Live data from Hacker News

Show HN: NextDNS Adds "Bypass Age Verification"

news.ycombinator.com

191–200 of 208 posts

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#191
post #190

Earlier quoted context omitted.

No you wouldn't. The current situation: - You ask Foo DNS Provider for the IP address of pornhub.com - Foo DNS Provider responds with the real IP address - You connect to that address, send a TLS ClientHello containing a Server Name Indication extension of "pornhub.com" What could happen: - You ask Foo DNS Provider for the IP address of pornhub.com - Foo DNS Provider responds with one of their own IP addresses - You…

This is wrong. It shows a fundamental misunderstanding of how certificate authorities (CAs) work. A certificate has to be signed by a trusted CA (one your browser already trusts). A DNS provider could mint a self-signed cert for pornhub.com, but your browser would reject it immediately. Even if they tried to trick a real CA, Certificate Transparency (CT) would expose the bogus certificate: https://en.wikipedia.org/wi…

> A certificate has to be signed by a trusted CA (one your browser already trusts).

Yes.

> A DNS provider could mint a self-signed cert for pornhub.com, but your browser would reject it immediately.

I never said anything about the DNS provider minting any certificates, and explicitly said that the certificate would be provided by PornHub's servers and merely relayed -- verbatim -- through the DNS provider. As well as the rest of the TLS negotiation.

> Instead, NextDNS is very likely abusing the EDNS Client Subnet feature to provide website operators with a spoofed client location.

That's what they are doing now, yes. What I propose is how they can continue to make it work once the website operators catch on and start looking at the ASN information of the source IP address of the HTTP connection.

I am well aware of how CAs and the Web PKI model and TLS work.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#192
post #61
post #42

That’s really cool. I thought you guys had stopped development altogether.

Same; I switched to ControlD when it appeared NextDNS was on autopilot without support or fixes.

I did as well, but went back to NextDNS after a bunch of stuff broke for me on ControlD. Plus, I really like being able to control log retention and they have a server closer to me.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#193
post #190

Earlier quoted context omitted.

This is wrong. It shows a fundamental misunderstanding of how certificate authorities (CAs) work. A certificate has to be signed by a trusted CA (one your browser already trusts). A DNS provider could mint a self-signed cert for pornhub.com, but your browser would reject it immediately. Even if they tried to trick a real CA, Certificate Transparency (CT) would expose the bogus certificate: https://en.wikipedia.org/wi…

> A certificate has to be signed by a trusted CA (one your browser already trusts). Yes. > A DNS provider could mint a self-signed cert for pornhub.com, but your browser would reject it immediately. I never said anything about the DNS provider minting any certificates, and explicitly said that the certificate would be provided by PornHub's servers and merely relayed -- verbatim -- through the DNS provider. As well as…

Ah, ok... a transparent proxy just to hide the origin IP. Thanks for clarifying. A lot of people are assuming full proxying, but I understand you were describing a hypothetical.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#194
post #193

Earlier quoted context omitted.

> A certificate has to be signed by a trusted CA (one your browser already trusts). Yes. > A DNS provider could mint a self-signed cert for pornhub.com, but your browser would reject it immediately. I never said anything about the DNS provider minting any certificates, and explicitly said that the certificate would be provided by PornHub's servers and merely relayed -- verbatim -- through the DNS provider. As well as…

Ah, ok... a transparent proxy just to hide the origin IP. Thanks for clarifying. A lot of people are assuming full proxying, but I understand you were describing a hypothetical.

Right. What I proposed is scarcely different from doing HTTPS over a SOCKS5 proxy. It's just that the proxy would infer your destination from the ClientHello rather than being instructed by the client in advance (Edit: and it would have to assume port 443 -- a safe assumption in the context of a service whose feature is bypassing website content blocking).

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#195
post #188

This sounds like a company using DNS to direct _other_ peoples' web traffic through _their_ proxies. Cloudflare started this way. That's why signing up for Cloudlfare requires using _Cloudflare's_ DNS servers The so-called "DNS trick", which is defintely not a trick, is to redirect traffic though a proxy server. Whoever operates the proxy, e.g. Cloudflare, NextDNS, etc., has control over the HTTPS traffic and _could_…

No, I don't think they are proxying traffic. They are giving the website operators a spoofed EDNS Client Subnet which tricks them into thinking the traffic is coming from a different geolocation.

ECS is popular with third party DNS providers with open resolvers, like Google, but not all software that sends DNS queries sends large DNS packets with EDNS extensions and some www users avoid open resolvers

One of the things that I noticed about NextDNS when they announced their service on HN is that like the other public caches, they too sent ECS, but they claimed they could "anonymise" it

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#196

Earlier quoted context omitted.

It's a great idea to get rid of, I'm shocked a company is this brave to do this. It's not in the interest of any adult to upload their ID so the government can track their web browsing. I didn't want to expose my kid to porn when they were 5, somehow it wasn't a problem because the avg browser use was guided by me, but also the browser blocked porn. When they were a bit older, a teenager, I also lightly guided their…

The solution to spam is that everyone replies to the spam and engages up to the point that human labor is required, thus making it financially impractictable The solution to this problem is not to provide YOUR ID but to provide AN ID, again and again, once per day. Again - cannot scale if a manual check is done by a human somewhere, flipside if it's fully automated now it's game-able

This is the AI we need.

Detect or tag an email as scam -> forward it to an AI agent that will keep the scammer conversing as long as possible.

Basically a tarpit solution but for actual humans.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#197
post #137

Earlier quoted context omitted.

I'm really surprised to see this pop up considering how the NextDNS team seems to have disappeared otherwise. Out of date offerings like you mentioned, coupled with 0 customer support when things break (and things break a lot). New features like this are fine only if the base service works. I can guess that this feature also is going to break soon, and I don't have high hopes for it getting fixed. I moved over to Con…

Same here, I left NextDNS because I didn't trust it anymore. I started using it personally in homelab and just found it to be randomly a bit sluggish at times. Saw other similar reports. Tried to get support and failed. I saw it trying to sell itself as business capable DNS, and considered if it would fit in at work. Then I got an e-mail giving 7 days for me to disable and move all my logs out of the EU region. I was…

In the replies to the reddit thread, I'm seeing a lot of people they tell me they moved to Control D. Some people had complaints about latency of the service and other factors, as it seems Control D doesn't have very extensive worldwide coverage.

But, it definitely seems to be the superior option. It's $40 a year more for the full plan, which is unfortunate, but if they offer more options, better customer support and etc it is probably worth it. NextDNS is $20 and standard Control D is the same price. NextDNS does work, but there is seemingly no support whatsoever.

I came across a Stacksocial coupon that offers $40/yr for the standard plan, so I'm tempted between the two options. The standard option doesn't offer changing location via DNS. That may not be important if you're already using a DNS, but it would be nice to have.

I bought a RPi5 with the intention of turning it into a PiHole but never got around to it, and I don't believe you can use your PiHole's DNS outside of your LAN (for example, if you use it on your mobile device and leave your local wifi, it can't connect to it's local IP).

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#198

Do not promote or use NextDNS, it's essentially abandoned. You will not get any support from the developer when something breaks, and it will break. I tried for a year to contact him before abandoning it. Just check the help forums.

I've used nextDNS for years but the past few weeks its been breaking websites left, right and centre so I gave up on it entirely. Everything feels much snappier since I dropped them for a different option too

You definitely want to be following yokoffing's NextDNS Configuration Guide [1] to set it up. You basically only want to be using one of the Hagezi blocklists [2] and a possibly a few other options based on your preferences.

I have it running on every device in my household and it works absolutely fine. I keep it on Hagezi Pro++, and that requires me to go through and whitelist some sites I use. That can be annoying, so in that case Hagezi Light or Normal should work just fine to block ads/trackers and not break things you have to go in and manually fix.

OTOH, Control D offers free DNS [3] that includes using the Hagezi blocklists and other lists, but it's just a set and forget type setup as you can't look at log files to see if it's blocking stuff you don't want or anything like that. Scroll down to "3rd Party Filters" to see their offerings.

[1] https://github.com/yokoffing/NextDNS-Config

[2] https://github.com/hagezi/dns-blocklists

[3] https://controld.com/free-dns

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#199
post #176

Earlier quoted context omitted.

Age verification doesn't protect minors, so I doubt their ethos changed.

Yeah the non-anonymity part of it is troubling. In HN comment thread for another post, I had hoped that we could come up with a rating system like we have with Movies, TV, Apps, mediated by HTTP Headers. I feel that is all we actually need. Then I can configure a browser a certain way, and the site publisher can just send a header saying "X-Content-Rating: Mature" or something along those lines, and that's it. It wou…

The RTA header has existed for almost 20 years now, but it's nowhere near universal.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#200
post #197
post #137

Earlier quoted context omitted.

Same here, I left NextDNS because I didn't trust it anymore. I started using it personally in homelab and just found it to be randomly a bit sluggish at times. Saw other similar reports. Tried to get support and failed. I saw it trying to sell itself as business capable DNS, and considered if it would fit in at work. Then I got an e-mail giving 7 days for me to disable and move all my logs out of the EU region. I was…

In the replies to the reddit thread, I'm seeing a lot of people they tell me they moved to Control D. Some people had complaints about latency of the service and other factors, as it seems Control D doesn't have very extensive worldwide coverage. But, it definitely seems to be the superior option. It's $40 a year more for the full plan, which is unfortunate, but if they offer more options, better customer support and…

Thanks!

This was a few years ago for me. It also aligned with my personal pendulum swinging back from cloud to on prem.

I switched to local pihole. I didn't really like it though, it felt a bit too toy-like. I then switched to adguard home, and I still use it. I've found it faster, easier and just generally more mature feeling than pihole.

Regarding using it away from local area network, I use tailscale (via selfhosting headscale) and then have adguard home joined on that, with the tailscale IP for adguard set as the DNS server for all my tailscale client devices. The only downside with this I personally face is it can be a little hit-and-miss changing networks on some older versions of Android.

Post reply on HN