The attempt to put a positive spin on the ad-version is kind of absurd.
Translation: "We tried to serve ads in a way that broke basic functionality for many people. But we didn't make that much money, so we are going to stop being malicious actors, and we're going to start following the protocols we're supposed to follow."
Except that isn't accurate. I get that's how you see it, but that's just not true.
It's ridiculous to say we broke things for many people. Our growth numbers tell a different story. Doesn't mean DNS nerds didn't like creating an account to re-enable standard nxdomain behavior, but it didn't cause issues for most people.
We made real money from ads, enough to be profitable with a decent-sized (20+) team. But we never saw a way to go from 5m to 50m or 500m with ads though. And we never loved the ads. I just never thought it aligned our interests with our customers in the right way. I get that Google has figured it out, and Facebook and Twitter sort of have, but we couldn't, and didn't want to.
Plus, at the time, you have to recall the browser landscape was wildly different. In fact, it's very possible that we may have created the eventuality of today by doing what we did. Chrome didn't even exist when we started. There was no omnibus. I demo'ed our service to Sundar Pichai back in 2007.
Turns out jblow's right. I banished OpenDNS because it was breaking basic DNS functionality to serve its ads (and is terrible privacy wise), this is the exact bad behaviour from ISP openDNS was supposed to help with.
But don't take my word for it and read this 2009 post from Stephane Bortzmeyer working at AFNIC in R&D in DNS security[1].
As jblow said the whole "no more ads" post reads as PR spin, same goes for your reply to him:
- growth numbers don't tell any story apart maybe from «many people read the "Open" part of the OpenDNS name and turn their brains off» [2].
- DNS nerds run their own DNS and keep away from openDNS for breaking DNS and invading privacy.
- not causing issues for most people doesn't disprove that it did cause issue for many people.
I do remember the browser landscape before openDNS and I'm quite happy to debunk your boasting attempt at being significant. The "search from the address bar" functionality has been around long before google chrome came to existence, actually it was in opera before openDNS existed and even better it allows to choose the search engine and use several with the use of a keyword. This was then added to firefox back in firefox 3. Again don't take my word for it and look a this 2008 post[3].
You hijacked NXDOMAIN breaking many applications in my personal experience. Over the past 4 years I have cautioned hundreds of people not to use this service because of that. It is not an issue that affects "DNS nerds", it affects everyone.
Give me a break they offered a service for free. Sure if they were an ISP I'd agree with you because your paying for the service but otherwise just don't use it?
It's bait and switch though. They claimed they offered a DNS service, but by deliberately breaking the spec, they offered something that wasn't a DNS service. It was something, but not DNS. I don't care how much it cost, it's dishonest.
Sure. I offer a service for free. I will back up all your email! Just forward it all to me and I will make sure you can get it back!
Does that sound like a harmless service? OpenDNS knowingly and deliberately broke the Internet for its customers. I have actually spent time debugging issues it caused just to find that the client was using their resolvers. They were not a free service, they were actively harmful. I am glad the profits are no longer there for them to keep up this malicious practice.
As davidu mentioned, you can make a free account on the site and restore normal NXDOMAIN behavior. Non-broken DNS was opt-in, but it was still a free service.
> It's ridiculous to say we broke things for many people.
Two weeks ago, I had to swap my company's network over to OpenDNS because Google DNS was having an outage. And then a day later, I spent 2 hours trying to chase down a problem running something that turned out was a result of OpenDNS feeding a page full of ads to something that was expecting JSON.
You might not have broken things for all the people that continued to use your service, but you broke things for people like me. And this is a place where people like me hang out....
The application broke because it couldn't handle unexpected input, I think you stated the problem and it was the application. OpenDNS has been clear about returning an HTML page of adverts. I appreciate the category level filter and the ability to block known harmful sites from my family's casual browsing. When my wife or kids want to browse to gun, gambling, typo-squatting or hate sites they'll need to learn how to resolve IP addresses (and I'll be proud of them). I also hope they'll learn to code and safely handle unexpected input.
[Edit: you didn't say your application unsafely handled the input, just making the point and not meaning to sound too snarky]
OpenDNS worked the way it was supposed to. It wasn't the right DNS solution for this situation.
I also don't think OpenDNS is a tool of censorship, as it is so easily circumvented. I hope my children learn how to circumvent tools of censorship and this can be their first practice... Until then it reduces the risk of accidentally going to phishing websites.
I'm only pointing out that in this spesific case it had nothing to do with the robustness of the application.
More specifically: A better application might have warned you about the failing part so that you won't have to go looking for it. Fixing the problem would still include either replacing OpenDNS or working around it.
The relevant question isn't whether it is "breaking things" in the abstract, but whether it is breaking things in a way meaningfully detrimental to end users. Or, if you really want to stretch it, perhaps also include externalities imposed on the "internet as a whole."
In the era before the omnibox, I personally can't see much in the way of "breaking things" on account of OpenDNS. Doesn't mean you and others can't disagree with that, but it's not as cut and dried as your statement seems to imply.
Agreed, I've run into this behaviour several times and it is confusing and annoying, especially while programming. A DNS response for a non-existent domain shouldn't be "this page full of adverts", it should be "this domain doesn't exist".
You are no different from ISPs hijacking all the unresolved names, breaking default web functionalities. I wonder how naive can your remaining users be, to still use your ad-bloated service...
My ISP was no better. And giving my DNS requests over to Google seems retarded, considering they're an ad company first and foremost. I'd run my own DNS server but afaik I'd still need to find a dns provider like google/opendns since DNS is heirarchical, I can't hold the entire internet's worth of DNS entries on my server. If someone could offer up some free DNS providers that I can use I'll point my dns requests to those, thanks.
Translation: "We tried to serve ads in a way that broke basic functionality for many people. But we didn't make that much money, so we are going to stop being malicious actors, and we're going to start following the protocols we're supposed to follow."