cable (SBC, AT&T, Comcast) - sometimes for 2 to 3 days at a time. Indeed, the frequency with which Comcast's DNS server stops responding to me has me switching to 8.8.8.8 on a bi-montly basis (and screwing up all the CDNs at the same time).

Shutting down this rogue DNS server will have little to no serious consequence on people's lives - it's not like the "internet" is a reliable service. People who do need reliability, have things like SONET with dual-entrance, multiple providers, and multiple data centers located in separate disaster zones with aggressive power redundancy facilities.


FYI, Comcast's new generation of DNS servers appear to be much more reliable. They support IPv6, DNSSec, and don't have ads. Also, they're anycast (like Google), so the IPs are the same everywhere:

75.75.75.75

75.75.76.76

2001:558:FEED::1

2001:558:FEED::2

http://dns.comcast.net/


None the things you mention in your second paragraph will help you if what fails is DNS lookup.

Depending on who you are, what you do and where you live, internet access may well be as vital to you as a land line. In fact, I'm not sure I'd notice if my landline stopped working.


> To add insult to injury, you would be forcing them to spend possibly significant amounts of money to get it working again, something that not everyone has ready access to.

Somebody needs to pay the money. In this case, it appears to be the taxpayer. I'm not sure I like this. I'd prefer software companies writing vulnerable software to pay the bill, or the people using the vulnerable software, or perhaps the ISPs (who are being paid by the people using the vulnerable software).

I don't like the taxpayer paying for it because software businesses are making more money by taking security shortcuts and as long as the taxpayer pays for the cost of this then there's no incentive for them to stop.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: