What part of ‘No!’ is so hard for the DNS understand?
At APNIC Labs we’ve been experimenting with understanding how the DNS handles requests to resolve nonexistent names to make the DNS more resilient to random name attacks.
At APNIC Labs we’ve been experimenting with understanding how the DNS handles requests to resolve nonexistent names to make the DNS more resilient to random name attacks.
IP addressing, congestion control protocols, and a gold rush in space at IETF 126 in Vienna.
BGP ORIGIN, ASPAs, PAVA, and ASRAs at IETF 126.
Recursive resolver DNS query behaviour, Post-quantum DNSSEC, Optimistic DNS, Automating DNS delegation management, and more from IETF 126.
Around mid-2026, we began receiving user complaints about certificate validation failures. The failure wasn’t a single bug, but the collision of optimization and slow distribution.
Distributed systems depend on synchronization, but every approach has tradeoffs. From full copies to delta updates, how do you choose the right method?
SpaceX and Starlink’s valuation, reality, and the limits of connectivity economics.
AI eats the world, geolocation, measuring IPv6, and the cost of SSH from NANOG 97.
In the DNS, name resolution space queries are free. To what extent do we see over-querying on the part of recursive resolvers in the DNS?
There is an obvious tension between resilience and speed in the design of a resolver’s query strategy. DNS cold starts bring that tension into focus.