Live data from Hacker News

Quad9 Enables DNS over HTTP/3 and DNS over QUIC

quad9.net

11–20 of 20 posts

Re: Quad9 Enables DNS over HTTP/3 and DNS over QUIC

#13

Does quad9 have a resolver that includes ad blocking?

"Does Quad9 offer content filtering? No. Quad9 has no plans to provide content filtering. Quad9 is dedicated solely to internet security and the blocking of malicious domains, such as phishing, malware, and exploit kits." https://quad9.net/support/faq/#dns_crypt

Re: Quad9 Enables DNS over HTTP/3 and DNS over QUIC

#14

Does quad9 have a resolver that includes ad blocking?

"Does Quad9 offer content filtering? No. Quad9 has no plans to provide content filtering. Quad9 is dedicated solely to internet security and the blocking of malicious domains, such as phishing, malware, and exploit kits." https://quad9.net/support/faq/#dns_crypt

That's a shame, because ad blocking would seem to fit in:

> blocking of malicious domains

Re: Quad9 Enables DNS over HTTP/3 and DNS over QUIC

#18

Earlier quoted context omitted.

"Does Quad9 offer content filtering? No. Quad9 has no plans to provide content filtering. Quad9 is dedicated solely to internet security and the blocking of malicious domains, such as phishing, malware, and exploit kits." https://quad9.net/support/faq/#dns_crypt

That's a shame, because ad blocking would seem to fit in: > blocking of malicious domains

I expect Mullvad will implement all this soon enough, and they do have adblocking with public endpoints.

Re: Quad9 Enables DNS over HTTP/3 and DNS over QUIC

#19
post #16

Quad9 is quite unreliable. Lots of outages and the like.

I've been using Quad9 at home for years as my only upstream DNS resolver and your comment does not track at all with my experience. My ISP goes out more often.

Well, my experience differs. Lots and lots of downtimes in the EU region. Not using the default one, I'm using the one without any malware etc. related protections.

Re: Quad9 Enables DNS over HTTP/3 and DNS over QUIC

#20
post #10
post #4

So many more layers than the original simple DNS protocol.

"Simple" doesn't always mean "better". A car without seatbelts is less complicated than one with, but it definitely doesn't make it a better car. Similarly, The original DNS protocol doesn't have any form of verification: it is is trivially easy for a MitM attacker to alter the responses - or even for a non-MitM one to send spoofed responses "in the blind". It also doesn't have any form of confidentiality: it is triv…

> it is is trivially easy for a MitM attacker to alter the responses

This is true even for DOH. There is no guaranty that your TLS certificate issuer is to be trusted. And, by the way, most of them are in the USA, a country known for its surveillance programs.

Post reply on HN