Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

91–100 of 232 posts

Re: Shutting down our public encrypted DNS

#92
post #40

Earlier quoted context omitted.

CIA is not stupid enough to break into a guarded data center in Switzerland or one of the less America friendly EU countries. They tell the NSA to look for security holes and spread narratives that only criminals use VPN hoping that a politician will notice and try to ban them, like what's happening in the UK. Big tech services are less private than you think but almost every provider who cares about privacy is safer…

Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?

[dead]

Re: Shutting down our public encrypted DNS

#93
post #82

Earlier quoted context omitted.

There's some irony in Germany using censorship for the purpose of ensuring people don't get into reading materials that might convince them to become... fascists who censor people

There is no irony. The German government is proto-fascist, and has been for a while, as are several other European governments. Apparently the UK now arrests more people per capita for online speech than China does.

I would like to see your definition of fascism under which the German government is proto-fascist.

Re: Shutting down our public encrypted DNS

#94
post #82

Earlier quoted context omitted.

There's some irony in Germany using censorship for the purpose of ensuring people don't get into reading materials that might convince them to become... fascists who censor people

There is no irony. The German government is proto-fascist, and has been for a while, as are several other European governments. Apparently the UK now arrests more people per capita for online speech than China does.

[dead]

Re: Shutting down our public encrypted DNS

#95
post #82

Earlier quoted context omitted.

There is no irony. The German government is proto-fascist, and has been for a while, as are several other European governments. Apparently the UK now arrests more people per capita for online speech than China does.

[flagged]

Mentioning evil Soros is like a 100% reliable political crackpot indicator, even though this here is a quite original take. He is usually an evil Jewish globalist, i.e. a nefarious leftist.

I think he seriously pissed off the right people in Russia who are now throwing whatever shit they can think of at the wall, and some of it sticks. They do not try to be consistent at all, anything that will convince someone is fine.

Re: Shutting down our public encrypted DNS

#96

Earlier quoted context omitted.

Curious what alternative you found as a replacement. Could you share?

I switched to ProtonVPN which has a heavy emphasis on port forwarding.

I did too, but I really miss Mullvad's static port forwarding system. It's a pain having to continually run a NAT-PMP client, and it doesn't work when you're connecting to ProtonVPN on your router.

Re: Shutting down our public encrypted DNS

#97

Earlier quoted context omitted.

The entire point is that it can't be reasonably enforced with any granularity. Rights-holders want it to be like that so a copyright win in a single country means something has to be taken down globally.

Sounds more like we should end copyright worldwide.

Indeed it needs to happen, and even here on HN, it can be difficult for some to admit and acknowledge.

It'd be great for this to be the first major relinquishment of nation-state power to happen without violence, without backroom deals, without wedge politics and flag waving.

Just... let it go.

It's beyond obvious that copyright is not going to exist in 1000 years. Every creature on earth - especially the internet - survives by copying information. It's the most basic life force in the universe.

Copyright is serving exactly nobody today. It's time. Are there elder stateswo/men in the room who can see the writing on the wall and act with grace?

Re: Shutting down our public encrypted DNS

#98
post #5
post #4

Earlier quoted context omitted.

On the Quad9 website: >Since Quad9 already performs DNSSEC validation, DNSSEC being enabled in the forwarder will cause a duplication of the DNSSEC process, significantly reducing performance and potentially causing false BOGUS responses. This sounds dodgy. Surely that means Quad9 can poison my DNS?

Not if Quad9 is using DNSSEC, no. What's the specific threat you're envisioning? If it involves Quad9 themselves being malicious, what would DNSSEC on the forwarding prevent? This page explains how all of this works in detail: https://quad9.net/news/blog/quad9-enables-dnssec-on-all-serv...

Wait, I must be misunderstanding you, because if you're resolving off Quad9, they can definitely poison your DNSSEC-signed records. Between a stub resolver and a recursor DNSSEC collapses down to a single "yes it was signed" bit in the header.

To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a reason why DoH took off instead.

Re: Shutting down our public encrypted DNS

#99

Earlier quoted context omitted.

Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS. [1] https://quad9.net/news/blog/italian-blocking-demands-followi...

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

German courts and technology are not always the best friends
Post reply on HN