» ISP News » 

DNS Providers May Be Forced to Block Internet Piracy Websites

Monday, June 21st, 2021 (1:06 pm) - Score 7,632
dns domain name system logo uk isp

In a possible sign of things to come, Sony has won a key court case in Germany that could force Domain Name Service (DNS) providers, such as Quad9 and eventually others too (Google Public DNS, OpenDNS, Cloudflare etc.), to block access to a website due to internet copyright infringement (piracy).

A DNS provider will typically work to convert Internet Protocol (IP) addresses into a human-readable form and back again (e.g. to examplezfakedomain.co.uk). Most such services tend to be provided automatically by your broadband and mobile provider, thus operating seamlessly in the background, without you ever really being aware.

However, it’s also possible to replace the DNS from your ISP with one from a free third-party service, such as those mentioned earlier (there are many more). The vast majority of you probably won’t feel a need to use custom DNS providers, but if your ISP starts to inject content (adverts etc.) and filtering systems into your website browsing, or suffers a fault / is slow with their own DNS system, then you may decide to try a third-party service.

Suffice to say that those with a little more IT knowledge often prefer to use a free third-party provider in order to benefit from the potential performance, privacy and security improvements. On the flip side, it’s also true that some people will use them in order to circumvent DNS-level website blocking by ISPs, some of which will have been imposed by a court ordered injunction (frequently used in the UK by copyright holders).

Naturally, Rights Holders are aware of this and so, after forcing UK and other ISPs around the world to block websites for internet piracy, some of them are now turning their attention to DNS providers. Torrent Freak reports that Sony Music appears to have landed the first blow by obtaining an injunction in the District Court of Hamburg, which requires the Swiss non-profit DNS-resolver Quad9 to block access to a music piracy site.

The court reportedly ruled that the DNS service was not eligible for the liability protections that other third-party intermediaries, such as ISPs and domain registrars, often enjoy. The court also seemed to accept Sony’s argument that Quad9 already blocks problematic websites (e.g. those that contain malware – viruses, spyware etc.), despite that being a very different consideration.

Quad9’s General Manager, John Todd, said:

“Quad9 derives its threat intelligence from qualified experts on malware and phishing, not from the claims of parties without relevant expertise. We would be unable to maintain our 98% success rate in blocking cyber-threats if we accepted input based on self-interested claims, rather than on forensics and expert analysis.”

The DNS provider and its owner(s) now run the risk of being hit with a fine worth 250,000 Euros per “infringing” DNS query, plus potentially 2-years in prison, if they fail to comply with the injunction (that seems a touch excessive). On top of that, we could imagine that many more Rights Holders may rush to make use of this for similar websites. Naturally, Quad9 intends to appeal and so the battle is not yet over.

The case also raises a question over how long it might be before Rights Holders turn their attention to Virtual Private Network (VPN) providers, although many of those exist in countries where such cases might struggle to reach a successful conclusion. The catch here is that such court processes are very expensive, and the costs soon mount up, for both the Rights Holders and DNS providers.

At this point it may not matter so much what the English court system thinks of this approach – although under current laws they could potentially grant a similar injunction – as many of the aforementioned DNS providers are based outside the UK. In short, when it comes to DNS providers, cases raised in other countries may affect the services used by people in this country. Quad9 may soon become an example of that.

Share with Twitter
Share with Linkedin
Share with Facebook
Share with Reddit
Share with Pinterest
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on Twitter, , Facebook and Linkedin.
Leave a Comment
31 Responses
  1. Anthony Goodman says:

    Someone please correct me if I am wrong. But could someone equally create a story from this ruling saying “DNS Providers May Be Forced to soon move their servers to countries like Antigua out of the reach of the courts”

    1. spurple says:

      Moving to Antigua (or any other suitable jurisdiction) would be a suitable workaround, *for now*.

      Enjoy it while it lasts people, borders are coming to the Internet, whether we like it or not.

    2. Mike says:

      I suspect once they get on the USTR naughty list they’ll curb the sites.

  2. Phil says:

    I’m my own DNS provider, it’s all done by the router, so good luck blocking me, not that I use pirate type sites.

    1. Anthony Goodman says:

      Do you have a guide to lookup over how you acheive this?

    2. dee.jay says:

      And what service is upstream of your router, exactly?

    3. Phil says:

      “And what service is upstream of your router, exactly?” Root Domain name server -> Top Level Domain Server -> Authoritive DNS server. My DNS Resolver is acting like Google DNS, OpenDNS etc but it’s my own DNS resolver for just my network.

      “Do you have a guide to lookup over how you acheive this?” I use pfSense on my router which contains the DNS Resolver, just a tick box really to enable it.

      You can also use Raspberry Pie to run DNSMasq or similar, as well as install DNS Resolvers on Windows or Linux. Once installed and configured you don’t need Google DNS servers or your ISP DNS servers, you have your own DNS server.

    4. Lucian says:

      This is one way of doing that, it’s very easy, too.


    5. Neil says:

      if the ip’s are known and shared with ISP’s, the ISP’s will block them. they can still resolve name to ip to block.

    6. Neil says:

      i forgot to add, they’re going after VPN providers to.

    7. zzing123 says:

      pfSense and OPNSense both use unbound, a resolving DNS server that supports DNSSEC and DNS-over-TLS.

      You can also use a Linux box and just install bind9, and by default it’ll be a fully resolving DNS server.

      The root servers are: https://www.iana.org/domains/root/servers, and the court wouldn’t be able to get them to do anything because they’re geographically dispersed around the world. And can be changed on a whim.

      Quite how a Hamburg court in Germany an EU country thinks it can force Quad9, in Switzerland, a non-EU country to do anything is however an entirely different matter as Quad9 doesn’t need to lift a finger to even pick its nose over this though, so it’s non-news.

    8. Krad says:

      Last time I looked dnsmasq want a fully recursive name server. That’s why pfsense label it as a DNS forwarder Vs unbound which is their resolver

    9. Sam says:

      Most ISP transparently proxy DNS queries and redirect them towards their own DNS servers. Especially blocked domains. So you probably aren’t as free as you think.

      You need to use DoH or DoT to prevent this, which top level domain servers don’t support.

      You’ll need to run something like Unbound or Cloudflared to be truly free!

  3. Mike says:

    In the US there is currently a lawsuit against a VPN provider for supposedly encouraging copyright infringement which if successful will probably be used to go after others.

    Since VPN providers use their own DNS as part of the service, this lawsuit could be easily used against them.

    The biggest danger is logging, as long as VPN providers don’t have to do that, torrent sites can be shielded behind Tor.

  4. Winston Smith says:

    Is the Hamburg court claiming jurisdiction over DNS servers based in Germany or those returning results to users based in Germany or both?

  5. Karl says:

    Instead of playing this cat and mouse game how about addressing these rip of prices for cinema and digital media. It amazes me that digital content cost more in some cases than physical media. And you don’t even own it. The copyright holders are just greedy.

    1. Mike says:

      That’s what filesharing is doing, providing an alternative, and precisely why the media companies want to destroy it, so they can back to £15 per album/dvd etc.

    2. Karl says:

      File sharing has always had the blame for greedy media companies.

    3. Buggerlugz says:

      Its the modern day equivalent of recording the top 40 on a sunday afternoon. It didn’t stop Paul McCartney from making millions and I doubt it’ll stop Tom Cruise or film producers of today either.

  6. GNewton says:

    Can be easily overcome by adding entries in your own local ‘/etc/hosts’ when using a Linux-based desktop PC.

    1. Jimbob says:

      Or Windows C:\windows\system32\drivers\etc\hosts

  7. Damien says:

    SO what if the dodgy site is hosted on cloudflare?

    Like the one I use is.

    1. Mike says:

      Don’t worry they’ll be forcing Cloudflare to expose/censor those sites too.

    2. Damien says:

      okay ta

  8. Mike says:

    Hamburg court seems to delight in issuing bonkers decisions.

    Nevermind, the neverending whack-a-mole will just move somewhere else…

  9. DavidUk73 says:

    Lol. Well that’s the end of piracy then
    Hopefully this will accelerate the move to dns over https

  10. David Howes says:

    I wonder if DNS stored in a blockchain would work

    1. Buggerlugz says:

      That’s a pretty good idea David!

    2. bforeai says:

      you mean like eDNS or Namecoin ? It works perfectly well … but to get it adopted a different story.

    3. I HAVE A QUESTION says:

      Why thought? blockchain can store your data securely.

  11. Nick says:

    Time to run your own recursive DNS with PI hole and unbind. If that’s affected that means the authoritative DNS servers by domain have been forced to obey and they effectively have no domain name any more.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Comments RSS Feed

Javascript must be enabled to post (most browsers do this automatically)

Privacy Notice: Please note that news comments are anonymous, which means that we do NOT require you to enter any real personal details to post a message. By clicking to submit a post you agree to storing your comment content, display name, IP, email and / or website details in our database, for as long as the post remains live.

Only the submitted name and comment will be displayed in public, while the rest will be kept private (we will never share this outside of ISPreview, regardless of whether the data is real or fake). This comment system uses submitted IP, email and website address data to spot abuse and spammers. All data is transferred via an encrypted (https secure) session.

NOTE 1: Sometimes your comment might not appear immediately due to site cache (this is cleared every few hours) or it may be caught by automated moderation / anti-spam.

NOTE 2: Comments that break our rules, spam, troll or post via known fake IP/proxy servers may be blocked or removed.
Cheapest Superfast ISPs
  • Vodafone £19.50 (*22.50)
    Speed 38Mbps, Unlimited
    Gift: None
  • NOW £20.00 (*32.00)
    Speed 36Mbps, Unlimited
    Gift: None
  • Hyperoptic £20.00 (*25.00)
    Speed 50Mbps, Unlimited
    Gift: Promo Code: BIRTHDAY10
  • Shell Energy £21.99 (*30.99)
    Speed 35Mbps, Unlimited
    Gift: None
  • Plusnet £22.00 (*38.20)
    Speed 36Mbps, Unlimited
    Gift: £60 Reward Card
Large Availability | View All
Cheapest Ultrafast ISPs
  • Gigaclear £24.00 (*49.00)
    Speed: 300Mbps, Unlimited
    Gift: None
  • Vodafone £24.00 (*27.00)
    Speed: 100Mbps, Unlimited
    Gift: None
  • Community Fibre £25.00 (*27.50)
    Speed: 200Mbps, Unlimited
    Gift: None
  • Hyperoptic £25.00 (*35.00)
    Speed: 150Mbps, Unlimited
    Gift: Promo Code: BIRTHDAY10
  • Virgin Media £28.00 (*52.00)
    Speed: 108Mbps, Unlimited
    Gift: None
Large Availability | View All
The Top 20 Category Tags
  1. FTTP (3552)
  2. BT (3021)
  3. Politics (1935)
  4. Building Digital UK (1924)
  5. FTTC (1887)
  6. Openreach (1834)
  7. Business (1690)
  8. Mobile Broadband (1478)
  9. Statistics (1408)
  10. FTTH (1365)
  11. 4G (1276)
  12. Fibre Optic (1172)
  13. Virgin Media (1166)
  14. Wireless Internet (1159)
  15. Ofcom Regulation (1147)
  16. Vodafone (845)
  17. EE (834)
  18. 5G (770)
  19. TalkTalk (769)
  20. Sky Broadband (747)
Helpful ISP Guides and Tips

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact