Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

51–60 of 231 posts

Re: Shutting down our public encrypted DNS

#51
post #42
post #9

Earlier quoted context omitted.

Quad9 doesn't have an adblocking DNS service though, so it's not really a replacement.

That's something people should run themselves. I run Adguard Home on my router. Unlike the main Adguard product, Adguard Home is fully FOSS. It's been rock-solid for me, and improves on pi-hole in various ways - like full IPv6 support.

I use Mullvad's adblocking DNS server on my phone which is not always behind my home router.

Re: Shutting down our public encrypted DNS

#52
> Running a privacy-focused public DNS service is a highly specialized undertaking

This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].

[0] https://github.com/hagezi/dns-blocklists

Re: Shutting down our public encrypted DNS

#53
post #3

disappointing, because alternatives matter too. quad9 and other well known servers are potentially blocked by some countries, so the more lesser known services there are the better.

There is always the option of running your own locally.

This is probably service you can host locally with the lowest maintenance and hardware requirements so it isn't even a hassle to do it yourself.

Re: Shutting down our public encrypted DNS

#54
post #40

Earlier quoted context omitted.

Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.

CIA is not stupid enough to break into a guarded data center in Switzerland or one of the less America friendly EU countries. They tell the NSA to look for security holes and spread narratives that only criminals use VPN hoping that a politician will notice and try to ban them, like what's happening in the UK. Big tech services are less private than you think but almost every provider who cares about privacy is safer…

Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?

Re: Shutting down our public encrypted DNS

#55
post #52

> Running a privacy-focused public DNS service is a highly specialized undertaking This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0]. [0] https://github.com/hagezi/dns-blocklists

You can't compare running a single service in your home network with the operations it takes to serve a public DNS

Re: Shutting down our public encrypted DNS

#56
post #52

> Running a privacy-focused public DNS service is a highly specialized undertaking This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0]. [0] https://github.com/hagezi/dns-blocklists

How much traffic is your public DNS serving?

Re: Shutting down our public encrypted DNS

#57
post #55
post #52

> Running a privacy-focused public DNS service is a highly specialized undertaking This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0]. [0] https://github.com/hagezi/dns-blocklists

You can't compare running a single service in your home network with the operations it takes to serve a public DNS

This is a scaling problem, not an intrinsic difficulty. Mullvad already had the infrastructure in place. I suspect the real reason is cost-cutting.

Re: Shutting down our public encrypted DNS

#58

Earlier quoted context omitted.

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

The entire point is that it can't be reasonably enforced with any granularity. Rights-holders want it to be like that so a copyright win in a single country means something has to be taken down globally.

My fear exactly.

Re: Shutting down our public encrypted DNS

#60

Their founder supports Nazis.

[flagged]

They are not far right, AFAICT they are “right” Marxists, probably most similar to Albanian Hoxhaism.

If you aren’t familiar with splits inside Marxism-Leninism, the “left” is most often represented by Trotskyism with the “right” tendency being more like Stalinism and North Korean Juche. (Note that these left/right terms aren’t universally used or applied because every faction claims to be correct.)

Post reply on HN