Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

71–80 of 240 posts

Re: Shutting down our public encrypted DNS

#71

Earlier quoted context omitted.

Source?

Translation: one of Mullvad’s two cofounders has donated money to Örebropartiet, a left-leaning Swedish political party that promotes strict and restrictive immigration laws.

And “donated money” here means “his donations amounted to 72% of the party's entire 2025 revenue”[0].

[0]: https://www.flamman.se/techprofil-ger-miljoner-till-orebropa...

Re: Shutting down our public encrypted DNS

#72
post #57
post #55

Earlier quoted context omitted.

You can't compare running a single service in your home network with the operations it takes to serve a public DNS

This is a scaling problem, not an intrinsic difficulty. Mullvad already had the infrastructure in place. I suspect the real reason is cost-cutting.

What is intrinsic difficulty? A product at scale has many intrinsic dimensions, not just technical. Saying scaling is not an intrinsic difficulty is pretty weird given a highly scalable product usually looks nothing like their 1-user counterpart even when they have the same functionality.

Re: Shutting down our public encrypted DNS

#73
post #55
post #52

> Running a privacy-focused public DNS service is a highly specialized undertaking This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0]. [0] https://github.com/hagezi/dns-blocklists

You can't compare running a single service in your home network with the operations it takes to serve a public DNS

>https://freedns.afraid.org/

This dude has been doing it for 25 years, and actually this is a dns provider for domain names which I'm decently sure makes it more complicated than public dns.

They're allowed to say they don't want to pay for it anymore, I just think their logic is bad. Or maybe their lawyer said they're running risks just ignoring takedown and they didn't want to deal with it anymore.

Re: Shutting down our public encrypted DNS

#74

These was one of the fastest DoH services for pipelined queries over single TCP connection IME, it was much faster than Quad9 for this purpose First Mullvad shuts down its Google search proxy Now its DoH service What's next

Also had a ChatGPT alternative with less surveillance

Discontinued

Re: Shutting down our public encrypted DNS

#75

Earlier quoted context omitted.

Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?

The data would/should be encrypted; while the NSA did successfully tap Google's inter-datacenter traffic before the Snowden leaks, since then it is encrypted, too. Hopefully other providers won't fall for that trick anymore, either.

IIRC, Google addressed the incident you're referring to by adding E2E encryption to sensitive inter-DC RPC sessions, rather than by fully encrypting inter-DC traffic at the link level. It would be nice to be able to reasonably expect carrier/ISP backbones to be secure against this threat, but in our actual reality this seems like fantastical thinking.

Re: Shutting down our public encrypted DNS

#77
post #9
post #2

>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead. Brilliant.

Quad9 doesn't have an adblocking DNS service though, so it's not really a replacement.

I've been using Control D and have been happy with it so far

Re: Shutting down our public encrypted DNS

#78
post #16

Earlier quoted context omitted.

NextDNS https://nextdns.io/

Been using them for years. The price is reasonable too. It’s the only way I found to block ads everywhere on iOS (except the YT app, Mullvad’s Albania wireguard did that)

The price is so reasonable, I think the risk is that you’re paying mainly with your data?

Re: Shutting down our public encrypted DNS

#79
post #5

Earlier quoted context omitted.

Not if Quad9 is using DNSSEC, no. What's the specific threat you're envisioning? If it involves Quad9 themselves being malicious, what would DNSSEC on the forwarding prevent? This page explains how all of this works in detail: https://quad9.net/news/blog/quad9-enables-dnssec-on-all-serv...

DNSSEC validation on your forwarder would prevent a maliciously modified record from Quad9 (or others) from being accepted locally - i.e. "Quad9 can poison my DNS". I've always been of two minds on this. On one hand, that concern is beyond any reasonable level of security/performance/reliability tradeoff for most any user. At the same time, it is a bit of a shame DNS doesn't have a more scalable & performant approach…

You are rely here on the assumption what your resolver already knows what the zone is DNSSEC signed. If your forwarder or resolver strips that information?..

Re: Shutting down our public encrypted DNS

#80

Earlier quoted context omitted.

Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS. [1] https://quad9.net/news/blog/italian-blocking-demands-followi...

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

There's some irony in Germany using censorship for the purpose of ensuring people don't get into reading materials that might convince them to become... fascists who censor people
Post reply on HN