[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: opendns.png (793 KB, 1617x1071)
793 KB PNG
Do you use/trust OpenDNS?
If not then what is a good alternative?
>>
quad9, opennic
>>
>>109610861
>quad9
this goes down more often than adguard even
>>
pihole
>>
Your own VPS. Trust no one.
>>
search for lifewire+dns
>>
File: 1706819426772624.gif (292 KB, 343x278)
292 KB GIF
>>109610822
>>
File: 1763313907550773.gif (43 KB, 294x235)
43 KB GIF
>>109613139
>>
>>109610822
>If not then what is a good alternative?
Root servers + unbound.
>>
>>109610822
I have Adguard home running on my router using adguard and quad9 DNSCrypt servers
>>
>>109610822
I've seen her on blacked.com
>>
>>109613139
>>109613449
idgi

>>109614933
cus of this?
>>
>>109610822
Unbound DNS talking directly to the root servers. I enable a DoH and DoT listener on it so I get ECH. Easy to set up.
>>
>>109610822
nextdns and controld are pretty nice
opendns is objectively bad however you look a it
>>
>>109611311
>Trust no one
Pretty hard in the case of DNS
>>
>>109610822
OpenDNS?
>>
>>109610822
i use adguard home
it uses quad9 by default and cloudflare as fallback
tried opennic but they're too slow
>>
>>109610861
>he doesn't know
FEDS
>>
>>109614933
You are a very strange person.
>>
>>109615053
Unbound+Mullvad DoT and you're good to go. Same can be done at the router level.
>>
>>109618249
I'm good with Unbound + Root/TLD servers. The only way I add encryption on the outbound side is if one day all the TLD/SOA DNS servers enable TLS. Other 3rd parties need not enter into the mix for me.
>>
>>109619199
I respect that
>>
File: 1696550655473901.jpg (142 KB, 595x572)
142 KB JPG
>>109610822
>>109613449
*sigh* it's so tiresome
>>
I do not trust OpenDNS because they are a private company and I don't care enough to research their ties to israel

i use libredns because it's not a business, they're open source advocates, they have dot/doh dns encryption, they support privacy and free speech, and they are ran by free speech activists. if there are ties to israel, someone will try and bitch about it to me, so i will care enough then to research both of them, but until then, libredns it is
>>
File: 1759884613966.jpg (295 KB, 1080x1150)
295 KB JPG
>>109619945
>libredns
is it safe now?
>>
>>109620274
I'm not seeing any connection to israel yet
>>
File: file.png (80 KB, 840x438)
80 KB PNG
That didn't take long
Still looking like libredns is the choice
>>
>https://hostdir.net/dns-resolvers/libredns
>Community-run resolver operated by LibreOps, a small Greek non-profit. Ad-blocking by default. No anycast; single-location infrastructure with the trade-offs that brings. Useful when you want a non-commercial alternative.
>>
>>109610822
NextDNS is p good
>>
>>109620403
Are they? They have a profit motive.
>>
File: dns.png (40 KB, 948x361)
40 KB PNG
What about Wikimedia DNS?
>>
>>109610861
fpbp
>>
>>109610822
unbound
>>
>>109610861
>quad9
Retard
>>
>>109620670
absolute moron
>>
>>109619199
yeah but your ISP can still see every unencrypted DNS request you make to the TLD servers tho
>>
>>109613469
>>109615053
>>109618249
>>109620676
This is the GOAT, right?
>>
>>109622163
It is for me. I can view what has requested what, add my own ad-blocking rules. If I wanted to hide DNS from my ISP I would just run it on a VM somewhere. Setting up DoT and DoH listeners is trivial.
>>
>>109622163
definitely not this guy >>109615053. he clearly doesn't understand what he's doing and what he is advocating for actually works.
>>
>>109622200
Easy peazy and I do it all the time.

https://nochan.net/b/Internet-Crap/20260602-Set-Up-Your-Own-DoH-Service/
>>
>>109622199
yeah but a listener only handles traffic coming from devices inside your house to your local Unbound serve
>>
>>109615053
>>109622218
enabling a DoH/DoT listener on a home Unbound server does not grant ECH capabilities to web traffic buddy, and because your outbound Unbound traffic to Root servers is unencrypted plaintext, your ISP still sees every single DNS query anyway... what are you don't to achieve?
>>
>>109622239
>what are you don't to
yes
>>
>>109610822
I use Cloudflare's DNS because it is good and helps keep the Internet healthy.
>>
>>109622239
Everything I documented is required to make ECH work so in fact I am correct. Without DoH you can not make use of a website that has implemented ECH. Fact. Also confirmed here https://tls-ech.dev/ So in fact I am right. Stop trolling.
>>
>>109622239
trying* to achieve
>>
File: file.png (19 KB, 595x303)
19 KB PNG
>>109622259
Thanks!
>>
>>109622258
this post glows
>>
>>109622265
To be fair cloudflare does help with BGP peering issues but their DNS system is unrelated to that afaik
>>
>>109620354
>jew investing in isreal
>"foreign"
???
>>
>>109622274
Foreign to Israel, yes. Israelis invest into foreign countries, sometimes heavily. This is not a secret.
>>
>>109622259
I understand and recognize Joe solid your structural setup is but ur conflating where the ECH keys are fetched from with how your own DNS server handles them.
>>
>>109622298
how*
>>
>>109622298
What if you just store your DNS queries (say top 600) websites and their IP addressses locally, along with any needed SNI/domain name routing info, stop sending DNS queries period, and pin all the certificates locally? Then what? Straight up nothing leaving besides encrypted data at that point.

>inb4 sni dpi
well just use wireguard to one vps and keep your list of dns routing local

block as much traffic you can at the dns level, since you're running your own. the rest? ublock origin.

Now what? What can you do beyond traffic shaping?
>>
>>109622298
>from with how
bro you might need some rest or am ambulance
>>
>>109622326
that's a highly theoretical "paranoid-tier" network design and you're just moving away from standard networking rules entirely... what about Anycast and dynamic IPs??? CDNs, certificate pinning etc.? the biggest flaw is that you think achieved ultimate privacy with this theoretical setup, but in reality you just shifted the entire problem to a hosting provider. vps sees everything...if you or someone actually built this, the next step in advanced traffic analysis is Website Fingerprinting
>>
>>109622387
thanks claude
>>
File: 1761182477095349.jpg (17 KB, 500x333)
17 KB JPG
>>109622415
breh...I accept your concession
>>
>>109622425
concussion*
>>
>>109622387
What if I don't use adversarial websites
>>
>>109610822
I'm a good leaf and use the leaf DNS resolver run by the leaf authority that maintains the .ca domain registry
https://www.cira.ca/en/canadian-shield/configure/summary-cira-canadian-shield-dns-resolver-addresses/
>>
>>109622445
You're into one right now.
>>
>>109622452
Nope. Not at that level. 4chan is not adversarial to me.
>>
>>109622457
>to me
kek pure comedy



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.