• 0 Posts
  • 32 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2023

help-circle


  • What? What do you mean “DNS space”? Classic DNS does not have any security, no encryption and no signatures.

    DNSSEC, which adds signatures, is based on TLDs, not any geography or country. And it is not yet enabled for most domains, though I guess it would be for google. But obviously EU does not control .com.

    And if you mean TLS certificates, those are a bit complicated and I already explained why forging those would be problematic and not work on Chrome, though it could be done.


  • Yes, I mentioned that in a comment deeper down. And even before that, just fine them. Chances are they will pay and if not, you can probably seize some bank accounts.

    I am not trying to say Google can afford to completely defy the EU, just found it interesting how hard it is to block just google search specifically.

    PS: Also mentioned in a burried comment, there actually is a way for ISPs to block google, since DNS over HTTPS is not enabled by default yet in browsers I think. I forgot this since I enabled encrypted DNS like 8+ years ago for myself and just assumed people also have it by now.





  • The backup is usually a different server from the same DNS provider. E.g. google has 8.8.8.8 as primary and 8.8.4.4 as secondary. Plus the backup doesn’t even always work on Windows.

    Also note, it is not browsers but operating systems that do primary DNS. Browsers may use DNS over HTTPS for security and privacy instead of the one in the OS, but that usually requires the OS DNS to resolve the address of the DNS over HTTPS server, since it is considered a security feature built on top of classic DNS instead of replacement.

    PS: Don’t get me wrong, EU could definitely block google.com sooner or later. It just wouldn’t be as easy as usual. The real risk is if Alphabet stops offering all of its services, chaos ensues. Companies unable to access their google spreadsheets. Services and data hosted on google cloud lost. People protesting lack of youtube…

    And even if Alphabet doesn’t do that, I expect a lot of issues just with google being unavailable and most people not even knowing there are other search engines. It’s really going to be last resort to try blocking google, I expect fines or some such.


  • It would likely be impossible to redirect google.com without either sparking a cyberwar or building something like the great firewall of China, quite possibly both.

    Blocking is somewhat possible, but to redirect, they would have to forge google certificates and possibly also fork Chrome and convince users to replace their browser, since last I checked, google hard-coded it’s own public keys into Chrome.

    Technical details

    I say blocking in somewhat possible, because governments can usually just ask DNS providers to not resolve a domain or internet providers to block IPs.

    The issue is, google runs one of the largest DNS services in the world, so what happens if google says no? The block would at best be partial, at worst it could cause instability in the DNS system itself.

    What about blocking IPs? Well, google data centers run a good portion of the internet, likely including critical services. Companies use google services for important systems. Block google data centers and you will have outages that will make crowd-strike look like a tiny glitch and last for months.

    Could we redirect the google DNS IPs to a different, EU controlled server? Yes, but such attempts has cause issues beyond the borders of the country attempting it in the past. It would at least require careful preparations.

    As for forging certificates, EU does control multiple Certificate authorities. But forging a certificate breaks the cardinal rule for being a trusted CA. Such CA would likely be immediately distrusted by all browsers. And foreig governments couldn’t ignore this either. After all, googles domains are not just used for search. Countless google services that need to remain secure could potentially be compromised by the forged certificate. In addition, as I mentioned, google added hard-coded checks into Chrome to prevent a forged certificate from working for it’s domains.


  • I think both. I imagine I would do a lot of good on global level, but probably abuse it on personal level.

    Although the specifics also matter, e.g. will there be a way to steal it from me, forcing me into paranoia?

    And if you believe in yourself, how would you try to convince an hypotetical entity to give you this wealth?

    It can’t end worse than the direction we are going, and will very likely end much better overall.


  • I understand why you would think that, but this is not the case. Not a lawyer though, not legal advice.

    There are 2 main types of causes of action for this, let’s go over them:

    1. Conversion, unjust enrichment: Here, Legal eagle and other creators allege Honey took money that was supposed to go to them. Basically just theft. This does not apply to adblock, since they don’t take the money.
    2. Tortious interference: Here they claim, that by removing the tracking cookie, they unlawfully interfere with the business relationship between the affiliates and the shopping platform. This could maybe apply to ad-blockers, but it is almost certainly superseded by the user explicitly wanting to remove tracking cookies, and the user has the right to do so. Saying that it is unlawful interference is like saying a builder hired by a land owner to build a fence is interfering with truckers who were using the land as a shortcut. They had no legal right to pass through the land in the first place. So the owner can commission a fence and a builder can build it. A contract between the truckers and amazon would not matter. In case of honey, it is like the builder was not hired by the owner and just built the fence to spite the truckers without owners permission.









  • DreamlandLividity@lemmy.worldtoTechnology@lemmy.worldItch.io games site taken down
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    edit-2
    1 month ago

    Wait, so your point is that we don’t need to moderate DMs (and by proxy other spaces that users don’t see), just make them feel unwelcome in the public ones.

    And earlier in the thread, when I ask where the extremist content is, I and Schadrach agreed it is mostly places people don’t see. Which you didn’t object to.

    So isn’t it job well done, Steam is as is should be? Or what is the issue here?