Re: OpenDNS safer or not?



Barry Margolin wrote:


And the SiteFinder issue wasn't one of NXDOMAIN vs. SERVFAIL.


Oh, it was, depending on your DNS resolver.

The problem with SiteFinder was that it couldn't tell the difference between
a query coming from a web browser (which can deal with being redirected
to a search server) and one coming from a mail server (which should get
an error so that it can bounce the message back with an appropriate
error). This is less likely to be a problem for the typical OpenDNS
user, because they're just running applications like web browsers, not
mail servers.


Ehm... what about P2P applications, VoIP stuff, etc.? It fails for the very
same problem.


Since I'm also missing a little part of the discussion: In which way should
OpenDNS be preferable to a simple stub resolver recursing on a typical
ISP's caching-only DNS server with the ICANN root or the ORSN root?
.