Do you use/trust OpenDNS? If not then what is a good alternative?
quad9, opennic
>>109610861>quad9this goes down more often than adguard even
pihole
Your own VPS. Trust no one.
search for lifewire+dns
>>109610822
>>109613139
>>109610822>If not then what is a good alternative?Root servers + unbound.
>>109610822I have Adguard home running on my router using adguard and quad9 DNSCrypt servers
>>109610822I've seen her on blacked.com
>>109613139>>109613449idgi>>109614933cus of this?
>>109610822Unbound DNS talking directly to the root servers. I enable a DoH and DoT listener on it so I get ECH. Easy to set up.
>>109610822 nextdns and controld are pretty nice opendns is objectively bad however you look a it
>>109611311>Trust no onePretty hard in the case of DNS
>>109610822OpenDNS?
>>109610822i use adguard home it uses quad9 by default and cloudflare as fallback tried opennic but they're too slow
>>109610861>he doesn't knowFEDS
>>109614933You are a very strange person.
>>109615053Unbound+Mullvad DoT and you're good to go. Same can be done at the router level.
>>109618249I'm good with Unbound + Root/TLD servers. The only way I add encryption on the outbound side is if one day all the TLD/SOA DNS servers enable TLS. Other 3rd parties need not enter into the mix for me.
>>109619199I respect that
>>109610822>>109613449*sigh* it's so tiresome
I do not trust OpenDNS because they are a private company and I don't care enough to research their ties to israeli use libredns because it's not a business, they're open source advocates, they have dot/doh dns encryption, they support privacy and free speech, and they are ran by free speech activists. if there are ties to israel, someone will try and bitch about it to me, so i will care enough then to research both of them, but until then, libredns it is
>>109619945>librednsis it safe now?
>>109620274I'm not seeing any connection to israel yet
That didn't take longStill looking like libredns is the choice
>https://hostdir.net/dns-resolvers/libredns>Community-run resolver operated by LibreOps, a small Greek non-profit. Ad-blocking by default. No anycast; single-location infrastructure with the trade-offs that brings. Useful when you want a non-commercial alternative.
>>109610822NextDNS is p good
>>109620403Are they? They have a profit motive.
What about Wikimedia DNS?
>>109610861fpbp
>>109610822unbound
>>109610861>quad9Retard
>>109620670absolute moron
>>109619199yeah but your ISP can still see every unencrypted DNS request you make to the TLD servers tho
>>109613469>>109615053>>109618249>>109620676This is the GOAT, right?
>>109622163It is for me. I can view what has requested what, add my own ad-blocking rules. If I wanted to hide DNS from my ISP I would just run it on a VM somewhere. Setting up DoT and DoH listeners is trivial.
>>109622163definitely not this guy >>109615053. he clearly doesn't understand what he's doing and what he is advocating for actually works.
>>109622200Easy peazy and I do it all the time.https://nochan.net/b/Internet-Crap/20260602-Set-Up-Your-Own-DoH-Service/
>>109622199yeah but a listener only handles traffic coming from devices inside your house to your local Unbound serve
>>109615053>>109622218enabling a DoH/DoT listener on a home Unbound server does not grant ECH capabilities to web traffic buddy, and because your outbound Unbound traffic to Root servers is unencrypted plaintext, your ISP still sees every single DNS query anyway... what are you don't to achieve?
>>109622239>what are you don't toyes
>>109610822I use Cloudflare's DNS because it is good and helps keep the Internet healthy.
>>109622239Everything I documented is required to make ECH work so in fact I am correct. Without DoH you can not make use of a website that has implemented ECH. Fact. Also confirmed here https://tls-ech.dev/ So in fact I am right. Stop trolling.
>>109622239trying* to achieve
>>109622259Thanks!
>>109622258this post glows
>>109622265To be fair cloudflare does help with BGP peering issues but their DNS system is unrelated to that afaik
>>109620354>jew investing in isreal>"foreign"???
>>109622274Foreign to Israel, yes. Israelis invest into foreign countries, sometimes heavily. This is not a secret.
>>109622259 I understand and recognize Joe solid your structural setup is but ur conflating where the ECH keys are fetched from with how your own DNS server handles them.
>>109622298how*
>>109622298What if you just store your DNS queries (say top 600) websites and their IP addressses locally, along with any needed SNI/domain name routing info, stop sending DNS queries period, and pin all the certificates locally? Then what? Straight up nothing leaving besides encrypted data at that point.>inb4 sni dpiwell just use wireguard to one vps and keep your list of dns routing localblock as much traffic you can at the dns level, since you're running your own. the rest? ublock origin.Now what? What can you do beyond traffic shaping?
>>109622298>from with howbro you might need some rest or am ambulance
>>109622326that's a highly theoretical "paranoid-tier" network design and you're just moving away from standard networking rules entirely... what about Anycast and dynamic IPs??? CDNs, certificate pinning etc.? the biggest flaw is that you think achieved ultimate privacy with this theoretical setup, but in reality you just shifted the entire problem to a hosting provider. vps sees everything...if you or someone actually built this, the next step in advanced traffic analysis is Website Fingerprinting
>>109622387thanks claude
>>109622415breh...I accept your concession
>>109622425concussion*
>>109622387What if I don't use adversarial websites
>>109610822I'm a good leaf and use the leaf DNS resolver run by the leaf authority that maintains the .ca domain registryhttps://www.cira.ca/en/canadian-shield/configure/summary-cira-canadian-shield-dns-resolver-addresses/
>>109622445You're into one right now.
>>109622452Nope. Not at that level. 4chan is not adversarial to me.
>>109622457>to mekek pure comedy