DNS Firewalling with MISP and Technitium DNS Server
Postedabout 1 month agoActiveabout 1 month ago
zaferbalkan.comTech Discussionstory
informativepositive
Debate
20/100
DNS SecurityMispTechnitium DNS
Key topics
DNS Security
Misp
Technitium DNS
Discussion Activity
Moderate engagementFirst comment
N/A
Peak period
8
0-12h
Avg / period
2.4
Key moments
- 01Story posted
Nov 27, 2025 at 2:38 AM EST
about 1 month ago
Step 01 - 02First comment
Nov 27, 2025 at 2:38 AM EST
0s after posting
Step 02 - 03Peak activity
8 comments in 0-12h
Hottest window of the conversation
Step 03 - 04Latest activity
Dec 3, 2025 at 5:44 AM EST
about 1 month ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
ID: 46066736Type: storyLast synced: 11/27/2025, 7:40:07 AM
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
No other DNS resolver is going to come close to it's number of deployment*years in operation.
I didn't read the article though, since I'm not going to enable javasript and cookies just to read someone's blag post 8-/
HTML much?
When it comes to Technitium, well, it's written in the blog.
GDPR preempted...
Because bind9 is not a dns server but a collection of all available CVE types for further studying.
"BIND is the de facto standard DNS server"
https://en.wikipedia.org/wiki/Comparison_of_DNS_server_softw...
9 just being the currently deployed version.
A non-wikipedia reference:
https://dn.org/a-comprehensive-comparison-of-popular-dns-ser...
Although this article does state that bind's "configuration files and options require careful attention to detail".
So, maybe it's not appropriate for the modern hype-cycle s/w development model?
In general, I don't think I'm disagreeing with you, so I'm not sure what message the reply is intended to convey.
Technitium seems like another one of those: "My weekend hobby project was to reinvent fire, and the wheel" sort of things, that seem popular on the HN feed.
My favorite feature of bind is "split views". This allows the same service to provide DNS on the local LAN, as well as authoritative DNS to the internet.
Are you kidding? Bind has been the de facto standard for DNS servers for ages but it's just a badly engineered piece of software and had braindead vulnerabilities for decades:
https://www.cvedetails.com/vulnerability-list/vendor_id-64/p...
Already 20 years ago it was common knowledge to never use software that Paul Vixie had touched (bind, vixie-cron, ...) and we used alternatives such as djbdns. Good old times...
And yet somehow, the internet has much bigger problems...
I am curious though, what would TDNS do so that you can replace BIND with TDNS in your homelab/workplace or wherever it is used? I genuinely ask for it so that I can help the original developer with some PRs.
mirror: https://archive.vn/8BCBn