DrivesserviceundergroundIfDNSfilteringbecomeswidespread,“underground”DNSservicesandalternativedomainhierarchieswillbeestablished,furtherfragmentingtheInternet,andtakingthecontentoutofeasyviewoflawenforcement.RaisesprivacyconcernsISPshavealwaysbeenabletoinspectandlogDNStrafficthroughtheirnetworks.DNSfiltering,however,raisesthespectreofanISP“spying”ontheircustomersandreportingonthecontentsoftheirDNSqueries.RaiseshumanrightsanddueprocessconcernsDNSfilteringisabroadmeasure,unabletodistinguishillegalandlegitimatecontentonthesameserver.Implementedcarelesslyorimproperly,ithasthepotentialtocausesignificantcollateraldamageandrestrictfreeandopencommunications.
ISOCposition:TalkingPointsandConclusions
DNSisoneofthefundamentalprotocolsonwhichoverallglobalInternetfunctionalityisbuilt
.
DNSfilteringcausesinstability,encouragesfragmentation,andunderminesthefoundationoftheInternet.DomainnameseizuresuffersfrommostofthesameproblemsasDNSfiltering,includingeasycircumvention,failuretosolvetheunderlyingproblem,andencouragementofashadownetworkoutofreachoflawenforcement.
UnilateralmodificationofDNSbehaviorcarrieshighrisks.
Asdetailedinthetableabove,DNSfilteringisincompatiblewithDNSSEC,reducingglobalInternetsecurity;DNSfilteringencouragesthecreationofalternativenon-standardDNSsystems,puttingindividualusersatrisk.BecausealmosteverysystemandserviceintheInternetdependsonDNS,filteringwillaffectmoreusersthanareintended.Filteringcreatesahighlyfragmented,country-by-countryInternetratherthanoneglobalnetwork.WhatisfilteredinPakistanmayaffectusersinPanama.
FilteringtheglobalDNShasriskstousersandwilldecreaseglobalsecurity.
FilteringDNSdoesnotsolvetheproblem.
ChangingtheDNSdoesn’tremovetheobjectionableorillegalcontentfromtheInternet;itsimplymakesithardertogetto.Userswhoaredeterminedtodownloadthistypeofmaterialwillstillbeabletodoso.IfDNSfilteringisusedinmanycountries,thentheseuserswillalsosetup“shadow”Internetstructurestoavoidfiltering,makingitmoredifficultforlawenforcementtoobserveandintervene.
Policymakersshouldfocusonthemosteffectivewaystosolvethe problem.
FilteringDNScausessignificantcollateraldamage.
WealreadyhaveabundantanecdotalevidencethatDNSfilteringwillaffectusersandcontentprovidersengagingincompletelylegalactivities.Forexample,inFebruary2011,USauthoritiesblockedthedomain"mooo.com,"becausesomechildpornographywasfoundonasub-domain.Theblockagealsoaffectedover80,000other(presumablylegal)websitessetupassub-domainsofmooo.com.Thiscollateraldamagecouldbeminimizedbyverycarefultechnicalimplementation,butitcanneverbeeliminated.
7
ThecostofDNSfilteringoutweighspossibleshort-termbenefits.
DNSfilteringhasnon-technicalsideeffects.
Thefundamentalproblemisanon-technicalproblem:howtokeepillegalcontentoffoftheInternet.Solvingthisnon-technicalproblemwithtechnology,suchasDNSfiltering,raisesprivacyandpublicpolicyissues.Basicprinciplesoftheruleoflaw,suchasthepresumptionofinnocenceuntilprovenguiltyandotherquestionssuchasdueprocesshavenotbeenwell
7
BecauseofthewayDNSwasdesigned,domainnamesmappoorlytoindividualsororganizations.DNSnamesactmuchlikephysicalproperty:it'seasytolookupthelistedownerofalotorbuilding,butmuchmoredifficulttotellwhothatownerreallyis,orwhethertheyareoccupyingtheproperty,sub-leasingit,orhaveestablishedamulti-tenantfacility.