Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

31–40 of 225 posts

Re: Shutting down our public encrypted DNS

#31
post #16

Does anyone know of good alternatives that also block ads? Seems Quad9 doesn't.

NextDNS https://nextdns.io/

Been using them for years. The price is reasonable too. It’s the only way I found to block ads everywhere on iOS (except the YT app, Mullvad’s Albania wireguard did that)

Re: Shutting down our public encrypted DNS

#32

These was one of the fastest DoH services for pipelined queries over single TCP connection IME, it was much faster than Quad9 for this purpose First Mullvad shuts down its Google search proxy Now its DoH service What's next

They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas

Curious what alternative you found as a replacement. Could you share?

Re: Shutting down our public encrypted DNS

#33

Earlier quoted context omitted.

This is a very important detail. Adblock in 2026 is necessary and DNS will transparently do a lot of that work for you. It isn't just about lightning fast lookups and five-nines uptime anymore.

For blocking, I would much rather run my own service.

I've been loving the Pihole setup I just set up. It uses Quad9 as the upstream provider and then I do all the blocking myself. I used to use NextDNS but this is so much better and free!

Re: Shutting down our public encrypted DNS

#34
post #4
post #2

>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead. Brilliant.

On the Quad9 website: >Since Quad9 already performs DNSSEC validation, DNSSEC being enabled in the forwarder will cause a duplication of the DNSSEC process, significantly reducing performance and potentially causing false BOGUS responses. This sounds dodgy. Surely that means Quad9 can poison my DNS?

Technically yes, in practice the odds your local resolver is validating DNSSEC is slim (and if you're intentionally configured it to do so, switch to a provider that isn't Quad9).

Re: Shutting down our public encrypted DNS

#35

Earlier quoted context omitted.

They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas

Curious what alternative you found as a replacement. Could you share?

I'm not the person you are responding to, but Proton VPN? That's what I switched to after it turned out one of the two Mullvad founders took my money and gave it to a local lunatic politician.

Re: Shutting down our public encrypted DNS

#36
post #21

I'm always wondering whether those centralized privacy services are not the easiest first target for three-letter-agencies to infiltrate to gain access to the most relevant users to track - and what currently would prevent them from doing so if they haven't already ? Maybe, as with the case of many TOR nodes , they might be running them.

> and what currently would prevent them from doing so if they haven't already they arent gods. some people actually have moral standards and dont just do whatever a foreign agency wants them to do

Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.

Re: Shutting down our public encrypted DNS

#37

These was one of the fastest DoH services for pipelined queries over single TCP connection IME, it was much faster than Quad9 for this purpose First Mullvad shuts down its Google search proxy Now its DoH service What's next

They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas

I stopped using Mullvad when they discontinued OpenVPN support (another one to add to the parent list). OpenVPN, if nothing else, provides a wider array of connection options that have a better chance of fulfilling your specific network needs. It supports both UDP and TCP, unlike WireGuard.

I say this respectfully, but Mullvad is perhaps “dumbing down” their VPN service in an effort to simplify their operations and cater to a wider and more general audience.

Re: Shutting down our public encrypted DNS

#38
post #2

>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead. Brilliant.

Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS. [1] https://quad9.net/news/blog/italian-blocking-demands-followi...

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders

Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

Re: Shutting down our public encrypted DNS

#39

Earlier quoted context omitted.

They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas

Curious what alternative you found as a replacement. Could you share?

I've heard AirVPN being mentioned around, if it interests you.

Re: Shutting down our public encrypted DNS

#40
post #21

Earlier quoted context omitted.

> and what currently would prevent them from doing so if they haven't already they arent gods. some people actually have moral standards and dont just do whatever a foreign agency wants them to do

Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.

CIA is not stupid enough to break into a guarded data center in Switzerland or one of the less America friendly EU countries. They tell the NSA to look for security holes and spread narratives that only criminals use VPN hoping that a politician will notice and try to ban them, like what's happening in the UK.

Big tech services are less private than you think but almost every provider who cares about privacy is safer than you expect. Most of the people who work there are committed to their mission, and if they ever get a gag order someone will leak it in no time because they know exactly how to do it without exposing their identity.

Post reply on HN