{"id":6451,"date":"2021-06-30T08:49:53","date_gmt":"2021-06-30T15:49:53","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=6451"},"modified":"2021-06-30T08:49:53","modified_gmt":"2021-06-30T15:49:53","slug":"internet-decentralization","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/community\/internet-decentralization\/","title":{"rendered":"Internet (de)centralization"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Since its &#8220;birth&#8221;, the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this &#8220;ideal world&#8221; started falling apart with the centralization of DNS services among a small number of global DNS service providers.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You may already know that DNS is a core Internet service and used in many ways, including traffic routing. Any DNS outage leads to broken communications and business impact. We already witnessed outages (not only for DNS) caused by attacks and misconfigurations where literally half of the Internet for some consumers was not accessible and these were just the first signs that one day we all can be &#8220;offline&#8221; for hours or even days. What can be considered as a minor disturbance for consumers, for enterprises may lead to huge losses and in extreme cases even bankruptcy.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There was a lot of talk about how DoH pushed from Internet browsers would centralize the Internet but no one highlighted that all enterprise-grade, cloud DNS services actually do the same. Enterprises became dependent on provider&#8217;s points of presence (PoPs) and connectivity to them. Even if your DNS service provider has hundreds of PoPs (unlikely) the issue still exists. I do not mean that there will be an outage with the service itself but it is likely that there are multiple providers in between, and your business depends on the reliability of all of these 3rd party providers without you having any direct contract to support it (signed by you or your vendor). That just increases the number of possible failure points you may or may not need to take into account while choosing a vendor.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Infoblox has more than 20 years of experience running DNS service for our customers with almost 50% of DDI market share and we were thinking of how to solve the DNS centralization problem and came up with a brilliant idea (honestly speaking it wasn&#8217;t my idea but I run it from the product management side), just let DNS do that which it is meant to do (just resolve DNS requests), and do it on customers&#8217; premises (on-prem) with extended security from the cloud.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Sounds good? Let&#8217;s see how we did it and what options our customers have.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">Unconditional on-prem DNS resolution<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">You would ask how it works &#8211; lets take a look at the diagram below and follow it step by step.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6452\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/decntralization-1.png\" alt=\"\" width=\"941\" height=\"274\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/decntralization-1.png 941w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/decntralization-1-300x87.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/decntralization-1-768x224.png 768w\" sizes=\"auto, (max-width: 941px) 100vw, 941px\" \/><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A client wants to connect to &#8220;example.com&#8221; and a browser sends a request to DNS Forwarding Proxy (DFP) which is integrated with BloxOne DDI DNS service (B1DDI DNS).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DFP has an internal policy engine and validates if &#8220;example.com&#8221; is already a known domain which is used for DNS Exfiltration\/Infiltration\/Tunneling.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If the request was not blocked locally, B1DDI DNS resolves the domain by sending requests to root DNS servers and authoritative DNSs for &#8220;.com&#8221; and &#8220;example.com&#8221;.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authoritative DNS responds back.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The request and the response are forwarded to BloxOne Cloud for security policy validation.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If the request is identified as malicious or should be blocked by a policy, the response will be altered.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DFP will cache the results and respond back to the client.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The client can (or can not) connect to &#8220;example.com&#8221;.<\/span><\/li>\n<\/ol>\n<h3><span style=\"font-weight: 400;\">So what are the major benefits?<\/span><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Are you running a business in China, Russia, Zimbabwe or Argentina where your DNS service provider will unlikely deploy PoP? &#8211; No problem. Your employee will get the same experience as using local ISP DNS servers because all DNS requests are resolved on-prem and a client will be able to connect to a nearest data center, means that the SaaS application latency will be minimal and in some cases he or she will enjoy a localized version of an application (if the app enforces language settings per data center).\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A client doesn&#8217;t depend on communications to the DNS service provider and, with a fail open architecture with base protection on-prem, can be sure that multiple potential points of failure are eliminated. For customers who prefer a fail closed architecture &#8211; see below.\u00a0<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">You may think, what are the potential downsides of the approach?\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Obviously the first DNS request will be resolved a bit longer in comparison with cloud only resolution but keep in mind that it will be the first request only and all following requests will be responded from a local cache.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">You will lose some privacy and your organization may be profiled due to un-encrypted communications with root and authoritative DNS servers (DNS over TLS and DNS over HTTPs for communications between DNS servers).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">You may not like the fail open configuration.\u00a0<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">The first issue is addressed by a solid DNS design and we have you covered if you want to handle issues 2 and 3 &#8211; just don&#8217;t enable the local resolution at all or for locations\/roaming clients you concerned about (the feature is enabled per security policy) or just enable it per application (described below).<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6453\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/decntralization-2.png\" alt=\"\" width=\"941\" height=\"274\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/decntralization-2.png 941w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/decntralization-2-300x87.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/decntralization-2-768x224.png 768w\" sizes=\"auto, (max-width: 941px) 100vw, 941px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The local resolution feature is disabled by default and there will be no changes to how the service works right now. To enable it there is a toggle button per security policy.<\/span><\/p>\n<p><strong>Prerequisites:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unconditional on-prem DNS resolution requires BloxOne Threat Defense and BloxOne DDI subscriptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DFP and B1DDI DNS services should run on the same on-prem host<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">On-prem DNS resolution per application<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">You should already get the idea of how unconditional on-prem DNS resolution works, so what is the difference with on-prem DNS resolution per application?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The idea is similar but instead of resolving all domains on-prem and potentially leaking a lot of information to 3rd party services you may enable on-prem DNS resolution only for applications which are relevant for your business.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Yes, you read this right, you can enable it per application. For example, if your company uses Microsoft Office 365, Microsoft Azure, Salesforce, Dropbox, Google suite etc, you can create a policy rule to enforce on-prem resolution for such applications.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So how it works:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DFPs and BloxOne Endpoints receive list of application and associated domains from the Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">When a request is received for one of the domains:<\/span>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">DFP will use configured 3rd party fallback DNS servers to resolve the request. Please be sure that such a DNS server is nearby.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">BloxOne Endpoint will forward the request to network provided DNS servers.<\/span><\/li>\n<\/ol>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Other requests will be forwarded to BloxOne Cloud as usual.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">You should trust the applications because in this case security validations are bypassed except if you are using a secure 3rd party DNS service (e.g. Infoblox NIOS with DNS Firewall feeds).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The feature works with standalone DFPs, DFPs running on NIOS and BloxOne Endpoints.<\/span><\/p>\n<p><b>Prerequisites<\/b><span style=\"font-weight: 400;\">:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">On-prem DNS resolution per application requires a BloxOne Threat Defense subscription.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a 3rd party fallback DNS server should be configured per DFP.<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">A few closing words<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Internet centralization is an issue which may not only lead to disastrous outages but provides a few big DNS provider companies with monopolized access to users&#8217; data. With Infoblox&#8217;s hybrid approach you can deploy services on-prem, in the cloud or &#8220;mix and match&#8221;, so you can choose what is most important for your company, deploy a relevant architecture and enjoy local DNS resolution even with a cloud only solution.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since its &#8220;birth&#8221;, the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this &#8220;ideal world&#8221; started falling apart with the centralization [&hellip;]<\/p>\n","protected":false},"author":283,"featured_media":2771,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[3],"tags":[107,30,521],"class_list":{"0":"post-6451","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-community","8":"tag-internet","9":"tag-dns","10":"tag-internet-decentralization","11":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Internet (de)centralization<\/title>\n<meta name=\"description\" content=\"Internet (de)centralization. Since its &quot;birth&quot;, the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this &quot;ideal world&quot; started falling apart with the centralization of DNS services among a small number of global DNS service providers.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Internet (de)centralization\" \/>\n<meta property=\"og:description\" content=\"Internet (de)centralization. Since its &quot;birth&quot;, the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this &quot;ideal world&quot; started falling apart with the centralization of DNS services among a small number of global DNS service providers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-30T15:49:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/Taming-the-Hybrid-Cloud.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"660\" \/>\n\t<meta property=\"og:image:height\" content=\"454\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Vadim Pavlov\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Vadim Pavlov\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/\"},\"author\":{\"name\":\"Vadim Pavlov\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/d94c7b52c9309b7ab694e709bcb82974\"},\"headline\":\"Internet (de)centralization\",\"datePublished\":\"2021-06-30T15:49:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/\"},\"wordCount\":1230,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Taming-the-Hybrid-Cloud.jpg\",\"keywords\":[\"Internet\",\"DNS\",\"internet decentralization\"],\"articleSection\":[\"Community\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/\",\"url\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/\",\"name\":\"Internet (de)centralization\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Taming-the-Hybrid-Cloud.jpg\",\"datePublished\":\"2021-06-30T15:49:53+00:00\",\"description\":\"Internet (de)centralization. Since its \\\"birth\\\", the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this \\\"ideal world\\\" started falling apart with the centralization of DNS services among a small number of global DNS service providers.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Taming-the-Hybrid-Cloud.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Taming-the-Hybrid-Cloud.jpg\",\"width\":660,\"height\":454,\"caption\":\"Taming the Hybrid Cloud\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/community\\\/internet-decentralization\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Community\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/community\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Internet (de)centralization\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/d94c7b52c9309b7ab694e709bcb82974\",\"name\":\"Vadim Pavlov\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5953dd194cba8fac3d1c7e1850847002a8b6f6d268f280277851c84d8b801c6b?s=96&d=blank&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5953dd194cba8fac3d1c7e1850847002a8b6f6d268f280277851c84d8b801c6b?s=96&d=blank&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5953dd194cba8fac3d1c7e1850847002a8b6f6d268f280277851c84d8b801c6b?s=96&d=blank&r=g\",\"caption\":\"Vadim Pavlov\"},\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/vadim-pavlov\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Internet (de)centralization","description":"Internet (de)centralization. Since its \"birth\", the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this \"ideal world\" started falling apart with the centralization of DNS services among a small number of global DNS service providers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/","og_locale":"en_US","og_type":"article","og_title":"Internet (de)centralization","og_description":"Internet (de)centralization. Since its \"birth\", the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this \"ideal world\" started falling apart with the centralization of DNS services among a small number of global DNS service providers.","og_url":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/","og_site_name":"Infoblox Blog","article_published_time":"2021-06-30T15:49:53+00:00","og_image":[{"width":660,"height":454,"url":"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/Taming-the-Hybrid-Cloud.jpg","type":"image\/jpeg"}],"author":"Vadim Pavlov","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Vadim Pavlov","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#article","isPartOf":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/"},"author":{"name":"Vadim Pavlov","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/d94c7b52c9309b7ab694e709bcb82974"},"headline":"Internet (de)centralization","datePublished":"2021-06-30T15:49:53+00:00","mainEntityOfPage":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/"},"wordCount":1230,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Taming-the-Hybrid-Cloud.jpg","keywords":["Internet","DNS","internet decentralization"],"articleSection":["Community"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/","url":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/","name":"Internet (de)centralization","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#primaryimage"},"image":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Taming-the-Hybrid-Cloud.jpg","datePublished":"2021-06-30T15:49:53+00:00","description":"Internet (de)centralization. Since its \"birth\", the Internet was decentralized like a well-organized chaos. Globalization and Cloud adoption lead us to a world where the same service can be provided from different locations aiming to be as close as possible to the service\u2019s consumers. A couple of years ago this \"ideal world\" started falling apart with the centralization of DNS services among a small number of global DNS service providers.","breadcrumb":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Taming-the-Hybrid-Cloud.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Taming-the-Hybrid-Cloud.jpg","width":660,"height":454,"caption":"Taming the Hybrid Cloud"},{"@type":"BreadcrumbList","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/community\/internet-decentralization\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Community","item":"https:\/\/www.infoblox.com\/blog\/category\/community\/"},{"@type":"ListItem","position":3,"name":"Internet (de)centralization"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/d94c7b52c9309b7ab694e709bcb82974","name":"Vadim Pavlov","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/5953dd194cba8fac3d1c7e1850847002a8b6f6d268f280277851c84d8b801c6b?s=96&d=blank&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/5953dd194cba8fac3d1c7e1850847002a8b6f6d268f280277851c84d8b801c6b?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5953dd194cba8fac3d1c7e1850847002a8b6f6d268f280277851c84d8b801c6b?s=96&d=blank&r=g","caption":"Vadim Pavlov"},"url":"https:\/\/www.infoblox.com\/blog\/author\/vadim-pavlov\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/6451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/283"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=6451"}],"version-history":[{"count":3,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/6451\/revisions"}],"predecessor-version":[{"id":6456,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/6451\/revisions\/6456"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/2771"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=6451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=6451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=6451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}