#OpenNIC

2026-02-01

Après avoir passé des heures à blinder mon serveur #dns je me suis posé une question en regardant le projet #opennic : pourquoi dépendre d'extensions comme .com, .fr, .org, .net... qui ne nous ressemblent pas ?

Le #fediverse est décentralisé, alors pourquoi notre adressage ne le serait-il pas ? J'ai eu une idée (je ne dois pas être le seul) : et si on créait des extensions DNS 'sémantiques' basées sur nos services ? Imaginez une adresse qui ne serait plus un sous-domaine perdu, mais une véritable identité.

Le concept ? Des extensions comme .immich, .matrix, .mastodon, ou n'importe quoi d'autre...
✅ Souveraineté : On ne dépend plus de l'ICANN ou des tarifs des registrars.
✅ Clarté : identité.peertube au lieu de d'une URL à rallonge.
✅ Privacy : Vos requêtes ne passent plus par les géants du Web.

C'est mon projet 'Tier 1 Personnel' que je souhaite ouvrir à ceux que ça tente.

Seriez-vous prêts à changer vos DNS pour accéder à un Internet plus intuitif et indépendant ?

#mesnumeriquesfr #autohebergement #souverainetenumerique

Kevin Karhan :verified:kkarhan@infosec.space
2026-01-14

@n3wjack nodds in agreement

That's why I have a list if DNS servers handy, and recommend using #OpenNIC + #quad9 / @quad9dns if you can only configure two!

  • Feel free to submit more if you know some.
🏳️‍🌈🎃🇧🇷Luana🇧🇷🎃🏳️‍🌈luana@wetdry.world
2026-01-05

Does anyone actually use OpenNIC?

I selfhost my DNS with unbound, apparently it's simple to use OpenNIC's root server hints but then you remove ICANN ones.

I know OpenNIC's root servers also respond for ICANN domains, but what I was wondering is: can I use ICANN ones for ICANN domains and only use OpenNIC ones when ICANN root servers don't know about a TLD?

#OpenNIC

Kevin Karhan :verified:kkarhan@infosec.space
2026-01-01

@dotmeow @da5nsy granted, #OpenNIC does also resolve the #ICANN #rootzone, and in fact they actually went out of their way to cancel a comflicthig #TLD in their rootzone...

  • The problem is the concentration at ICANN and the ones that tried to fight that #monopoly legally - #NameDotSpace - seem to have gone bankrupt on that endeavour...

Obviously you'd not do a #Kickstarter campaign and try to raise $$$$$$$ in funds if you didn't want to get included in ICANNs rootzone, which paywall the hell out of gTLD applications...

Kevin Karhan :verified:kkarhan@infosec.space
2025-12-30

@da5nsy so basically a .meow @dotmeow as a #NEWgTLD?

  • I mean, that's posssible on #OpenNIC but I guess they want to be in the #ICANN-ROOT so yeah.

  • Wasn't there a .lgbt ?? Or is the #Crowdfunding there cuz it ain't gonna be a for-profit registrar?

Kevin Karhan :verified:kkarhan@infosec.space
2025-12-22

@blogwart hab' hier ne kuratierte Liste an DNS-Servern

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-18

@AdminKirsty I got no problem, but then again I query 20 different DNS servers at the same time, so my shit just works and #OpenNIC has been solid for me...

github.com/greyhat-academy/lis

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-14

@pitrh And now you know.why I use #OpenNIC

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-11

@nono2357 and I agree with @quad9dns in that these are not a solution if we consider #Piracy as a problem.

  • Rather such things will only generate #StreisandEffect and increase said piracy as well as making users change over to alternatives like #OpenNIC

Besides, it should be up to the sysadmins / users to make informed decisions on what they want to filter, because the demands for a corporation, school, home network or hotel are vastly different and IMHO the only legitimate excuse to manipulate #DNS by them would be to prevent #malvertising and twart other #malware from working.

  • But I digress…
2025-11-10

Between February and August, the #Eleven11 was on the news. Using the parallel #DNS root #OpenNIC was nothing new for a botnet. Yet, this botnet was the first known botnet of it's size using the OpenNIC system.

We summarized insights in a new blog post: 161 Days of Eleven11

#DDoS #RapperBot #Eleven11bot #Netscout #ASERT #infosec

2025-11-08

Cloudfalre-dns #Rust Oxy
#Rustlang #Development @torproject
blog.cloudflare.com/introducin

None of it matters if you are utizing #onionsites that don't draw from other parts of the net (like an onion proxy), but be sure to change your trr / uri in your browser to #cloudflare for #https sites with #oniux (network.trr.mode 5 means the network chooses the resolver). Cloudflare has the tor dns monopoly, apparently. Why not something even more #decentralized like #openNIC in the future. Not developed enough now.

#Arti has two versions now
[arti-23c1c907a8c1ccef
arti-27424ad6be662444]
and has not updated documentation for binding local:9150 to socks. No systemd for #Debian yet either. Of course, that doesn't matter with oniux, although it is a mystery what they mean by "leaks" with a socks binding. I suppose a namespace will leak, then. Sure. Timelords, perhaps? Crazy. @micahflee

Kevin Karhan :verified:kkarhan@infosec.space
2025-10-21

@0x4d6165 It's only DNS when you have incompetent people at work.

  • I NEVER had #DNS issues...

But then again I use #ClouDNS & #OpenNIC and not overpriced bullshit like #aws & #CloudFlare!

PurpleJillybeansjillybeans@blog.n8fq.org
2025-08-19
I recently switched my DNS over to #OpenNIC, so my instance should be able to federate with servers on their altTLDs now.
2025-08-17

This thread here suggests that more activity might be expected again from the #OpenNIC parallel #DNS #root .

Not sure, if more activity, and a reborn of the #OpenNICproject leads to less or more abuse from the system. Any opinions from the #infosec community?

#askfedi #askinfosec

House Panther :verified_paw:housepanther@goblackcat.social
2025-08-11

So I just learned about #OpenNIC. Apparently this is a non-profit that operates an alternative DNS root with a far more democratic process for getting top level domains. Granted, you have to use their system but it’s nevertheless cool as hell!

opennic.org/

Kevin Karhan :verified:kkarhan@infosec.space
2025-08-10

Thx @lina for exposing the #Copyrightmafia's #DNS-based #internetcensorship:
cuiiliste.de

As for circumvention: Just use #OpenNIC's DNS servers...

The sheer #Zensursula-Style bullshit is the #IllicitActivity! #ISP|s should have no right to interfere with any traffic (except to defend their own infrastructure from getting hacked) unless explicitly requested by customers to do so.

I do wish @ooni would take a look at the CUII blocklist and add that to their #OONIprobe to test for.

Kevin Karhan :verified:kkarhan@infosec.space
2025-08-02

@TheDoctor512 ROFLMAO!

IMHO sollte solche #Zensursula-Shice woe diese absurde Gerichtsentscheidung als Beleidigung des Intellekts der User*innen strafbar sein.

Ich rate zu #OpenNIC was #DNS angeht:
github.com/greyhat-academy/lis

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst