I think as a compromise I’ll run my own recursive DNS on a digital ocean droplet and point my local dnsmasq instance at that.
I think as a compromise I’ll run my own recursive DNS on a digital ocean droplet and point my local dnsmasq instance at that.
Now, Google does claim they don't track DNS requests. But consider why that is? Once upon a time they didn't scan Gmail content either, but that was before GMail dominated the webmail space.
What do you think is going to happen once DNS becomes centralized? If it's taken too far we won't be able to go back. And it can easily go too far. Chrome and Firefox are ubiquitous enough that if they succeed in removing local resolvers from the loop it will mean that the entire ecosystem will have transformed to accommodate them. Software stacks, configuration policies, etc will have all evolved to disfavor niche use cases and favor Google, Cloudflare, etc.
ISPs can already see the IP address we're all connecting to, and the correlation between domains and IPv4 addresses is more than strong enough to provide the necessary information for commercial profiling. IPv6 will virtually make it 1:1. (So Encrypted SNI likewise provides little benefit.)
The shift to TLS accounts for 90% of the potential capacity for avoiding ISP snooping, short of VPNs or TOR. That last 10% comes with a huge price tag.
I could run a VPN full time, but I'm not willing to accept the added latency and bandwidth cost.
What would you suggest?
Thank you! We need more people to run their own network services in order to preserve our freedom and privacy.
I’d still run my own email if it weren’t such a pain in the ass. I’m not new to this stuff[1], but at some point you get tired of doing SA stuff at home when it’s also your day job.
Package management is more difficult, but if I have to install something as a package I probably don't want the headache. Upgrades are more manual as compared to Linux distros, but they're simple and consistent and well-documented so require no more than an hour every 6 months. Sysmerge (for upgrading /etc) and now syspatch (for kernel patches) have made it even simpler. The upgrades come precisely every 6 months. The system evolves incrementally so I don't need to invest much effort in keeping pace--just stay on schedule.
I only backup user data and a few key configuration files (e.g. domain specific rules for smtpd.conf and httpd.conf) as I can recreate a setup with minimal effort.
I stopped running POP and IMAP a long time ago. OpenBSD never provided native solutions. (They shipped a POP3 daemon, popa3d, for a few years but few people used it.) I use mutt, some others use alpine, and others just forward their email to somewhere else. I do greylisting with OpenBSD's native spamd and some simple RBL checks that run from the MDA, but that's it. I get more spam than I might otherwise, but it's tolerable, especially considering I don't have to maintain additional software. And most other users don't see the same spam volume--I've used my e-mail address on web pages and in public forums for nearly two decades so it's on pretty much every list traded among spammers and marketers.
[1] People criticize their "secure by default" mantra as disingenuous or misleading, but if you've been running these services for years or decades you know exactly what they mean by it.
Amen! Which is really sad sometimes. I really enjoyed that stuff when I was younger. Sometimes makes me wish I had picked another career so I might still enjoy fiddling with more or less trivial tech as a hobby.
Why not run DoH over tor? Much better privacy than a server/ip address only used by you and can be traced back to you.
https://www.nytimes.com/2017/06/23/technology/gmail-ads.html
> Now, Google does claim they don't track DNS requests. But consider why that is? Once upon a time they didn't scan Gmail content either, but that was before GMail dominated the webmail space.
You seem to assume that it's a singular organization with a unified agenda, but this really isn't the case. It's the same thing about when folks assume Google looks at your Drive files to recommend ads to you -- it isn't true, there's different motives there.
Drive: we want to sell you storage, your data isn't scanned (except for viruses). Google DNS: speed up DNS, which improves load times, which improves the overall web experience. Photos: Ditto, we want to sell you storage.
Performance is a feature, and most ISP resolvers are junk. Worse, many of those resolvers like to inject their own NXDOMAIN pages. :\
You could argue that Google DNS does positively impact Ads, but only in the respect that faster DNS resolution helps ads load faster too. Overall, I see it as one of those "long term greedy" (my own words) strategies.
As a privacy-conscious Googler myself, I've taken a look at Google DNS to convince myself that it's what it says on the tin. As far as I can tell it is, but I don't expect you to take my word for it. What logging exists is extremely temporary (short-term debugging.)
Re: Gmail, this isn't true either. Sure, there's still processing of your emails (we receive your email, scan it for spam), but it isn't used for Gmail ads. The public perception of this was so bad and the incremental improvement in ad quality so low, that now ads just use your general ad profile. No email scanning involved.
> Software stacks, configuration policies, etc will have all evolved to disfavor niche use cases and favor Google, Cloudflare, etc.
This is a different matter entirely, but this isn't _always_ a bad thing. I'm thinking of TCP here, which has almost entirely been ossified by middleboxes. Same for TLS -- TLS development has been hamstrung by these same kinds of middleboxes and "protocol accelerators." This kind of incredible technology position has allowed for the acceleration of HTTP/2 and the development of QUIC (and therefore HTTP/3). Overall, Google has been incredibly open with the development of these and worked to include everyone. I'm sure it's not always that way. Can you bring up some examples where "niche use-cases" have been locked out by Google-driven software stacks and configuration policies?
Drive: > your data isn't scanned (except for...
Google DNS: > What logging exists is extremely temporary...
Gmail: > we receive your email, scan it for ....
There’s a lot to worry about w.r.t. privacy online. Virus scanning, spam filtering, and debug logging aren’t high on my worry-list.
Oh, just stop.
It's even more disappointing to consider that you believe this to be true.
Edit: I should add that the slowness wasn't a peak hour thing, it was consistent, all day, for several months.
Switching made my subjective experience better.
1. I do not use google for DNS 2. I do not use chrome. I use firefox with ad blocking 3. I only browse in private browsing mode 99% of the time. 4. I have a script that updates a block list of 10s of 1000s IPs for ad and tracking blocking, etc into my host file.
So I order a box of cigars. Confirmation is to a gmail account. Next day I get stop smoking ads in YouTube. Never seen them before then.
So...