Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

221–230 of 253 posts

Re: Shutting down our public encrypted DNS

#221

Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics. First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and wit…

> Quad9 is based in Switzerland. Despite what may be common knowledge from movies, there is a very formal and rigorous process for governments (Swiss or non-Swiss) to demand data.

Due to Lugano Convention [0] / Budapest Convention [1] / Hague Convention etc, I don't see how Switzerland is any more insulated than, say, Norway is (both these countries are part of EFTA & signatories to various UN/EU/EFTA treaties). Per this article [2], Switzerland ranks below Ireland, Portugal, Denmark, France in Data privacy laws (in fact, it ranks the same as the UK).

If I am being honest, at this point, "based in Switzerland" (or Cyprus or Sweden or Gibraltar) comes across as marketing gimmick VPN companies are notorious for.

[0] EU civil & commercial law enforcement in Switzerland: https://www.legal500.com/guides/chapter/switzerland-enforcem...

[1] Mutual Legal Assistance Treaty (MLAT) is bypassed: https://rm.coe.int/16802e726c

[2] https://www.comparitech.com/blog/vpn-privacy/surveillance-st...

Re: Shutting down our public encrypted DNS

#222

Earlier quoted context omitted.

Copyleft software couldn't exist. But all software would be free by default, because all source would be in the public domain, and all reverse compilation of binaries would produce public domain code.

Sure, but if all software is in the public domain, then the profit motive for developing software will be completely wiped out, and much less will be produced as a result. Software development be reduced to a hobby or developers will have to seek out patronage like artists did in the 1600s. That’s not a world that most of us want to return to.

Why do you think so much open source software is written, if you need a profit motive for software to be created?

Also, let's be real - human written (and therefore copyrightable) code is dying already. When the machines can write anything on demand, why do you need a profit motive?

Re: Shutting down our public encrypted DNS

#223

Earlier quoted context omitted.

Copyleft software couldn't exist. But all software would be free by default, because all source would be in the public domain, and all reverse compilation of binaries would produce public domain code.

> But all software would be free by default, because all source would be in the public domain, and all reverse compilation of binaries would produce public domain code. I am not aware of any open-source license which tries to approximate the "there is no copyright" situation: - Such a license would not compulse you to publish the source code of any modification you make for it. - Such a license would allow you to dis…

CC0 is an explicit attempt to emulate public domain in license form, isn't it?

Re: Shutting down our public encrypted DNS

#224

Earlier quoted context omitted.

Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS. [1] https://quad9.net/news/blog/italian-blocking-demands-followi...

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

In related news, the Spanish soccer league LaLiga successfully won an injunction against Cloudflare so that during Spanish soccer matches ISPs have to prevent access for their users to the entire Cloudflare CDN network.

The reason is that the CDN network is/was being used to illegally stream games so access to the entire CDN network is closed.

https://apnews.com/article/laliga-cloudflare-piracy-spanish-...

https://hayahora.futbol/#sobre-los-bloqueos (click "IN" to view in English)

Re: Shutting down our public encrypted DNS

#225

Earlier quoted context omitted.

Sounds more like we should end copyright worldwide.

There may be a middle ground between the current maximalist copyright regime and ending copyright altogether.

Are you proposing this as a bridge to eliminating it entirely? Because to be quite frank, the “copyright holders” don’t deserve a damned thing. They’ve already robbed the commons and will continue to do so. Appeasement is the same as capitulation. And quite frankly the way things are shaping up… association is the same as guilt and I am not in a forgiving mood, having been robbed blind by these same people for my entire life.

Re: Shutting down our public encrypted DNS

#226
post #191

Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics. First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and wit…

You are probably the guy to ask. I have always found dns over TLS to be the fastest, but with the quic versions making an entrance, maybe things have changed. Which is the one that gives me the fastest replies?

Not OP but I don’t think DoQ is very interesting. DoH is nice because it blends in with HTTPS. Both do the protocol level things to avoid connection handshakes. The HTTP overhead isn’t that much really.

DoT is more complex than you’d imagine because it has to try hard to implement its own solutions to avoid handshakes.

Re: Shutting down our public encrypted DNS

#227
post #214

Quad9 is a reasonable choice given the stance on privacy and the similar jurisdiction (Mullvad would probably face the same takedown orders as Quad9), but really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver. Unbound is a great choice. Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Y…

I don’t honestly see how that’s necessarily better. Now your ISP can tap your individual household to see what’s being queried. Whereas if you use Do[THU] to connect to some remote recursive resolver it practically functions as a mixer.

That’s why I suggested routing queries through a VPN or Tor if that’s a concern. This bypasses centralized DNS services that may face national blocking orders while retaining privacy.

Re: Shutting down our public encrypted DNS

#228

Earlier quoted context omitted.

> But all software would be free by default, because all source would be in the public domain, and all reverse compilation of binaries would produce public domain code. I am not aware of any open-source license which tries to approximate the "there is no copyright" situation: - Such a license would not compulse you to publish the source code of any modification you make for it. - Such a license would allow you to dis…

CC0 is an explicit attempt to emulate public domain in license form, isn't it?

> CC0 is an explicit attempt to emulate public domain in license form, isn't it?

Public domain is something different from an emulation of "there is no copyright":

You can take public domain material to build some program binary:

- In the current legal system, you can enforce restrictions on the usage of this binary, and can forbid redistribution, reverse-engineering, ...

- In a "no copyright world", you cannot enforce such restrictions.

Re: Shutting down our public encrypted DNS

#229

Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics. First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and wit…

I saw your response about not blocking ads currently. What about blocking adult content, for a child's computer? Mullvad had such an option[1] under family.dns.mullvad.net. Very useful!

[1]https://mullvad.net/en/help/dns-over-https-and-dns-over-tls

Re: Shutting down our public encrypted DNS

#230

Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics. First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and wit…

Thanks for the clarification, I mistakenly assumed you were also required to block sanctioned media (mostly Russian/Iranian), but upon further research apparently that only applies to ISP DNS.
Post reply on HN