Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

201–210 of 214 posts

Re: Shutting down our public encrypted DNS

#201

Earlier quoted context omitted.

"your code is a trade secret protected via contracts" isn't enough to replace copyright because the contracts are only enforceable to the signing parties. Let's say you write some software for your employer and they sell the product to several customers with a contract not to distribute it. However, the product appears on some pirate website anyway, and you can't identify who allowed the product to be leaked. Once it…

Yeah, I'm assuming most people here aren't selling proprietary code to customers directly. I assume most professionals here work somewhere that sells SaaS or uses the software they develop internally only.

If I recall correctly most software work goes to custom software. Note that in many, possibly most, cases, the (sole) customer retains the exclusive rights to the source code, making the software effectively Free per the FSF definition (because the user is free).

Almost my entire career was spent on such custom software. The rest was internal software. And even that one I was doing as a contractor, so in a way we could argue it was custom software even there.

Re: Shutting down our public encrypted DNS

#202

Earlier quoted context omitted.

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

What's even worse: the court fined us because they claimed this use case was in some way in contempt of their ruling. Then, when we won the overall case, that money was never returned because it wasn't specifically referenced by the final court. The response from the lower court was effectively: "Well, you will need to sue the court to get that money back." Edit: I'm with Quad9 (CTO)

That’s insane. Thank you for the service you provide.

Re: Shutting down our public encrypted DNS

#203

Earlier quoted context omitted.

Sure, but if all software is in the public domain, then the profit motive for developing software will be completely wiped out, and much less will be produced as a result. Software development be reduced to a hobby or developers will have to seek out patronage like artists did in the 1600s. That’s not a world that most of us want to return to.

Or have a universal income. Capitalism isn't inevitable. And it will end anyway, at it hits planetary limits. Better start thinking of alternatives before one of the worst ones gets imposed on us.

[flagged]

Re: Shutting down our public encrypted DNS

#204

Earlier quoted context omitted.

> t was designed to maximize creativity and inventiveness If you look at outcomes it has completely failed while making big corps very rich in the process

Unfortunately that will happen irrespective of the law. If you want permissive rules then corporations will just resell your IP (like we see with SaaS). And if you want tighter rules then you just create a higher barrier for entry that benefits corporations rather than independent entities. Either way, it’s easier to operate when you already have a leading position.

Then just outlaw big corps. Put a hard cap on company size or capital, possibly on a per-domain basis. Or just put what has to be big infrastructure under direct state control. Worked wonders in practice in France.

Oh, and also put a hard cap on individual wealth while we're at it. No one, no matter how hard working, deserves a billion dollars. And no one should be trusted with that much power, it's too goddamn dangerous.

(The caps should be indexed to stuff like median income or wealth. Wanna get richer? There's a way: help everyone get richer. That way we're actually in this together.)

Re: Shutting down our public encrypted DNS

#205

This feels like a nitpick but it's important to mention anyway > Mullvad Browser uses them [ the DoH servers ] by default when you're not on Mullvad VPN, preventing your ISP from seeing the domains you visit. This is a half-truth until Encrypted Client Hello (ECH) is in-use for most of your traffic. Sure, you won't have clear-text DNS floating out there in the series of tubes. However, without ECH the hostname you're…

Even ECH isn't that helpful. ISP still sees the IP addresses you connect to. Even when non-dedicated IPs are used, I'd be surprised if a quite basic traffic analysis (say, bytes transferred on first visit) wouldn't identify the domain.

VPN providers at the tier of Mullvad should be precise about this stuff -- I think it's more than just a nitpick, considering the audience. oh god did I just use an emdash.

Note that you need some flavor of secure DNS to enforce ECH. The protocol is designed to be downgradable.

Re: Shutting down our public encrypted DNS

#206

Earlier quoted context omitted.

What's even worse: the court fined us because they claimed this use case was in some way in contempt of their ruling. Then, when we won the overall case, that money was never returned because it wasn't specifically referenced by the final court. The response from the lower court was effectively: "Well, you will need to sue the court to get that money back." Edit: I'm with Quad9 (CTO)

>wasn't specifically referenced by the final court. Maybe your lawyer fucked up? Did you immediately appeal the fine or request a stay pending the main action? Appeal court ruled on the substantive case. My understanding is that in Germany it has no procedural jurisdiction to order the state treasury to refund an enforcement fine. You need restitution claim that makes the thing yet another hoop.

Cost and staff time to pursue were not significantly higher than the return. We just want to help people with security and privacy and do DNS stuff - this legal fighting is absurd and misplaced and a spectacular waste of time, but here we are.

Re: Shutting down our public encrypted DNS

#207
post #2

>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead. Brilliant.

Terrible. No malware / trackers / ad blocking on 9999.

I hope at least they'll keep these options in their tunnel configuration but if not there's not much sense in keeping their service....

Re: Shutting down our public encrypted DNS

#208

Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics. First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and wit…

Thanks for this! I was looking at your transparency report (https://quad9.net/about/transparency-report/) and I notice 2026 is not included in the 'list of years in which we have not received a request for data', despite the list being updated quarterly according to the text below it. When I saw the page earlier, I assumed that either the list isn't actually updated quarterly, or I'd discovered an exciting example of a warrant canary.

Re: Shutting down our public encrypted DNS

#209

What does everybody here think about Daniel Berntsson, founder and co-owner of Mullvad, personally donating 5 million Swedish krona to the populist Örebro party, criticized for its stances on race & immigration? I'm not trying to start an unhealthy discussion about this topic, genuinely curious about your opinion on the matter.

I stopped paying for or using Mullvad because of that. I have no intention of funding more nazis, when I can help it

Re: Shutting down our public encrypted DNS

#210

Earlier quoted context omitted.

I've been loving the Pihole setup I just set up. It uses Quad9 as the upstream provider and then I do all the blocking myself. I used to use NextDNS but this is so much better and free!

How do you block ads when you're outside of your home network? Do you expose your pihole outside?

VPN back to your home network?
Post reply on HN