> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…
Thai Database Leaks 8.3B Internet Records
31–40 of 79 posts
Re: Thai Database Leaks 8.3B Internet Records
#32Earlier quoted context omitted.
I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec. I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server). I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.
Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?
Re: Thai Database Leaks 8.3B Internet Records
#33Earlier quoted context omitted.
I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec. I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server). I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.
Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?
DoT: dns.digitale-gesellschaft.ch
DoH: dns.digitale-gesellschaft.ch/dns-query
Source:
https://de.wikipedia.org/wiki/DNS_over_HTTPS
https://de.wikipedia.org/wiki/DNS_over_TLS
https://www.digitale-gesellschaft.ch/dns/
Sorry, for not being available in the en-wiki
Re: Thai Database Leaks 8.3B Internet Records
#34> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…
If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.
Re: Thai Database Leaks 8.3B Internet Records
#35Earlier quoted context omitted.
DoH just moves the logging from Thai telecom and moves it to Cloudflare (or, whoever you set up as your DoH server, but most likely Cloudflare), no? I trust CF much more than my ISP, but it makes the potential leak much worse... edit: On the other hand, DoH makes DNS requests independent of ISP, which is nice. ISPs are often monopoly by nature.
Could be interesting to use a list of DoH servers and pick one at random for each DNS query.
Re: Thai Database Leaks 8.3B Internet Records
#36AIS is mobile operator hence assign you random IP from the pool every time you reconnect to the network. IP address could be used by many different users during a day, definitely not a household as author states. Looks like useless data for me.
Re: Thai Database Leaks 8.3B Internet Records
#37> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…
Most malicious ISPs disable DoH (ex: Verizon) so it likely wouldn’t have solved this. If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.
Re: Thai Database Leaks 8.3B Internet Records
#38Earlier quoted context omitted.
If you trust your vps dns, easiest way would be autossh -D and set your browser's socks5 proxy to localhost: and tell it to use remote dns when resolving domains. This requires no wireguard setup, no certificate generation or anything.
I've been doing both and have to say Wireguard is much more performant and stable than an ssh tunnel. Besides, it shouldn't be too hard to set it up on a VPS.
Re: Thai Database Leaks 8.3B Internet Records
#39Earlier quoted context omitted.
Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?
Yes, well i trust this one: DoT: dns.digitale-gesellschaft.ch DoH: dns.digitale-gesellschaft.ch/dns-query Source: https://de.wikipedia.org/wiki/DNS_over_HTTPS https://de.wikipedia.org/wiki/DNS_over_TLS https://www.digitale-gesellschaft.ch/dns/ Sorry, for not being available in the en-wiki
Re: Thai Database Leaks 8.3B Internet Records
#40Earlier quoted context omitted.
> ... countries that respect persons privacy May be a long time ago, in a galaxy far away, such a thing once existed. It's a sweet thought though.
You don't even need that to be useful though. In my tinpot banana republic (Australia) ISP metadata retention is required by law, and warrantless access to that is granted to organisations involved in fighting terrorism, child abuse, and other serious crimes - and those agencies include local councils, animal control, the taxi commission, and various horse racing oversight organisations... :sigh: Even moving your met…