Safety of pointing Nintendo servers to 95.216.149.205

sven7777

Developer
OP
Developer
Joined
Aug 3, 2018
Messages
20
Trophies
0
Age
34
XP
917
Country
United States
Pretty much all of the instructions on the net for setting up your switch for running CFW (e.g. Atmosphere) indicate the following DNS redirects:

95.216.149.205 *conntest.nintendowifi.net
95.216.149.205 *ctest.cdn.nintendo.net

My question is - who owns 95.216.149.205 and is it safe to rely on that person/entity to not do something malicious in the future with whatever is running on 95.216.149.205? I understand this DNS redirect has worked fine for everyone over several years and is the generally-accepted process to follow, but I'm a bit leery relying on any external server. Is there any way we can get the source code to what is running on 95.216.149.205 so that we could install that same software in our private networks and then we can point the above to our local server instead of 95.216.149.205? That way we know it will always be available and will always be non-malicious.
 

binkinator

Garfield’s Fitness Coach
Member
GBAtemp Patron
Joined
Mar 29, 2021
Messages
6,511
Trophies
2
XP
6,156
Country
United States
Pretty much all of the instructions on the net for setting up your switch for running CFW (e.g. Atmosphere) indicate the following DNS redirects:

95.216.149.205 *conntest.nintendowifi.net
95.216.149.205 *ctest.cdn.nintendo.net

My question is - who owns 95.216.149.205 and is it safe to rely on that person/entity to not do something malicious in the future with whatever is running on 95.216.149.205? I understand this DNS redirect has worked fine for everyone over several years and is the generally-accepted process to follow, but I'm a bit leery relying on any external server. Is there any way we can get the source code to what is running on 95.216.149.205 so that we could install that same software in our private networks and then we can point the above to our local server instead of 95.216.149.205? That way we know it will always be available and will always be non-malicious.
There’s a lot of brewha about the “safety” of it. I’ve seen absolutely zero reason to be concerned. In the even they go offline then you can’t look up addresses at all so there’s no danger there…you’d essentially be offline.

e: there have also been concerns about speed where a GSLB balance site might infer that you are in a geodistant location. If you see this effect and it bothers you, you’re free to change. It’s not the end of the world.

e2: there’s also been the concern of “malicious admin” or “negligent admin” but they have been up for years without incident. I think they have a pretty proven track record.

e3: for the record I have switched to dns:mitm and exosphere.ini to that are built in to Atmosphere now. But I don’t discourage anyone who prefers 90DNS and incognito_RCM…I just include the information so people can. Make their own informed decisions.

e4: the authors of 90DNS include instructions for building your own and include the zone files. they are good people IMO.
 

sven7777

Developer
OP
Developer
Joined
Aug 3, 2018
Messages
20
Trophies
0
Age
34
XP
917
Country
United States
There’s a lot of brewha about the “safety” of it. I’ve seen absolutely zero reason to be concerned. In the even they go offline then you can’t look up addresses at all so there’s no danger there…you’d essentially be offline.
Thanks for replying - my concern is less about them going offline and more about them changing their server so that it does something malicious. I don't know what that "something malicious" might be - but perhaps there would be a way to reshape the traffic in-transit so that every request gets redirected to an actual nintendo server which would allow them to instantly know/target which switches are hacked. Or somehow Nintendo seizes control of the IP for the same end-goal.
 

binkinator

Garfield’s Fitness Coach
Member
GBAtemp Patron
Joined
Mar 29, 2021
Messages
6,511
Trophies
2
XP
6,156
Country
United States
Thanks for replying - my concern is less about them going offline and more about them changing their server so that it does something malicious. I don't know what that "something malicious" might be - but perhaps there would be a way to reshape the traffic in-transit so that every request gets redirected to an actual nintendo server which would allow them to instantly know/target which switches are hacked.
I added some edits…
Or somehow Nintendo seizes control of the IP for the same end-goal.
Think about that for a second…Nintendo goes online, grabs a DNS server and forces you to connect to their servers and break their TOS in spite of you specifically using it to avoid connecting to them? Lawyers would have a hey day with that shit!

e: here’s what I’m currently using…it’s built into AMS
https://rentry.org/ExosphereDNSMITM
 

sven7777

Developer
OP
Developer
Joined
Aug 3, 2018
Messages
20
Trophies
0
Age
34
XP
917
Country
United States
I added some edits…

Think about that for a second…Nintendo goes online, grabs a DNS server and forces you to connect to their servers and break their TOS in spite of you specifically using it to avoid connecting to them? Lawyers would have a hey day with that shit!
Nintendo isn't forcing anyone to connect to 95.216.149.205. Virtually everyone who is running a hacked switch is connecting to 95.216.149.205. If Nintendo takes control of it (which isn't far-fetched because we know how litigious they are), they instantly know who is running a hacked switch. I see no legal entanglements whatsoever.

Question still stands - who is running that IP and can we get the source code to what's running on it? That's the safest method regardless of how reliable/benevolent the owners have been in the past.
 

binkinator

Garfield’s Fitness Coach
Member
GBAtemp Patron
Joined
Mar 29, 2021
Messages
6,511
Trophies
2
XP
6,156
Country
United States
Nintendo isn't forcing anyone to connect to 95.216.149.205. Virtually everyone who is running a hacked switch is connecting to 95.216.149.205. If Nintendo takes control of it (which isn't far-fetched because we know how litigious they are), they instantly know who is running a hacked switch. I see no legal entanglements whatsoever.
No entrapment? No liability? I think it would be a fiasco…creating a situation that didn’t exist prior just so they could cut off services that weren’t in use prior.
Question still stands - who is running that IP and can we get the source code to what's running on it? That's the safest method regardless of how reliable/benevolent the owners have been in the past.
90DNS was brought to us by @AveSatanas

source code is here: https://gitlab.com/a/90dns

https://gbatemp.net/threads/90dns-dns-server-for-blocking-all-nintendo-servers.516234/
 

sven7777

Developer
OP
Developer
Joined
Aug 3, 2018
Messages
20
Trophies
0
Age
34
XP
917
Country
United States
No entrapment? No liability? I think it would be a fiasco…creating a situation that didn’t exist prior just so they could cut off services that weren’t in use prior.

90DNS was brought to us by @AveSatanas

source code is here: https://gitlab.com/a/90dns

https://gbatemp.net/threads/90dns-dns-server-for-blocking-all-nintendo-servers.516234/

How is it entrapment? Nintendo did not entice people to use 95.216.149.205 - everyone is doing it of their own accord. What would be Nintendo's liability? I'm certain their TOS (which we all click through to use the switch) covers/protects them for anything the Switch does during its operation.

90DNS owners/creators is not necessarily the same thing as who owns/operates 95.216.149.205. Are you asserting it's running a version of 90DNS? I have not seen any evidence that proves what 95.216.149.205 is running.
 

Dragon91Nippon

Well-Known Member
Member
Joined
May 14, 2020
Messages
360
Trophies
0
XP
771
Country
Japan
Also unless I'm missing something these are connection test URLs, they don't contain or receive any data from you, they're just there for pings and an HTML test page.
 

MichaelW1980

New Member
Newbie
Joined
Feb 25, 2024
Messages
1
Trophies
0
Age
44
XP
13
Country
Germany
I'm sorry to bring back up this rather old topic, but it keeps coming up if you ask google the same question, as @sven7777 did. I noticed something, that might give the more concerned users of that IP address some peace of mind.

Apparently whatever IP address you sent those two entries of your host file to is merely used for a ping, as far as connecting to a local network goes.

So if you are concerned about 95.216.149.205 being safe, you might want to give the (local) IPV4 adress of your internet router a try. As long as it allows you to ping it, you can establish WIFI / wired connections that way and nothing ever even leaves your home network.
 
Last edited by MichaelW1980,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
    +1
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87 cents. Free shipping from China... It arrived it works and honestly I don't understand how it was so cheap.
    +1
    Psionic Roshambo @ Psionic Roshambo: @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87... +1