← Back to context

Comment by fapjacks

7 years ago

Well no, CloudFlare doesn't get to talk about not "violating the integrity of DNS" after you stopped responding to "any" queries in violation of the standard. You started by doing your own thing and then proposed a change to the standard to fit your business decision. [0]

[0] https://www.rfc-editor.org/info/rfc8482

There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.

  • They could have allowed "any" only via TCP. Instead Cloudflare told everyone "our software can't handle any, so yours shouldn't either".

  • Wait, but both of these are horrible ideas. Horrible analogy; theres no need to bring politics into this.

    • It's a fine analogy: the former is something some people think is a good idea, and others think isn't, whereas about the latter most people agree it should not be done. Which is what OP wanted to express.

They also stopped responding to all DNS queries for some neonazi asshats because of public pressure and politics. They're definitely jerks but they still should be treated like any other customer unless they're actively breaking the law.