Live data from Hacker News

Apple-centric guide to improve privacy and security

gacallea.github.io

11–15 of 15 posts

Re: Apple-centric guide to improve privacy and security

#11
post #8

Note that your ISP can see/log your internet history regardless of which Dns server you use (unless of course you use a Vpn/Tor.) So be aware that using a Dns server other than your isp-provided-one, will result in giving your dns lookups to yet another third party (the public dns provider) without gaining an advantage. It might actually decrease privacy. Therefor, in my opinion, it only makes sense to do this if for…

> Note that your ISP can see/log your internet history regardless of which Dns server you use (unless of course you use a Vpn/Tor.)

Not if you use DNSCrypt which is mentioned in TFA, and quite easy to install. It can't also be MITMed.

If you're using a VPN you can also fail to use DNS over VPN.

The article is furthermore rather specific about using a load of extensions (which is profilable), it suggests 1Password which is expensive (open source alternatives available, also cheaper alternatives available), it suggests WiFi Spoofing which is 20 USD on the App Store (free tools available in Homebrew and /sbin/ifconfig), it suggests some unknown VPN called Mullvad VPN which 'claims' it doesn't log (you never know that for sure). In short, reads like an advertisement without going into specifics about the competition. I, for one, would recommend ProtonVPN because of Secure Core and a wide array of VPN endpoints throughout the world. But I would not say I am an expert about knowing ProtonVPN's competition. Then it goes on: "By the way, should you be doing torrents, use qBittorrent." Why? Why not Transmission? Why not WebTorrent? Why not rtorrent? Etc. Why not use Usenet/NZBs? If you're cool shelling out 20 USD for a MAC spoofer and pay for 1Password why not consider also to pay for a Usenet provider?

Re: Apple-centric guide to improve privacy and security

#12
post #11
post #8

Note that your ISP can see/log your internet history regardless of which Dns server you use (unless of course you use a Vpn/Tor.) So be aware that using a Dns server other than your isp-provided-one, will result in giving your dns lookups to yet another third party (the public dns provider) without gaining an advantage. It might actually decrease privacy. Therefor, in my opinion, it only makes sense to do this if for…

> Note that your ISP can see/log your internet history regardless of which Dns server you use (unless of course you use a Vpn/Tor.) Not if you use DNSCrypt which is mentioned in TFA, and quite easy to install. It can't also be MITMed. If you're using a VPN you can also fail to use DNS over VPN. The article is furthermore rather specific about using a load of extensions (which is profilable), it suggests 1Password whi…

> Not if you use DNSCrypt

That's not correct; Dnscrypt prevents against man-in-the-middle attacks, meaning your dns requests can not be manipulated. However, it does not provide end-to-end encryption.

Re: Apple-centric guide to improve privacy and security

#13
post #11

Earlier quoted context omitted.

> Note that your ISP can see/log your internet history regardless of which Dns server you use (unless of course you use a Vpn/Tor.) Not if you use DNSCrypt which is mentioned in TFA, and quite easy to install. It can't also be MITMed. If you're using a VPN you can also fail to use DNS over VPN. The article is furthermore rather specific about using a load of extensions (which is profilable), it suggests 1Password whi…

> Not if you use DNSCrypt That's not correct; Dnscrypt prevents against man-in-the-middle attacks, meaning your dns requests can not be manipulated . However, it does not provide end-to-end encryption.

DNSCrypt is an implementation of DNSCurve.

DNSCurve.org mentions:

"DNSCurve uses high-speed high-security elliptic-curve cryptography to drastically improve every dimension of DNS security:

Confidentiality: DNS requests and responses today are completely unencrypted and are broadcast to any attacker who cares to look. DNSCurve encrypts all DNS packets.

Integrity: DNS today uses "UDP source-port randomization" and "TXID randomization" to create some speed bumps for blind attackers, but patient attackers and sniffing attackers can easily forge DNS records. DNSCurve cryptographically authenticates all DNS responses, eliminating forged DNS packets.

Availability: DNS today has no protection against denial of service. A sniffing attacker can disable all of your DNS lookups by sending just a few forged packets per second. DNSCurve very quickly recognizes and discards forged packets, so attackers have much more trouble preventing DNS data from getting through. Protection is also needed for SMTP, HTTP, HTTPS, etc., but protecting DNS is the first step."

Your ISP will see encrypted traffic on say port 443 TCP or UDP, and that's it.

Re: Apple-centric guide to improve privacy and security

#14
post #13

Earlier quoted context omitted.

> Not if you use DNSCrypt That's not correct; Dnscrypt prevents against man-in-the-middle attacks, meaning your dns requests can not be manipulated . However, it does not provide end-to-end encryption.

DNSCrypt is an implementation of DNSCurve. DNSCurve.org mentions: "DNSCurve uses high-speed high-security elliptic-curve cryptography to drastically improve every dimension of DNS security: Confidentiality: DNS requests and responses today are completely unencrypted and are broadcast to any attacker who cares to look. DNSCurve encrypts all DNS packets. Integrity: DNS today uses "UDP source-port randomization" and "TX…

I see.. interesting. I read this from the author:

"While not providing end-to-end security, it protects the local network, which is often the weakest point of the chain, against man-in-the-middle attacks." https://github.com/jedisct1/dnscrypt-proxy/blob/master/READM...

So my guess is that for example your dns requests could be intercepted/re-routed to say another dns server of an attacker and Dnscrypt would not notice/protect you against this.

However, indeed your ISP would not be able to see your requests :)

Re: Apple-centric guide to improve privacy and security

#15
post #13

Earlier quoted context omitted.

DNSCrypt is an implementation of DNSCurve. DNSCurve.org mentions: "DNSCurve uses high-speed high-security elliptic-curve cryptography to drastically improve every dimension of DNS security: Confidentiality: DNS requests and responses today are completely unencrypted and are broadcast to any attacker who cares to look. DNSCurve encrypts all DNS packets. Integrity: DNS today uses "UDP source-port randomization" and "TX…

I see.. interesting. I read this from the author: "While not providing end-to-end security, it protects the local network, which is often the weakest point of the chain, against man-in-the-middle attacks." https://github.com/jedisct1/dnscrypt-proxy/blob/master/READM... So my guess is that for example your dns requests could be intercepted/re-routed to say another dns server of an attacker and Dnscrypt would not notic…

I'm not sure whether it does certificate pinning or not. You don't know the security of the recursor either, and there is no E2EE between the nameserver of their domain and you. A hostile recursor could still cause DNS poisoning.

An easy way to remember is that DNSCurve protects you between client and recursor whilst DNSSEC protects from (cc)TLD till name server (while also adding gigantic bloat to DNS requests).

Trust issues often occur at the first hop: LTE (SS7 for example, lol), (public) WiFi (example: hotel, train station), or plain hostile ISPs who hijack DNS requests (like Comcast has done), inject ads, or government interventions (such as during Arabic revolution). DNSCurve/DNSCrypt can protect against these attacks.

Post reply on HN