Run a private DNS over HTTPS service
fly.io
fly.io
>> DNS over HTTPS (or DoH) is a protocol that makes browsing more private. Browsers typically resolve domain names with an unencrypted protocol, allowing nosy neighbors and internet providers to snoop on some internet activity. DoH creates an enecrypted connection between browsers and the DNS resolver to make it difficult to even see what domains a user is loading.
This is simply not true (typo aside). My resolver runs locally in my apartment or in our office. "nosy neighbors and internet providers" are not a threat to us but surveillance companies are, who coincidentally pushing for DoH. And DoH is a protocol that makes browsing easier to be controlled by your browser vendor. These guys just forget that not all DNS traffic is originated from web browsers. Google (Chrome) already ignores resolv.conf and trying to force its way to 8.8.8.8. Basically fighting for the last bit of information they can get about you. Thanks, but no thanks.
- full recursive (meaning you are going to query the root servers and all the other servers until you get your answer)
- custom upstream provider who is not a surveillance company
The first is as secure as the protocol to use to query. You can use DoT to make it more secure.
"DNS over TLS (DoT) is a security protocol for encrypting and wrapping Domain Name System (DNS) queries and answers via the Transport Layer Security (TLS) protocol. The goal of the method is to increase user privacy and security by preventing eavesdropping and manipulation of DNS data via man-in-the-middle attacks."
The second case is a bit better when DoT is not available for all the nameservers, using Cloudflare's DNS service as an upstream gives you what you want (it also supports DoT AFAIK).
As far as I am concerned DoT is the way to go and the best would be if all DNS servers support that all the way to the root servers and I could run my home service with ad filtering on while other people could just use Cloudflare or whoever they want and not leaking out what they are querying for companies in between. DoH is pointless in my opinion if you have DoT.
If you really don't think that is a threat, you're foolish.
Also I would like to see proof regarding Chrome "forcing" itself to 8.8.8.8 - I have never seen that. I run Chrome on Linux, Mac, and Windows.
Thanks for the doh-proxy tip off though, might be worth chucking that on the box that runs my DNS :)
Or you can use ads blocking DoH server https://blahdns.com
[1]: https://nextdns.io/
...nope!
You can totally use the Docker image in the article without doing that though. And maybe we should figure out how to make "login with your Hacker News" work.