DNS ad-hocracy in peril as ICANN advisors mull root server shakeup

Plan could reduce the number of central server operators

Internet overseer ICANN is considering a self-managed governance model for the world's Domain Name System root servers – and one of the outcomes could be a reduction in the number of root servers.

Today, 12 companies operate the 13 DNS root servers that are used by browsers and other software to ultimately translate domain names, like theregister.com, into network IP addresses, like, which are assigned to the servers that cough up their content. These central root servers fan out lookup requests to thousands upon thousands of DNS name servers run by all sorts of organizations across the world. That model has, in internet time, virtually existed since time immemorial.

Ever since ICANN took full stewardship of various crucial internet functions – such as overseeing DNS and domain names – from the US government's Department of Commerce, it has been considering questions like: who holds root server operators accountable and to what rules; how do they assure continuity of service; and who should be regarded as stakeholders?


US govt mulls snatching back full control of the internet's domain name and IP address admin


The very good – and perhaps surprising – reason such questions are important is that today's root system is one of the internet's remaining examples of ad-hoc arrangements sustained by goodwill. Everyone agrees to be nice and friendly and keep the internet as we know it glued together.

And that model may not be entirely sustainable, according to ICANN's Root Server System Advisory Committee (RSSAC), which last week presented its own root server governance model.

That proposal pointed out that “the RSOs [root server operators] today operate completely independently under their own goodwill and funding without any direct oversight by the stakeholders of the service, which is provided solely based on historical trust and integrity. RSSAC has documented much of the history and current structure of root server operations and management, but the governance of the RSS [root server system] remains largely informal and undocumented.”

The presentation of the proposal, by Tripti Sinha and Brad Verd, covered the key questions of root system stakeholders – ICANN, the IETF, the Internet Architecture Board, and root server operators – and governance, and offered up the perhaps surprising conclusion that root server operators could, in the future, be consolidated to fewer than 13.

The benefit of that being it would be easier to ensure quality control and quality of service with fewer operators.

Our friends over at Heise.de reported that Sinha, whose day job is being the CTO of the University of Maryland in the US, told the meeting: “There could be fewer than twelve, and we'll end up there.”

Sinha and Verd's presentation proposed that bandwidth, packets per second, and queries per second become the fundamental yardsticks – and requirements – for the DNS root system.

The full RSSAC-proposed governance model is discussed in this 50-page white paper [PDF]. ®

Similar topics

Other stories you might like

  • The future: Windows streaming through notched Apple screens

    Choice is the word for Jamf's Dean Hager

    Interview As Apple's devices continue to find favour with enterprise users, the fortress that is Windows appears to be under attack in the corporate world.

    Speaking to The Register as the Jamf Nation User Conference wound down, the software firm's CEO, Dean Hager, is - unsurprisingly - ebullient when it comes to the prospects for Apple gear in the world of suits.

    Jamf specialises in device management and authentication, and has long been associated with managing Apple hardware in business and education environments. In recent years it has begun connecting its products with services such as Microsoft's Azure Active Directory as administrators face up to a hybrid working future.

    Continue reading
  • There’s a wave of ransomware coming down the pipeline. What can you do about it?

    AI can help. Here’s how…

    Sponsored The Colonial Pipeline attack earlier this year showed just how devastating a ransomware attack is when it is targeted at critical infrastructure.

    It also illustrated how traditional security techniques are increasingly struggling to keep pace with determined cyber attackers, whether their aim is exfiltrating data, extorting organisations, or simply causing chaos. Or, indeed an unpleasant combination of all three.

    So, what are your options? More people looking for more flaws isn’t going to be enough – there simply aren’t enough skilled people, there are too many bugs, and there are way too many attackers. So, it’s clear that smart cyber defenders need to be supplemented by even smarter technology incorporating AI. You can learn what this looks like by checking out this upcoming Regcast, “Securing Critical Infrastructure from Cyber-attack” on October 28 at 5pm.

    Continue reading
  • Ransomware criminals have feelings too: BlackMatter abuse caused crims to shut down negotiation portal

    Or so says infsec outfit Emsisoft

    Hurling online abuse at ransomware gangs may have contributed to a hardline policy of dumping victims' data online, according to counter-ransomware company Emsisoft.

    Earlier this month, the Conti ransomware gang declared it would publish victims' data and break off ransom negotiations if anyone other than "respected journalist and researcher personalities" [sic] dared publish snippets of ransomware negotiations, amid a general hardening of attitudes among ransomware gangs.

    Typically these conversation snippets make it into the public domain because curious people log into ransomware negotiation portals hosted by the criminals. The BlackMatter (aka DarkSide) gang's portal credentials (detailed in a ransom note) became exposed to the wider world, however, and the resulting wave of furious abuse hurled at the crims prompted them to pull up the virtual drawbridge.

    Continue reading

Biting the hand that feeds IT © 1998–2021