Live data from Hacker News

Add doh.nsa.gov – DNSCrypt/dnscrypt-resolvers

github.com

21–24 of 24 posts

Re: Add doh.nsa.gov – DNSCrypt/dnscrypt-resolvers

#21

I like a good April Fool's joke as much as the next guy, but it seems like a git commit is more difficult to roll back. You'd have to make another commit on April 2nd reversing the April 1 commit, right?

`git revert 3f858d836a1d07c5ba682ba327df0711e7ada8fd` ought to do it, no?

Re: Add doh.nsa.gov – DNSCrypt/dnscrypt-resolvers

#22

In some ways, the NSA is actually not a bad choice: it's constitutionally required to uphold free speech (can't censor anything), and I don't think it can sell your data to advertisers either. And, the NSA can collect your data anyway from US based providers via PRISM or NSLs. The main risk is it creating a MITM.

I can’t tell if you’re joking. If this resolver was real, I would rather use a resolver which promises transparency reports and no-logging, and hope it doesn’t fall into the hands of the NSA. Using a resolver by the NSA would guarantee it’s being collected by the NSA.

Both options aren’t very good, so I recommend running your own resolver using Unbound.

Re: Add doh.nsa.gov – DNSCrypt/dnscrypt-resolvers

#23

In some ways, the NSA is actually not a bad choice: it's constitutionally required to uphold free speech (can't censor anything), and I don't think it can sell your data to advertisers either. And, the NSA can collect your data anyway from US based providers via PRISM or NSLs. The main risk is it creating a MITM.

I can’t tell if you’re joking. If this resolver was real, I would rather use a resolver which promises transparency reports and no-logging, and hope it doesn’t fall into the hands of the NSA. Using a resolver by the NSA would guarantee it’s being collected by the NSA. Both options aren’t very good, so I recommend running your own resolver using Unbound.

I'm being a little tongue-in-cheek, but I don't think what I said is wrong. Sure, it's not the best conceivable choice, but I don't think the NSA would be particularly out of place on this list, given that it includes things like "child-safe" censoring servers. It ultimately depends on what your threat model is.
Post reply on HN