Live data from Hacker News

Encrypted DNS Outside of the US

eloydegen.com

1–5 of 5 posts

Re: Encrypted DNS Outside of the US

#4
post #3
post #2

There are many encrypted DNS servers outside the US: https://dnscrypt.info/map

Yes, but they aren't used as a default by browsers. Currently, Firefox is only relying on Cloudflare by default for US users.

Which is good. I don't want a browser to bypass DNS settings to use something else instead.

Especially since DNS encryption and anonymization is already done on the router for the whole network.

Re: Encrypted DNS Outside of the US

#5
post #4
post #3

Earlier quoted context omitted.

Yes, but they aren't used as a default by browsers. Currently, Firefox is only relying on Cloudflare by default for US users.

Which is good. I don't want a browser to bypass DNS settings to use something else instead. Especially since DNS encryption and anonymization is already done on the router for the whole network.

> I don't want a browser to bypass DNS settings to use something else instead.

In an ideal situation, me neither. But there are a lot of users who use for example Windows 7, which will never get encrypted DNS on system level. Browsers get updates and can provide more DNS security for the average user. Not a single average user is going to configure a DNSCrypt client on their computer.

> Especially since DNS encryption and anonymization is already done on the router for the whole network.

So you would prefer using a DHCP provided DNS server on untrusted Wi-Fi networks and let it snoop on DNS queries?