[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


[Advertise on 4chan]


File: 1758606038130370.png (310 KB, 1080x1976)
310 KB PNG
why are they supporting an obvious fed honeypot??? quad 9 is CIA/FBI/Mossad

why is no one talking about this
>>
quad9 is german you dunce
>>
wow what a shit decision
>>
>>109804169
>Quad9 was initially launched in 2017 through a collaboration that included the Global Cyber Alliance (GCA), Packet Clearing House (PCH), and IBM. The GCA was founded in part by the City of London Police and the Center for Internet Security (CIS), and IBM has deep, historical ties to enterprise and government defense contracts.
kys faggot
>>
>>109804155
>why is no one talking about this
probably because the news is from 2 weeks ago? were you off grid hiking or something? check the archive there was plenty of melty.
>>
>>109804155

Why would you be using that instead of cloudflare's one? Are you retarded?
>>
so what does /g/ anon use now
>>
>>109804687
Control D
>>
>>109804238
>City of London Police
square mile lads represent
>>
>>109804155
Because they're not. Their service doesn't use quad9, they're just not supporting poorfags any more.
>>
>>109804155
first it was port forwarding and now this?
faggots
>>
>>109804401
china-syndrome-tier glow
>>
>>109804687
unbound
>>
>>109804687
Adguard DNS
>>
>>109805497
it's a matter of time until every vpn service drops port forwarding. Get used to it
>>
File: 1.1.1.1.png (183 KB, 1080x1949)
183 KB PNG
>>109804401
This, but actually unironically.
>>
Create your own DoH service
https://nochan.net/b/Internet-Crap/20260602-Set-Up-Your-Own-DoH-Service/

If you have a Linux firewall such as PiHole, pfsense, etc... then update the OS and verify Unbound DNS is built with libnghttpd.

unbound -V | grep --color libnghttp2

If so add a LetsEncrypt cert and enable the DoT/DoH listeners and a DNS hint for phones to find the DoT listener

local-data: "_dns.resolver.arpa. 4d IN SVCB 2 internal.yourdomain.tld. alpn=dot port=853 ipv4hint=192.168.x.x"

Then verify it is working by going to https://tls-ech.dev/
>>
>>109806454
won't it make me stand out since stuff like
https://browserleaks.com/dns
will show my vps ip?
>>
>>109806478
It would for those tracking what DNS server you use. Its up to you to decide your OpSec/Threat vectors that realistically apply to you.
>>
File: 1764533039532992.png (124 KB, 610x613)
124 KB PNG
>>109804401
>>
>>109806454
thank you anon
>>
>>109804401
Because cloudflare logs every request you dumbass.
>>
is Mullvad still the most secure VPN service to date for common man usage?
>>
>>109807155
Depends, does it hide the fact its a VPN or can I easily block it?
>>
>>109804169
I dont know anything thats "German" and not a fed honeypot.
Probably because its an occupied country that doesn't even have a constitution, so glowfags outsource their illegal shit to there, similar to how they outsourced torture prisons to Eastern Europe and guantanamo.
>>
>>109804155
who is funding this crap anyway?
>>
using a vpn is pedo tier schizo
>>
>>109807657
as such a good reason to block VPN's on forums and chan sites.
>>
>>109807693
dats right
>>
>>109804687
CIRA Canadian Shield DNS
Ran by the leaf organization that handles the .ca TLD
>>
>>109804965
They do a lot of cybercrime investigations outside of their territorial jurisdiction.
>>
What is the consensus on Quad9 vs AdGuard's
>>
>>109807693
they should also block staff from using a VPN as well. Not just users, not sure why staff get exempt from using a vpn.
>>
fuark i've been using quad9 for a year now
>>
>>109804169
>quad9 is (honeypot the country) you dunce
Was meinte er damit?
>>
File: 1786296681943842.png (138 KB, 786x756)
138 KB PNG
>yeah it was founded by the most glowing associates possible but t-t-trust me it's very privacy respecting and uh... based (on what?) in switzerland now!!!
lmao
>>
>>109806454
The root servers don't support TLS. If you do your own recursive resolver to the root servers (like Unbound), anyone can see your connections to the root servers because your connection to them is not encrypted.
>>
>>109809735
so what's the way forward? how do you encrypt the root queries. mullvad DoT I've been using
>>
>>109809773
dnscrypt-proxy running ODoH and unbound
>>
>>109809773
The way forward seems to be this >>109809806 (though I'm unsure how to set it up with Unbound as well), and then to get websites to embrace encrypted client hello (ECH). Most websites do not support ECH yet, but some do. It's also important to remember that all of this schizo shit will only ever potentially hide the domain names of the websites you're connecting to. It will not hide the IPs of the websites you're connecting to, so your ISP will still see them. Also, even if you set up DoH/DoT, if ECH is not enabled on the websites you're visiting, then your ISP will see the plaintext domain of the website you're connecting to anyway because the SNI handshake leaks the domain in plaintext.

Assuming ECH is on the website, there is probably some security benefit to doing all this. Since many websites get served by cloud providers who share their IPs with many other websites, it thus makes it harder for your ISP to determine who you're actually connecting to if the only IP they see is a cloudflare one a million other sites use. But again, the domain is only hidden if ECH is enabled on the website.
>>
>>109809984
so is it worth setting it up as a general practice to blind the ISP?
>>
>>109810397
yes this >>109809984 pretty much.
if the destination is an unencrypted site or an un-sandboxed connection your ISP will see the destination IP in plain text even though it may not be the specific page path if it's HTTPS
>>
>>109804155
my general rule is to never do stupid shit on the internet because the internet isn't private nor anonymous but I just don't want anyone in my business even though I have nothing to hide and don't do foul shit. simply put VPNs are dead and so too is privacy
>>
>>109810397
Maybe? dnscrypt-proxy (in anonymized or ODoH mode) is not a VPN. Neither is DoT or DoH. If you're expecting to get the same privacy as a VPN from setting these up, you're misinformed. As I said in the first post, the only way that your ISP will not see the root domain of the website you visit (ex, 4chan.org) is if you are using DoT/DoH/dnscrypt-proxy/maybe something else AND your browser AND the website you're connecting to have ECH turned on. If ECH is not enabled by all parties, your queries are still unmasked via the unencrypted SNI handshake, even if you use one of the above technologies. Even if ECH is enabled and working, and you're using one of the above technologies, the IP of the website you're visiting will still be visible to your ISP.

ECH is new and many websites don't support it yet. You can check if a website supports it by running
dig type65 4chan.org
or putting the domain into https://dns.google/, changing RR type to HTTPS, and clicking resolve again. If the response contains
ech=...
, the website has ECH up and running.

tldr: this stuff has some degree of privacy benefit but if you're a true schizo you'll need more
>>
>>109811177
>if you're a true schizo
i think the true schizos live in a cabin in the woods
>>
>>109809735
Unbound can cache the root zone and hold TLD cache as long as you wish. There are plans to push for all the authoritative NS to do TLS but that is a ways out. Either way I am fine with talking directly to the root/TLD servers rather than handing all my data over to glowie DNS providers.
>>
>>109811264
But how long can you effectively cache the lookups? Don't IPs get rotated relatively often? This was the question I was trying to answer when researching this stuff. Good to hear that they're planning to do TLS on the authorative servers though. Do you have any more info on that?
>Either way I am fine with talking directly to the root/TLD servers rather than handing all my data over to glowie DNS providers.
Given that the lookups are all unencrypted anyway, can't anyone (especially your ISP) see them?
>>
>>109811304
>Given that the lookups are all unencrypted anyway, can't anyone (especially your ISP) see them?
They can and they do not care what I browse. I know all of them and they all know me. Yes they can see me going to 4chan and they could not possibly care less.

As for caching, one can set up a cron job to do hourly re-validation of domains one uses and a bunch of domains one does not use to mix it up. Unbound can also pre-fetch domains

If I was doing something shady I would be using methods that neither my ISP nor glowies nor anyone else could see and I would do it from someone elses IP. Thankfully I am boring.

There's no new news on SOA doing TLS at the moment its still in talks. Dont know why, it's trivial to set up.
>>
>>109804931
I'm willing to bet that you're the only intelligent person on this board
>>
>>109811177
thank you anon
>>
>>109804687
I run my own DNS resolvers. If you can read, and have a bare metal server or VPS, it's really fucking easy, and actually kind of fun. The fun factor quadruples if you make it publicly accessible too.
>>
>>109807155
Yes. Mullvad is by far the best.
>>
>>109812058
the best at sucking state dick
>>
>>109812242
solid state
>>
>>109809806
>>109809984
The one thing I'm confused about with dnscrypt-proxy is how to vet the relays. If everything is encrypted going to the relay, does it even matter? Are there lists of the good relays?
>>
>>109804155
just like the port forwarding, MUHHH RUSSIA!!!
Also the founders are giga faggots I don't trust them after leaks they were funding some political group that literally goes against their principle written in their site of muh privacy and whatever
>>
>>109806454
Is the VPS owner seeing all your traffic a concern here? Or maybe you could set Unbound to get rid of its logs often?
>>
Their DNS always blocks dnsleaktest so they were censoring sites sponsored by other vpns anyway.
>>
>>109804687
Wikimedia DNS is what I've been using.
>>
If you're doing something where your DNS is your main protection, you're a retard.

Privacy is binary.

You either do the maximalist approach in every single aspect, as well as spending actual time doing your own research to keep up with news and development - or you do nothing.

Every half measure, even if stacked, equates to 0.
>>
>>109804687
I currently use dnsproxy forwarded to my paid NextDNS account. I used to use unbound for the prefetching, but OpenWrt's package is gimped. I used DNS over HTTPS/TLS on my local network for speed and ECH.
>>
>>109806791
you're thinking of google, cloudflare logs about the same as quad9
>>109804401
depending on your location controld is faster
>>109804687
i use dnscrypt-proxy2 on my router with everything redirected to it, which queries cloudflare/controld/nextdns/quad9/plan9dns/cryptostorm
>>
>>109804155
Host your own DNS
>>
>>109804155
Why isn't everyone using Technitium? Are /g/tards terminally stuck in the past living under a rock?
>>
>>109813839 British reddit slop tier dns for larpoids
>>
>>109813839
I've seen this recommended a lot. Why do people recommend this? I looked at it and it didn't seem to do anything other big boys like bind or Unbound did.
>>
>>109813714
>I used to use unbound for the prefetching, but OpenWrt's package is gimped
Interesting, why was it gimped?

Also, what do you think about this >>109812672
Wondering how to find safe relays. For ODoH there are only two relays, and one is run by the guy who made dnscrypt-proxy. Is that sketchy or fine?
>>
>>109814005
+100000 izzat has been deposited into your account
>>109814041
It's a fully featured self-hosted, recursive DNS 2ith precaching ootb with blocklist support. It does more than pihole, adguard, and unbound combined. It's the natural progression of all who use pihole, adguard, and unbound in that order.
>>
>>109809469
can i have mod
>>
>>109814052
>Interesting, why was it gimped?
iirc the package wasn't compiled to support DoH, only DoT. That's the only reason I'm using dnsproxy.
>>
>>109804155
>why are they supporting an obvious fed honeypot??? quad 9 is CIA/FBI/Mossad
cause i said so
>>
DoQ is da way
>>
>>109814052
>For ODoH there are only two relays
dnscrypt also has another implementation that is equivalent to odoh, with a lot more relays for it. i think that's just the ones labelled "dnscrypt" in this list https://dnscrypt.info/public-servers/
>>
>>109804155
is this why i've started getting spurious dns resolution errors you NIGGERS
>>
the only thing better than ODoH/T is a VPN and TOR. the only going better than a VPN of TOR. browsing the clearnet with TOR isn't bad at all, provided that the sites you visit have not blocked it and not put you thru captcha hell
>>
>>109816116
ODoQ*
>>
File: 1785324789763935.png (1.23 MB, 1920x1080)
1.23 MB PNG
>quad 9 is CIA/FBI/Mossad
>>
>>109816150
why would DoQ be better? it's easier to identify as DNS traffic
>>
>>109806454
about how much resources does it take to run such a service and why couldn't it run on everyone's device?
>>
>>109816210
it's faster
and yes it's definitely harder to identify DoT/DoH when ISP sees the same host in the client hello
>>
>>109815903
Yes, that's the "anonymized mode" which is similar to ODoH. I don't know which is more secure, but they're both decently secure outside of the SNI stuff which is always a problem. The anonymized mode relay list is here:
https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/refs/heads/master/v3/relays.md/

But my problem is I don't know which one to choose and which ones would be safe, or if the choice would even matter.
>>
>>109816150
>>109816415
Doesn't thi just do what DoT and DoH do?
>>
>>109817398
yes but over quic
>>
File: eudssr.jpg (11 KB, 500x334)
11 KB JPG
>>109809573
>the European Union
Biggest red flag in that image by far.
>>
>>109814074
Buy an ad
>>
>>109819236
Buy a cock, troon.
>>
>>109804401
>goyflare
eat shit and die



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.