A guide to set up your own round-robin DNS-over-HTTPS proxy for privacy
dohproxy.com
dohproxy.com
If there is any pattern in the DNS queries you perform (e.g you visit certain sites regularly), then all of a sudden there are now going to be four additional organisations that know your browsing habbits, on top of your existing one (your ISP).
Imagine you go to pornhub.com every day. Your ISP knows that you're doing that today because of your DNS lookups, and they will still know that after the deployment of DOH and ESNI, because like millions of other websites, pornhub doesn't share their IP addresses. But now all of a sudden, you'll be telling cloudflare one day that you go to pornhub, google the next day, opendns the next day, and 42l the next day.
Why do people insist on increasing the number of organisations with access to their browsing history, in the name of privacy?
Don't set up or use this system.
But once you use DoH using a private DNS proxy does in fact provide (some) protection because it detaches one's client address from the requests. Breaking this requires timing correlation or individual domain names for tracking.
Addendum: If it's about distrusting your ISP you gotta consider that you're just moving trust to another ISP or service provider (or worst case both, if they're separate entities).
When somebody says that using a VPN would be better. You need to consider what they are saying it is better than.
If you set up a DoH proxy, and don't route the rest of your traffic through an encrypted tunnel to the same point, then you're choosing two ISPs to give your data to, instead of just the one.
This assumes you trust your ISP. I know mine does metadata retention, therefore I do not trust them with my privacy. I also know mine blocks things based on a government "block list" which was implemented all in the name of stopping "serious criminals" such as pedophiles and terrorists.
However, in practice it's used for much more than that, of which does not constitute any criminality (news websites such as torrentfreak.com, that's because of corruption. The Minister for Communications https://en.wikipedia.org/wiki/George_Brandis that oversaw the implementation of this system was also the Minister for Arts and had heavy ties to the movie industry. He had a lot of collusion with Village Roadshow and Sony (evident by the leaked Sony emails) on this matter.
In other parts of the world I have heard that certain ISPs collect that data for marketing purposes.
> When you set up a private VPN to tunnel your traffic through, doesn't your VPN server just become your client? Or am I missing something here?
This is why I pipe everything through a VPN, that I trust more to protect my privacy than my ISP.
My DNS requests then go through to the DNS server on my VPN's network (it's in private address space), that recurses to Cloudflare. As far as those DNS providers are concerned "someone from that provider did a lookup for something", assuming that it isn't already cached.
The reason I use a VPN provider and don't run a VPN on my own server is because that would just link back to a server that is controlled by me, this way my network traffic is mixed with unrelated customers. For times when I need strong anonymity of course I use Tor. (Just before anyone points that out).
I have found issues in the past, particularly with EDNS subnet information not being available when accessing archive.is https://news.ycombinator.com/item?id=19828317 so that's why I have mine setup like so:
https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
My network has dual-stack IPv6 so with this kind of routing https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
I believe this is the 'correct' way to ensure privacy. Essentially my network works like this:
VLAN2 -> direct to ISP via ppp0
VLAN3 -> through VPN via tun0
Local unbound server forwards everything into dnscrypt that first tries my VPN's DNS server, then tries to use DNSCrypt over the VPNRegardless of which VLAN I am on, my DNS traffic is always sent through my VPN, https://www.dnsleaktest.com/ is a great site for testing that.
I tend to use VLAN2 for things like financial, or stuff where I do not want to be anonymous or cases that require extremely low latency such as gaming. In either case DNS lookups still go through the VPN.
Yes I meant to say "there is little to gain hiding just DNS traffic from your ISP"
It isn't privacy.
[1] https://www.theguardian.com/technology/2019/sep/24/firefox-n...
So you can make a kiddy filter DNS provider that won't let you resolve pornhub, but your users need to have gone "Yeah, kiddy filter, that's what I want" not get opted into it by a government policy.
If you don't want a TRR agreement then sure, but now you'll need to teach users to go in and manually configure your servers. I have a feeling that "Here are the mandatory government instructions for ensuring censorship citizen" is not an effective strategy.
Presumably the fear is that having DoH built into the browser lowers the bar to entry for people who want to use it as part of engaging in criminality.
Wow. I mean, you can have an argument over de desirability of DoH, but referring to Mozilla as internet villains is really missing the forest for the trees.
Luckily:
> A month later, the body withdrew the nomination and cancelled the “award” entirely, saying it “clearly sent the wrong message”.
I'm happy to hear that they currently have no plans to launch DoH in the UK, but I worry that this is only a temporary situation.
Note: If you want to protect the less tech-savy Firefox users on your LAN from Mozillas DoH implementation, update your DNS server to NXDOMAIN use-application-dns.net. You can do this easily in Unbound with the following piece of config:
local-zone: "use-application-dns.net" staticAs there has to be at least party which will know the request, some information will be leaked. But what can be prevented, is giving "unrelated" requests in the hands of the same resolver. Few of the request per se are interesting, the combinations of them allow to build user profiles.
The policy should not be round robin, but somehow based on the domain itself, so that all requests about the same domain go to the same resolver, but to nobody else.
An even better mechanism would take into account who is the owner and the controller of the domain. So that requests about, let say, facebook.com and fbsbx.com land at the same resolver, but github.com and microsoft.com by another.
[1] Looking at SNI is even more accurate, since DNS lookups don't necessarily (but often) mean a connection to that host will be made; a TLS handshake, on the other hand, means a connection is being made.
https://blog.cloudflare.com/encrypted-sni/
I doubt DoH is a ploy to break adblocking; if you don’t control the device making the requests they could already do plenty of things to break crude adblocking techniques like that. (Nevermind the fact that one of its biggest supporters is Mozilla.)
Stating that this is pointless for privacy seems like an exaggeration. Sure its not a panacea, but for probably 80% of sites, the destination IP tells you you are headed to Amazon or Cloudflare. Besides that, why reveal more information than less, and why not remove unencrypted, easily manipulated network traffic? Personally, I aim to eliminate unencrypted traffic on my networks.
Edit: And Cloudflare‘s own service mitigates the use of IP addresses to identify sites, since (AFAIK) all Cloudflare-wrapped sites are accessed via the same IP. Of course, this is only an improvement if you trust Cloudflare.
edit: I'm wondering what the ideal setup actually is. Would the root servers need to provide DoH endpoints?
[0] https://en.m.wikipedia.org/wiki/Unbound_(DNS_server)#Feature...
Be sure that you trust your “over the wire” connection to not sniff and uniquely tag all of your DNS requests with your specific identifying information, such as Verizon and many other service provides often do.
Having a local recursive resolver with the Client Subnet in DNS Queries turned off would be better for privacy.
Round robin providers is really bad idea. Its like leaving your foot print in literally all places.
Best is to use Tor Browser if you really need privacy.