SingaporeRep
Member
Benchmark Addict
- Joined:
- Jul 2024
- Posts:
- 227
- From:
- Singapore, SG
$3 Vultr instance in Osaka
Vultr Osaka is good DC. I test there sometimes. But for DNS, single point of failure. Your 12 players maybe okay with downtime, but principle matters.
I run Pi-hole at home on Raspberry Pi 4, secondary to Vultr Singapore. Total cost $3/month. Local queries <1ms, fallback if ISP DNS dies. Benchmarked both. Pi-hole does ~25k qps with caching, enough for apartment.
fio, iperf, geekbench. results or gtfo.
GeorgeNmp
Member
AS64512
- Joined:
- May 2024
- Posts:
- 218
- From:
- Ashburn, US
To bring this back to the actual security question: the original concern was correlation risk. Having registrar and DNS at one company means one support ticket, one legal order, one compromised account can change both ownership and resolution path.
Separate doesn't eliminate risk. If your registrar account is compromised, attacker can still change NS records to evil DNS. But now they need to also compromise the DNS provider to maintain control, or rely on TTL expiration. Adds steps. Adds detection time.
RPKI + DNSSEC with proper DS at registrar closes the loop even with separate providers. Do both.
iBGP, eBGP, don't care, just peer