Live data from Hacker News

Thai Database Leaks 8.3B Internet Records

rainbowtabl.es

31–40 of 79 posts

Re: Thai Database Leaks 8.3B Internet Records

#31
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

Well in Firefox you can turn it on: about:preferences#general >> Network Settings >> Settings...

Re: Thai Database Leaks 8.3B Internet Records

#32
post #9
post #4

Earlier quoted context omitted.

I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec. I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server). I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.

Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?

Check out this list in privacytools.io: https://www.privacytools.io/providers/dns/

Re: Thai Database Leaks 8.3B Internet Records

#33
post #9
post #4

Earlier quoted context omitted.

I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec. I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server). I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.

Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?

Yes, well i trust this one:

DoT: dns.digitale-gesellschaft.ch

DoH: dns.digitale-gesellschaft.ch/dns-query

Source:

https://de.wikipedia.org/wiki/DNS_over_HTTPS

https://de.wikipedia.org/wiki/DNS_over_TLS

https://www.digitale-gesellschaft.ch/dns/

Sorry, for not being available in the en-wiki

Re: Thai Database Leaks 8.3B Internet Records

#34
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

Most malicious ISPs disable DoH (ex: Verizon) so it likely wouldn’t have solved this.

If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.

Re: Thai Database Leaks 8.3B Internet Records

#35

Earlier quoted context omitted.

DoH just moves the logging from Thai telecom and moves it to Cloudflare (or, whoever you set up as your DoH server, but most likely Cloudflare), no? I trust CF much more than my ISP, but it makes the potential leak much worse... edit: On the other hand, DoH makes DNS requests independent of ISP, which is nice. ISPs are often monopoly by nature.

Could be interesting to use a list of DoH servers and pick one at random for each DNS query.

dnscrypt-proxy can do that for you, downside slow DNS server means slow DNS responce time

Re: Thai Database Leaks 8.3B Internet Records

#36

AIS is mobile operator hence assign you random IP from the pool every time you reconnect to the network. IP address could be used by many different users during a day, definitely not a household as author states. Looks like useless data for me.

also they probably, like every ISP nowadays know when what IP to who was assigned so dynamic IP is not guarantee for anonymity

Re: Thai Database Leaks 8.3B Internet Records

#37
post #34
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

Most malicious ISPs disable DoH (ex: Verizon) so it likely wouldn’t have solved this. If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.

How do they disable DoH? They block TLS over that port?

Re: Thai Database Leaks 8.3B Internet Records

#38

Earlier quoted context omitted.

If you trust your vps dns, easiest way would be autossh -D and set your browser's socks5 proxy to localhost: and tell it to use remote dns when resolving domains. This requires no wireguard setup, no certificate generation or anything.

I've been doing both and have to say Wireguard is much more performant and stable than an ssh tunnel. Besides, it shouldn't be too hard to set it up on a VPS.

As a counter point about reliability, I've been tunnelling my HTTP traffic (and DNS) through SSH (to get around corporate restrictions and monitoring) for 10 years or so - I don't think I've ever had any reliability issues.

Re: Thai Database Leaks 8.3B Internet Records

#39
post #33
post #9

Earlier quoted context omitted.

Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?

Yes, well i trust this one: DoT: dns.digitale-gesellschaft.ch DoH: dns.digitale-gesellschaft.ch/dns-query Source: https://de.wikipedia.org/wiki/DNS_over_HTTPS https://de.wikipedia.org/wiki/DNS_over_TLS https://www.digitale-gesellschaft.ch/dns/ Sorry, for not being available in the en-wiki

Hadn't seem them before, very interesting. Vielen dank.

Re: Thai Database Leaks 8.3B Internet Records

#40
post #25
post #17

Earlier quoted context omitted.

> ... countries that respect persons privacy May be a long time ago, in a galaxy far away, such a thing once existed. It's a sweet thought though.

You don't even need that to be useful though. In my tinpot banana republic (Australia) ISP metadata retention is required by law, and warrantless access to that is granted to organisations involved in fighting terrorism, child abuse, and other serious crimes - and those agencies include local councils, animal control, the taxi commission, and various horse racing oversight organisations... :sigh: Even moving your met…

Isn't the official language in Belize is English? Aren't South America's routers accessible by the agencies collaborating with the US Govt.?
Post reply on HN