Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

211–220 of 231 posts

Re: Shutting down our public encrypted DNS

#211
post #148

Earlier quoted context omitted.

Really? I never found it effective unless I messed with certs on my phone. For example, DNS blocking isn't going to block YouTube ads if you're using the app since they don't need to respect your DNS, but it will if you're in browser because they can't control that. For apps I always use revanced.

Ads from providers like Google AdMob and AppLovin are blocked. Apps could bundle their own DNS or DoH resolver or use hardcoded static IP addresses but in my experience most do not. Youtube ads do not get blocked by DNS adblock because Youtube ads are served from the same domains as the content and thus DNS blocking would be counterproductive. I don't think it has anything to do with respecting DNS. I don't have the…

Are you explaining my comment or rebuting it? I really can't tell what the intent is. Maybe the internet has trained me poorly in thinking most replys are generally rebuttals. But it really does seems like you're just explaining my comment.

Re: Shutting down our public encrypted DNS

#212

Quad9 has horrible latency and frequent query failures, I hope Mullvad encourages them to improve their routes

I frequently get mini failures with quad9 and my DNS client is too dumb to retry with another server (or quad9 returns a valid but bogus response that prevents my client from hoping to the next server) so I had to ditch quad9.

Quad9 also has worse latency but I could live with it, I just can't live with web pages failing to load several times per day(especially hacker News that has their DNS TTL set to 1 second)

It doesn't happen with my ISP's servers nor with CloudFlare or google or even good ol' L3.

Re: Shutting down our public encrypted DNS

#214

Quad9 is a reasonable choice given the stance on privacy and the similar jurisdiction (Mullvad would probably face the same takedown orders as Quad9), but really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver. Unbound is a great choice. Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Y…

I don’t honestly see how that’s necessarily better. Now your ISP can tap your individual household to see what’s being queried. Whereas if you use Do[THU] to connect to some remote recursive resolver it practically functions as a mixer.

Re: Shutting down our public encrypted DNS

#215
post #198

Earlier quoted context omitted.

> Copyright is serving exactly nobody today Except for nearly everyone who writes anything (including software) or other artistic pursuits to make a living. This includes a majority of people here on HN.

I'm guessing you didn't click my profile before writing this knee-jerk, but I'm a professional musician. And I've worked in software engineering, across a zillion different licenses, for many years. I'm not just shooting from the hip here.

I'm a trained attorney who specialized in intellectual property law, and I happen to know a little about both the performing arts and software industries. It does serve people and power entire industries.

You wrote "copyright is serving exactly nobody today." If that's not what you meant, choose your words more carefully next time. This is a forum of writing, and, much like songwriting, the right words and nuance matter.

Re: Shutting down our public encrypted DNS

#217

These was one of the fastest DoH services for pipelined queries over single TCP connection IME, it was much faster than Quad9 for this purpose First Mullvad shuts down its Google search proxy Now its DoH service What's next

They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas

> is nice to have on the high seas

For sailing the high seas, or for harboring? I, for one, am glad to not have Mullvad's IP ranges blacklisted everywhere.

Re: Shutting down our public encrypted DNS

#218

Does anyone know of good alternatives that also block ads? Seems Quad9 doesn't.

Since this seems to be the thread for public DoH providers, this article is probably worth mentioning (it can sort by DoH, DoT, DoQ, etc support).

https://en.wikipedia.org/wiki/Public_recursive_name_server

Re: Shutting down our public encrypted DNS

#220

Earlier quoted context omitted.

Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS. [1] https://quad9.net/news/blog/italian-blocking-demands-followi...

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

Funny aspect is law is building demand for more capable ISP equipment devoid of principles.

Anybody can change their DNS and for an ISP to perform a man in the middle on all dns they would need to inspect every packet. Impossible

Post reply on HN