Live data from Hacker News

How to keep your ISP’s nose out of your browser history with encrypted DNS

arstechnica.com

121–130 of 195 posts

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#121
post #4

Isn't there an option to polute the information the ISP sees to such a level that their information is useless? E.g. contact a friendly service that gives back N different random domain names; then lookup those domain names, spread over, say, an hour; then repeat.

I just realized I'm obfuscating my internet usage inadverently. Here's how:

Good source of reasonable randomness is twitter. I've set up a scrapper for various twitter accounts and I'm downloading every page that is linked by those accounts automatically.

With this approach you can even select what you want to look like based on your browsing data by selecting proper accounts. Gold bug? Bitcoin fool? Knitting expert? No problemo. ;)

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#122
post #40

Earlier quoted context omitted.

I'm still pissed off we didn't get encrypted SNI in TLS 1.3 It would've broken so many dpi based censorship systems in countries like Iran, Turkey, and Russia.

We’re working on it.

(for the lazy: eastdakota's profile claims to be the CEO & co-founder of CloudFlare)

Thanks & very, very good luck!

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#123

If you care about privacy, use your ISPs DNS servers. Your ISP can see exactly which websites you're visiting regardless of how you do DNS, thanks to being able to see which IPs you're sending packets to, and thanks to SNI. The only thing you get from adding some third party encrypted DNS service to the mix, is an additional party which can also see what websites you're visiting.

Not every site uses SNI. Most probably do not. Not every site uses custom DNS for their CDN, either.

Your ISP knows way less about you if you avoid their DNS. And they are the only ones that know your legal name and billing address, usually.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#124
post #110

I cannot begin to understand how is it better to reveal your DNS access patterns to the global company like Cloudflare, as opposed to revealing them to your local ISP? Who do you think can smoother monetize your data - your local ISP or Cloudflare? Or maybe Cloudflare solemnly promised never to do it? If an effort is to be taken, the best thing is to run your own DNS resolver that will query root servers and follow t…

It's fragmenting the data - CloudFlare _only_ gets your DNS data, whereas your ISP has DNS, content of non-HTTPS traffic (Cloudflare gets a non-zero percentage of this anyway), billing information, real identity etc. Your ISP can _immediately_ tie your DNS records to a real identity (or a member of your household at the very least), whereas CloudFlare can only make inferences from the data and the source IP location. It gives two companies an incomplete picture, rather than one knowing EVERYTHING. CloudFlare promise to not do so is also a non-zero consideration - it's clearly unenforceable/you would never know, but the mere promise is probably better than many ISPs.

I'd also say most users' ISPs are probably are global companies (or at least national) anyway.

> the best thing is to run your own DNS resolver that will query root servers and follow the chains directly

Only if the first step is also encrypted. If it is plain DNS, then your ISP can see the requests almost as easily as if going to their own servers (or transparently redirect the requests to their servers).

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#125

From the article it seems like 'DNS over HTTPS' (DoH), seems to be the winner . Seems the authors best advice is to set up DoH via DNSCrypt Proxy 2, possibly using a raspberry pi to make it easier to manage ur whole network. Do people here agree this is a pretty good approach?

I thought that dnscurve was the method to actually prevent domain snooping. Regardless, I think running your own authoritative dns which updates from root servers is the real way to go.

Unless you are using encrypted DNS, I'm not how that helps -- even using your own resolver, your ISP can sniff the content of the requests (though it might be a legal rather than a technical hurdle -- they can only legally monetise requests that go to their servers -- depending on jurisdiction?).

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#126

If you care about privacy, use your ISPs DNS servers. Your ISP can see exactly which websites you're visiting regardless of how you do DNS, thanks to being able to see which IPs you're sending packets to, and thanks to SNI. The only thing you get from adding some third party encrypted DNS service to the mix, is an additional party which can also see what websites you're visiting.

Not every site uses SNI. Most probably do not. Not every site uses custom DNS for their CDN, either. Your ISP knows way less about you if you avoid their DNS. And they are the only ones that know your legal name and billing address, usually.

SNI is part of the first message a TLS client sends to the server - the Client Hello. TLS clients that support SNI (including all modern browsers) will typically always send the SNI extension, regardless of whether the server supports or makes use of SNI.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#127
post #60

Earlier quoted context omitted.

Sure, however any warrant can get billing data from your hosting provider, or your credit card company will resolve directly to you.

But if your VPS is in a country that's not very friendly to your country, getting data from the hosting provider won't be easy.

Well seeing as all credit cards are basically subject to US law, you'd need to find a VPS that is going to accept say Bitcoin for server space. Perhaps one that is going to accept cash in the mail.

Then hope that said provider is reputable enough to be up to date on their security, and honest enough not to just cave under pressure.

Realistically the VPS solution fails simply because there is no obscuring of traffic. We all know that security through obscurity isn't real security. However if a VPN provider has 1,000 users using their IP block than any specific traffic is harder to isolate to one user. -- Presuming they are honest and not keeping logs.

Running your own VPS means that all traffic is owned by you.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#128
post #126

Earlier quoted context omitted.

Not every site uses SNI. Most probably do not. Not every site uses custom DNS for their CDN, either. Your ISP knows way less about you if you avoid their DNS. And they are the only ones that know your legal name and billing address, usually.

SNI is part of the first message a TLS client sends to the server - the Client Hello. TLS clients that support SNI (including all modern browsers) will typically always send the SNI extension, regardless of whether the server supports or makes use of SNI.

That's why I use IE6: for Privacy reasons.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#129
post #27

Earlier quoted context omitted.

Well if you’re using a VPN then your ISP can’t see much. Some VPNs offer DNS too.

I've spoken to some folks that worked in the VPN provider industry... many of them aren't the bastion of consumer protection they claim/are perceived to be. With the exception of Tor (and even that has been found to have problems) I'm not sure "single-point" anything will really provide you with anonymity. I think it really comes down to your threat model though and what tradeoffs you're willing to accept for anonymi…

there's a huge difference between anonymity when someone is looking for you and anonymity in general.

As you've mentioned, if someone wants to track you through Tor, that's still potentially possible. But that's a completely different ballgame than "My ISP wants to track every last website I visit so they can pair that with my address/billing info to sell to advertisers". I don't think my ISP is going to go through all the hoops to find my Tor exit node, just so they can sell that to advertisers. Passive onlookers can be untrustworthy too.

The shades on my windows keep people from seeing me change, but if someone really wanted to see specifically me naked, they could probably enter my house and make the shades useless.

I still consider the shades useful.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#130

If you care about privacy, use your ISPs DNS servers. Your ISP can see exactly which websites you're visiting regardless of how you do DNS, thanks to being able to see which IPs you're sending packets to, and thanks to SNI. The only thing you get from adding some third party encrypted DNS service to the mix, is an additional party which can also see what websites you're visiting.

So if I make an ssh tunnel and use a remote DNS, my ISP can still log requests? How?
Post reply on HN