Earlier quoted context omitted.
When all the authoritative servers support TLS I can enable TLS outbound but very few of them do at the moment. At some point someone is decrypting, turtles all the way down. I could of course just do DoT to another instance of Unbound somewhere else but I do not need to do that as my ISP does not care about my queries. I used to keep standby DoT Unbound servers around but I have never once seen a US ISP tinker with…
Yours is not particularly problematic but I've always wondered how come advertising agencies allow highly controversial topics on their billboards in the US. I know some (all?) EU advertisers deny creatives based on optics i.e. "our name and logo is on the billboard frame, we don't wanna get associated with topic X".
Choosing a Public DNS Resolver
81–90 of 143 posts
Re: Choosing a Public DNS Resolver
#82ISP: 1ms to Cloudflare
Cloudflare: 10ms to Cloudflare
Thank you for your attention to this matter.
Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
Re: Choosing a Public DNS Resolver
#83Earlier quoted context omitted.
I pre-cache for speed, verifying records that have expired since I retain the expired records for sites that have intermittent DNS issues and also to throw in domains that I do not use in the off chance someone is logging where I go and when. They will see the Cloudflare top 20K domains hourly. Myself and family members have been able to access sites when others around the internet can not due to infrastructure relat…
Or you could use dnscrypt so ISP doesn’t see your lookups at all
Nothing prevents the ISP from collecting that.
Re: Choosing a Public DNS Resolver
#84Happy NextDNS user. Lots of configurability, including which filterlists to enable, configurable logging etc. Plus it’s reliable and fast from basically anywhere (which is harder to achieve if I ran my own resolvers in the cloud, and anyway I don’t want to have to maintain that).
Yup, same here, especially after hears of messing around with a pihole and got tired of maintaining it. Also, NextDNS works easily with Mullvad VPN, when needed.
Re: Choosing a Public DNS Resolver
#85What would be the additional load if everyone ran a local caching recursive resolver like unbound? It would need to be built into iOS/Android/Linux/Windows/MacOS but what would be the disadvantages? I can see greater load on root servers but caching is specifically designed to reduce that. I can see potential problems for CDNs and equivalent geo-based resolvers. But are they really that bad?
To avoid hitting the root, don't send your queries there! Problem solved! localroot.isi.edu Bias: I created it, and am a author of one potential set of future specifications (rewrite).
What is the primary difference between using an Unbound auth-zone (as described in the RFC) compared to localroot?
Re: Choosing a Public DNS Resolver
#86Earlier quoted context omitted.
When all the authoritative servers support TLS I can enable TLS outbound but very few of them do at the moment. At some point someone is decrypting, turtles all the way down. I could of course just do DoT to another instance of Unbound somewhere else but I do not need to do that as my ISP does not care about my queries. I used to keep standby DoT Unbound servers around but I have never once seen a US ISP tinker with…
Yours is not particularly problematic but I've always wondered how come advertising agencies allow highly controversial topics on their billboards in the US. I know some (all?) EU advertisers deny creatives based on optics i.e. "our name and logo is on the billboard frame, we don't wanna get associated with topic X".
Re: Choosing a Public DNS Resolver
#87Re: Choosing a Public DNS Resolver
#88Earlier quoted context omitted.
Was about to comment this. I actually don't like advert or malware blocking on my public DNS resolvers. It sounds cool but annoying when it misfires. Once Quad9 blocked Halo MCC XBOX Live -> Steam achievements, several fileshare services (probably used for malware somewhere but not my usage) etc... 1.1.1.1 blocked archive.is or got blocked by them or something... Gone back to Google DNS (gasp) for now, yes as a Europ…
I believe cloudflare only blocked archive.is on their "Families" filtered dns. I've been using their normal 1.1.1.1 and haven't encountered any blocks.
Re: Choosing a Public DNS Resolver
#89Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout. ISP: 1ms to Cloudflare Cloudflare: 10ms to Cloudflare Thank you for your attention to this matter. Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
Re: Choosing a Public DNS Resolver
#90Earlier quoted context omitted.
I believe cloudflare only blocked archive.is on their "Families" filtered dns. I've been using their normal 1.1.1.1 and haven't encountered any blocks.
IIRC the block was on archive.today's side as a protest against 1.1.1.1 intentionally not supporting ECS. https://news.ycombinator.com/item?id=36971650 https://news.ycombinator.com/item?id=19828702