Earlier quoted context omitted.
They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.
I assume that all US TLAs have (or could have) access to all data that my ISP logs (or could log). That's just how it is. Given government ~monopoly on force. And that's why I use VPN services. But the same is true for VPN services, regarding US and/or other TLAs. So I use nested VPN chains, to make it harder to get complete data. And when it really matters, I add Tor to the mix. Even if it's heavily infiltrated by U…
Big ISPs aren’t happy about Google’s plans for encrypted DNS
171–180 of 456 posts
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#172Is there a way to set up a big list of round-robin DNS servers in Linux, to at least minimize the amount of navigation history any one DNS provider knows about you?
https://gist.github.com/MatthewVance/5051bf45cfed6e4a2a2ed9b...
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#173While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.
They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.
We still need to encrypt the accessed resource and DNS queries everywhere.
Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#174While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.
They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#175Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#176Earlier quoted context omitted.
They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.
Netflow data, DNS capture, enrichment of cell tower access data (location), reporting on non-usage (idle time, tracking), Bill and household information, credit account usage, etc. SPs are huge sellers in this market. We still need to encrypt the accessed resource and DNS queries everywhere. Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.
I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#177Earlier quoted context omitted.
There is no reason for ISP customers to use ISP DNS, given the available alternatives, and this will become even clearer as more people boot up DoH resolvers as alternatives to Cloud Flare.
Again this is absolutely false. Your ISP, and nobody else, can deliver the lowest latency and quickest path DNS resolution short of other providers paying ISPs for last mile fog boxes (as some DNS providers do). Why can’t my ISP support DoT? But that also highlights a huge misconception about DoT/DoH: it only provides privacy to the resolver . It does not make your requests private in the eyes of the server or spanni…
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#178Earlier quoted context omitted.
This is incorrect. Mozilla is ignoring your os/dhcp configured server and using Cloudflare. Your PiHole no longer sees the traffic. There is a way to configure your network to make Firefox not do this, so that's good. But it's not the default.
Thats also false. Mozilla added a canary domain (use-application-dns.net) that if blocked will default to the local dns resolver. There are several threads in the pihole community about blocking it by default so I expect that will be done before mozilla turns int on for the masses.
That’s what I’m referring to.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#179Earlier quoted context omitted.
I assume that all US TLAs have (or could have) access to all data that my ISP logs (or could log). That's just how it is. Given government ~monopoly on force. And that's why I use VPN services. But the same is true for VPN services, regarding US and/or other TLAs. So I use nested VPN chains, to make it harder to get complete data. And when it really matters, I add Tor to the mix. Even if it's heavily infiltrated by U…
So if VPN over Tor (or Tor over VPN) increases anonymity then why is it the popular advice on the Net is not to do it?
Almost by definition, that means you're worth taking a closer look at.
Once you're under the microscope, you'd better hope your opsec is flawless or that your activities are completely boring, or else the $TLA knows exactly what you've been up to, TOR or not.
Disclosure: my activities are completely boring, and I don't use Tor, VPNs, or anything like them.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#180Earlier quoted context omitted.
Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.
Completely untrue. Those services just need to serve their own DoH endpoint and the user can add it in Firefox preferences. No harder than and arguably easier than the complicated procedure for changing system DNS, and it allows you to block things in your browser that you may not want blocked at the system level for all users.
It sounds harder than my simple “redirect all outgoing DNS requests to my PiHole” rule that I have set up in my router.
No messing with any DNS settings required.