why are they supporting an obvious fed honeypot??? quad 9 is CIA/FBI/Mossadwhy is no one talking about this
quad9 is german you dunce
wow what a shit decision
>>109804169>Quad9 was initially launched in 2017 through a collaboration that included the Global Cyber Alliance (GCA), Packet Clearing House (PCH), and IBM. The GCA was founded in part by the City of London Police and the Center for Internet Security (CIS), and IBM has deep, historical ties to enterprise and government defense contracts. kys faggot
>>109804155>why is no one talking about thisprobably because the news is from 2 weeks ago? were you off grid hiking or something? check the archive there was plenty of melty.
>>109804155Why would you be using that instead of cloudflare's one? Are you retarded?
so what does /g/ anon use now
>>109804687Control D
>>109804238>City of London Policesquare mile lads represent
>>109804155Because they're not. Their service doesn't use quad9, they're just not supporting poorfags any more.
>>109804155first it was port forwarding and now this?faggots
>>109804401china-syndrome-tier glow
>>109804687unbound
>>109804687Adguard DNS
>>109805497it's a matter of time until every vpn service drops port forwarding. Get used to it
>>109804401This, but actually unironically.
Create your own DoH service https://nochan.net/b/Internet-Crap/20260602-Set-Up-Your-Own-DoH-Service/If you have a Linux firewall such as PiHole, pfsense, etc... then update the OS and verify Unbound DNS is built with libnghttpd.unbound -V | grep --color libnghttp2If so add a LetsEncrypt cert and enable the DoT/DoH listeners and a DNS hint for phones to find the DoT listenerlocal-data: "_dns.resolver.arpa. 4d IN SVCB 2 internal.yourdomain.tld. alpn=dot port=853 ipv4hint=192.168.x.x"Then verify it is working by going to https://tls-ech.dev/
>>109806454won't it make me stand out since stuff likehttps://browserleaks.com/dnswill show my vps ip?
>>109806478It would for those tracking what DNS server you use. Its up to you to decide your OpSec/Threat vectors that realistically apply to you.
>>109804401
>>109806454thank you anon
>>109804401Because cloudflare logs every request you dumbass.
is Mullvad still the most secure VPN service to date for common man usage?
>>109807155Depends, does it hide the fact its a VPN or can I easily block it?
>>109804169I dont know anything thats "German" and not a fed honeypot.Probably because its an occupied country that doesn't even have a constitution, so glowfags outsource their illegal shit to there, similar to how they outsourced torture prisons to Eastern Europe and guantanamo.
>>109804155who is funding this crap anyway?
using a vpn is pedo tier schizo
>>109807657as such a good reason to block VPN's on forums and chan sites.
>>109807693dats right
>>109804687CIRA Canadian Shield DNSRan by the leaf organization that handles the .ca TLD
>>109804965They do a lot of cybercrime investigations outside of their territorial jurisdiction.
What is the consensus on Quad9 vs AdGuard's
>>109807693they should also block staff from using a VPN as well. Not just users, not sure why staff get exempt from using a vpn.
fuark i've been using quad9 for a year now
>>109804169>quad9 is (honeypot the country) you dunceWas meinte er damit?
>yeah it was founded by the most glowing associates possible but t-t-trust me it's very privacy respecting and uh... based (on what?) in switzerland now!!!lmao
>>109806454The root servers don't support TLS. If you do your own recursive resolver to the root servers (like Unbound), anyone can see your connections to the root servers because your connection to them is not encrypted.
>>109809735so what's the way forward? how do you encrypt the root queries. mullvad DoT I've been using
>>109809773dnscrypt-proxy running ODoH and unbound
>>109809773The way forward seems to be this >>109809806 (though I'm unsure how to set it up with Unbound as well), and then to get websites to embrace encrypted client hello (ECH). Most websites do not support ECH yet, but some do. It's also important to remember that all of this schizo shit will only ever potentially hide the domain names of the websites you're connecting to. It will not hide the IPs of the websites you're connecting to, so your ISP will still see them. Also, even if you set up DoH/DoT, if ECH is not enabled on the websites you're visiting, then your ISP will see the plaintext domain of the website you're connecting to anyway because the SNI handshake leaks the domain in plaintext. Assuming ECH is on the website, there is probably some security benefit to doing all this. Since many websites get served by cloud providers who share their IPs with many other websites, it thus makes it harder for your ISP to determine who you're actually connecting to if the only IP they see is a cloudflare one a million other sites use. But again, the domain is only hidden if ECH is enabled on the website.
>>109809984so is it worth setting it up as a general practice to blind the ISP?
>>109810397yes this >>109809984 pretty much.if the destination is an unencrypted site or an un-sandboxed connection your ISP will see the destination IP in plain text even though it may not be the specific page path if it's HTTPS
>>109804155my general rule is to never do stupid shit on the internet because the internet isn't private nor anonymous but I just don't want anyone in my business even though I have nothing to hide and don't do foul shit. simply put VPNs are dead and so too is privacy
>>109810397Maybe? dnscrypt-proxy (in anonymized or ODoH mode) is not a VPN. Neither is DoT or DoH. If you're expecting to get the same privacy as a VPN from setting these up, you're misinformed. As I said in the first post, the only way that your ISP will not see the root domain of the website you visit (ex, 4chan.org) is if you are using DoT/DoH/dnscrypt-proxy/maybe something else AND your browser AND the website you're connecting to have ECH turned on. If ECH is not enabled by all parties, your queries are still unmasked via the unencrypted SNI handshake, even if you use one of the above technologies. Even if ECH is enabled and working, and you're using one of the above technologies, the IP of the website you're visiting will still be visible to your ISP.ECH is new and many websites don't support it yet. You can check if a website supports it by running dig type65 4chan.org or putting the domain into https://dns.google/, changing RR type to HTTPS, and clicking resolve again. If the response contains ech=..., the website has ECH up and running.tldr: this stuff has some degree of privacy benefit but if you're a true schizo you'll need more
dig type65 4chan.org
ech=...
>>109811177>if you're a true schizoi think the true schizos live in a cabin in the woods
>>109809735Unbound can cache the root zone and hold TLD cache as long as you wish. There are plans to push for all the authoritative NS to do TLS but that is a ways out. Either way I am fine with talking directly to the root/TLD servers rather than handing all my data over to glowie DNS providers.
>>109811264But how long can you effectively cache the lookups? Don't IPs get rotated relatively often? This was the question I was trying to answer when researching this stuff. Good to hear that they're planning to do TLS on the authorative servers though. Do you have any more info on that?>Either way I am fine with talking directly to the root/TLD servers rather than handing all my data over to glowie DNS providers.Given that the lookups are all unencrypted anyway, can't anyone (especially your ISP) see them?
>>109811304>Given that the lookups are all unencrypted anyway, can't anyone (especially your ISP) see them?They can and they do not care what I browse. I know all of them and they all know me. Yes they can see me going to 4chan and they could not possibly care less.As for caching, one can set up a cron job to do hourly re-validation of domains one uses and a bunch of domains one does not use to mix it up. Unbound can also pre-fetch domainsIf I was doing something shady I would be using methods that neither my ISP nor glowies nor anyone else could see and I would do it from someone elses IP. Thankfully I am boring.There's no new news on SOA doing TLS at the moment its still in talks. Dont know why, it's trivial to set up.
>>109804931I'm willing to bet that you're the only intelligent person on this board
>>109811177thank you anon
>>109804687I run my own DNS resolvers. If you can read, and have a bare metal server or VPS, it's really fucking easy, and actually kind of fun. The fun factor quadruples if you make it publicly accessible too.
>>109807155Yes. Mullvad is by far the best.
>>109812058the best at sucking state dick
>>109812242solid state
>>109809806>>109809984The one thing I'm confused about with dnscrypt-proxy is how to vet the relays. If everything is encrypted going to the relay, does it even matter? Are there lists of the good relays?
>>109804155just like the port forwarding, MUHHH RUSSIA!!!Also the founders are giga faggots I don't trust them after leaks they were funding some political group that literally goes against their principle written in their site of muh privacy and whatever
>>109806454Is the VPS owner seeing all your traffic a concern here? Or maybe you could set Unbound to get rid of its logs often?
Their DNS always blocks dnsleaktest so they were censoring sites sponsored by other vpns anyway.
>>109804687Wikimedia DNS is what I've been using.
If you're doing something where your DNS is your main protection, you're a retard.Privacy is binary.You either do the maximalist approach in every single aspect, as well as spending actual time doing your own research to keep up with news and development - or you do nothing.Every half measure, even if stacked, equates to 0.
>>109804687I currently use dnsproxy forwarded to my paid NextDNS account. I used to use unbound for the prefetching, but OpenWrt's package is gimped. I used DNS over HTTPS/TLS on my local network for speed and ECH.
>>109806791you're thinking of google, cloudflare logs about the same as quad9>>109804401depending on your location controld is faster >>109804687i use dnscrypt-proxy2 on my router with everything redirected to it, which queries cloudflare/controld/nextdns/quad9/plan9dns/cryptostorm
>>109804155Host your own DNS
>>109804155Why isn't everyone using Technitium? Are /g/tards terminally stuck in the past living under a rock?
>>109813839 British reddit slop tier dns for larpoids
>>109813839I've seen this recommended a lot. Why do people recommend this? I looked at it and it didn't seem to do anything other big boys like bind or Unbound did.
>>109813714>I used to use unbound for the prefetching, but OpenWrt's package is gimpedInteresting, why was it gimped?Also, what do you think about this >>109812672Wondering how to find safe relays. For ODoH there are only two relays, and one is run by the guy who made dnscrypt-proxy. Is that sketchy or fine?
>>109814005+100000 izzat has been deposited into your account>>109814041It's a fully featured self-hosted, recursive DNS 2ith precaching ootb with blocklist support. It does more than pihole, adguard, and unbound combined. It's the natural progression of all who use pihole, adguard, and unbound in that order.
>>109809469can i have mod
>>109814052>Interesting, why was it gimped?iirc the package wasn't compiled to support DoH, only DoT. That's the only reason I'm using dnsproxy.
>>109804155>why are they supporting an obvious fed honeypot??? quad 9 is CIA/FBI/Mossadcause i said so
DoQ is da way
>>109814052>For ODoH there are only two relaysdnscrypt also has another implementation that is equivalent to odoh, with a lot more relays for it. i think that's just the ones labelled "dnscrypt" in this list https://dnscrypt.info/public-servers/
>>109804155is this why i've started getting spurious dns resolution errors you NIGGERS
the only thing better than ODoH/T is a VPN and TOR. the only going better than a VPN of TOR. browsing the clearnet with TOR isn't bad at all, provided that the sites you visit have not blocked it and not put you thru captcha hell
>>109816116ODoQ*
>quad 9 is CIA/FBI/Mossad
>>109816150why would DoQ be better? it's easier to identify as DNS traffic
>>109806454about how much resources does it take to run such a service and why couldn't it run on everyone's device?
>>109816210it's fasterand yes it's definitely harder to identify DoT/DoH when ISP sees the same host in the client hello
>>109815903Yes, that's the "anonymized mode" which is similar to ODoH. I don't know which is more secure, but they're both decently secure outside of the SNI stuff which is always a problem. The anonymized mode relay list is here:https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/refs/heads/master/v3/relays.md/But my problem is I don't know which one to choose and which ones would be safe, or if the choice would even matter.
>>109816150>>109816415Doesn't thi just do what DoT and DoH do?
>>109817398yes but over quic
>>109809573>the European UnionBiggest red flag in that image by far.
>>109814074Buy an ad
>>109819236Buy a cock, troon.
>>109804401>goyflareeat shit and die