Transparent DNS proxies
dnsleaktest.com
dnsleaktest.com
Isn't this one of the points of Net Neutrality? My ISP (Comcast) doesn't do this currently. I suppose I'll have to check again on January 21.
Actually, init7 itself is in Germany, right ? I know they have POPs there, as in France and .nl, etc.
I don't think this specific example is malicious (it's part of Google's Edge Network I guess? I wouldn't know), but it does show that they're already capable of modifying the DNS lookups ran by their customers.
I'm with BT and they don't appear to do this.
I suspect you maybe seeing resolution to Google's edge network. This isn't modification - it is how DNS is designed to work.
Perhaps I'll check some other domains too.
Without it the functionality described above will just work - it's only when you are using an unusual DNS setup that the extension is needed.
If you prefer something more privacy oriented, but possibly not as fast:
https://servers.opennicproject.org/
84.200.69.80 # dns.watch
84.200.70.40 # dns.watch
37.235.1.174 # freedns.zone
37.235.1.177 # freedns.zone
213.73.91.35 # dnscache.berlin.ccc.de
194.150.168.168 # dns.as250.net; Berlin/Frankfurt
85.214.20.141 # FoeBud (digitalcourage.de)
77.109.148.136 # privacyfoundation.ch
77.109.148.137 # privacyfoundation.ch
91.239.100.100 # anycast.censurfridns.dk
89.233.43.71 # ns1.censurfridns.dk
204.152.184.76 # f.6to4-servers.net, ISC, USA
Edit: I know this won't do anything for ISPs using transparent proxies (from the article: "Some ISP's").This is just for people with shitty, but not as shitty ISPs. Such as ones that hijack NXDOMAIN: https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_...
Edit2: I couldn't get the test from dnsleaktest.com to work on my computer, but starting at step 3 from [0] seems to work fine (I do already use DNSCrypt with Unbound).
[0] https://www.smartydns.com/support/isp-doing-transparent-dns-...
I'm sure you have 500 kB free RAM for a proper resolver that works in the real world, and validates DNSSEC for free. I think most resolving should be done locally nowadays. Latency is mostly a last mile problem.
Currently I'm planning to do just DNS over TLS. I'd love feedback on this if people are interested. Both of these address this issue pretty well.
iptables -t mangle -A PREROUTING -p {udp,tcp} --dport 53 -j TPROXY --on-ip mitm-ip --on-port 53
Doing this isn't inherently malicious. Most of the time it's done for performance reasons. Bad idea, if you ask me, but whatever.Since dnscrypt transmits DNS requests over port 443, which is also used by HTTPS, ISPs can't redirect the packets without performing more costly fingerprinting, or else websites would break.
dnscrypt packets are also encrypted and authenticated, so the worst probable thing an ISP could do is, like you said, drop the requests.
I wish people would stop fucking with DNS. It's bad enough as it is. To quite Kris Buytaert: everything is a freaking DNS problem.
Silly question - if you're in this kind of environment, is it safe to do something like messing with DNS requests? This would make you "stand out" from a traffic analysis point of view.
https://github.com/wrouesnel/dns-over-https-proxy
I wouldn't use this all the time, but I've been stuck behind a DNS-filtering ISP before which had a broken proxy. Nice to have a fallback ready
https://github.com/jedisct1/dnscrypt-proxy/blob/master/DNSCR...
Oh! Sorry! I misread your comment. Yes: HTTPS can leak hostnmes.
Only if your handshake negotiates to use SNI.
Which exposes nothing more than the previous solution of having one ip per https domain, which made it just as obvious what domain you were connecting to. Putting the domain in the request allowed people running the servers to host any number of sites from the same ip. A convenience for the operators that exposed nothing new for the consumers.
DNSCrypt over Tor helps (unless all your traffic is sent only over Tor) but I'm not seeing tools to do this around.
In the future, DNS over TLS, will also prevent this kind of tampering, and additionally prevent snooping on your DNS-to-resolver traffic.
Right now there are real, tangible benefits to just using OpenDNS. There are very few benefits to setting up your own resolver with DNSSEC due to the limited amount of zones signing with it.
I know these protect you from two different types of attacks, but for the average user the OpenDNS solution is more likely to protect them from harm (malware, ransomware, etc) than DNSSEC stopping a state actor doing a MITM (between end user and OpenDNS) which wouldn't be possible if you used OpenDNS via dnscrypt anyway; the state actor would have to successfully and undetectably poison OpenDNS's cache.
tl;dr: To the average user DNSSEC has a miniscule security impact in their everyday internet usage.
Another plus is that I've tweaked unbound config to return NXDOMAIN to some ad networks, so I can browse internet with less ads without adblock.
https://en.wikipedia.org/wiki/Verisign#2003:_Site_Finder_leg...
A critical piece of securing ones Internet, and a small price to pay to buy a good one. PIA passed the test for me, on mobile and desktop.
however when i click on the extended test i still get some IPs from my ISP. what can I do to fix that?
Not all OVPN configurations will do this correctly, it depends on your distro / configuration.
host whoami.akamai.net
This will return the IP address of the DNS server you are using.My DNS is 8.8.8.8
dig resolver.dnscrypt.org
or dig txt resolver.dnscrypt.orgIf you work on DNS at all you need control over the cache so you can purge it as needed. This is why I run my own local unbound server as well. Plus it makes it easy to add forwarders for specific domains when you use a limited routing VPN.
* http://greatfirewallofbelgium.be/
* https://en.wikipedia.org/wiki/Censorship_in_Denmark#Internet...