Fedora and fallback DNS servers
Fedora and fallback DNS servers
Posted Feb 25, 2021 21:38 UTC (Thu) by pizza (subscriber, #46)In reply to: Fedora and fallback DNS servers by logang
Parent article: Fedora and fallback DNS servers
This argument falls flat once you consider that most folks already send "all of their DNS queries" to "a single company" -- namely their home ISP -- and the historical record is full of examples of ISPs (and especially hotspot operators) being much less trustworthy (and less reliable) than the likes of Google or Cloudfare.
This whole discussion seems to be question about "fail closed" or "fail open" -- or alternatively, two points on the "usability vs security" curve. Which one is appropriate is _entirely_ context-dependent. and to be honest, for those scenarios where "fail closed" is appropriate, this default is just one of many things that need changing for their particular deployment environment. For most everyone/everything else, having a sane fallback is a GoodThing(tm), because the alternative is not "working" at all.
> But, yes, a fall back is fine *if* you complain loudly so the user can know that something bad has happened and can perhaps seek help.
Sure, though it's not entirely clear what mechanism could be used to do this complaining.
