Ask HN: Which DNS service do you use for your computer's network settings?
I saw a comment recommending Mullvad's. I currently use the default DNS (my ISP's default).
I saw a comment recommending Mullvad's. I currently use the default DNS (my ISP's default).
Some additional details:
- Outbound internet access over port 53 is blocked for everything on the network, other than the Pi-Hole/Unbound server
- IpTables rule in place to force all outbound traffic over port 53 to go thru the Pi-Hole. This prevents devices from circumventing the Pi-Hole filtering by hard-coding public DNS servers
- Cronjob that polls http://public-dns.info/nameservers-all.txt regularly, and updates an IpTables rule to block all outbound internet traffic over any port/protocol to servers in that list. This is my attempt to block things that try to circumvent DNS filtering by doing DNS over HTTPS
- Unbound makes it possible to bypass DnsCrypt for specific zones, as needed. It also is configured to prefetch records before expiration, which generally eliminates the latency introduced by DnsCrypt
---
This is overkill, but I tried to address privacy concerns as well as ad-blocking with this setup, and it's also been fun to tinker with
edit: to be honest though, I don't look at the logs often to see what else gets caught, or why
- pihole and unbound are running in a VM on an old intel NUC with an i5 and 18GB of RAM. The NUC is running Proxmox, and is connected to the edgerouter over ethernet
- Separately, there's a ubiquiti WAP and a standalone modem, but there's nothing special about their configuration
you could do it, but just because the USG software was a fork of Vyatta that had a way for doing it and Ubiquiti never put the effort to block it..
So while there was a way of doing it, it was never really officially supported..
But this is why when it came time to upgrade my USG3 i choose to migrate to Opnsense (pfsense fork) instead of upgrading to the latest Ubiquiti router.
UAP-AC-Lite for APs.
Dell PowerEdge R420 with proxmox hosting Opnsense as router, AdGuard Home for DNS, Unifi Controller hosted on Ubuntu and Home Assistant.
BUT, it will slow down everything else simply because its another layer in the lookup cake. Which doesn't sound bad since everything will end up cached, until you notice all the cool people have decided that DNS forms part of their load/failover scheme and have set the TTL to just a few seconds, which effectively either keeps unbound constantly fetching those addresses to keep them fresh, or you pay the unbound overhead penalty all the time on your local machines. And yes, unbound can be configured to ignore TTL's below a certain value, but that has its own problems.
So, yes, run your own resolver, just be aware that it has tradeoffs. One of the big pluses is that you can configure it do to DOH/etc and then serve everything on your network unencrypted DNS that has been previously validated/etc.
Or that you haven't ever actually listened to him
But hey, you want to cheerlead for him with his track record, go right ahead.
Ok - I've listened to him off and on for about a decade
If you want to be upset over him ... go ahead
And that's fine, many don't. Which is why it's important those of us that do continue to speak up.
Take care.
Let it go
I don't really have it out for this guy, I'm just pointing out that he is a charlatan.
You seem to be really offended by that and are cheerleading for him even harder. Bizarre. I'm sorry the truth hurts you so.
Hahahaha
Well, "buddy", you seem to have it out for someone with zero evidence you can provide for why you are upset beyond, "if you know, you know"
That is not a reason, it is a claim to secret knowledge
Which...since you will not share, we have to assume does not exist
You're really one of those 'need to have the last word' types, huh.
Well, it's all yours. I have no more time to debate you than a Taylor Swift fan pissed off at me because I said one of her songs wasn't great.
That's fine - if you want to hold a grudge irrationally... you do you
Honestly, I find it hilarious you are defending this guy. He must have a real comforting voice or something.
Enlighten us, then, oh wise one!
What "knowledge" do you think I do not have that you somehow secretly do?
Cool
You are a mind reader!
SO glad you came out to tell me I do not know what I have been doing for years on end!
/s
There are lots of people in IT. It's a low barrier to entry. Plenty of people are like you and think they know what they are talking about while even managing to get paid for it.
Congratulations!
Apparently you never read my comment history ... or went through and downvoted me out spite
Keep your secret knowledge to yourself if you want - since you seem so averse to sharing why you think something
Such as ...?
But keep thinking you have
And also he sells ONE product that in 2023 has admittedly dubious value (SpinRite), and I will also admit that the website oversells it quite a bit. But all of the complaints I've seen about it basically boil down to those people not really understanding what it's for or what it does. It's not for "undeleting" data, it's not for fixing your broken filesystem, it can't recover data off a disk with a bullet-hole in it. It only works on spinning rust with _some_ bad physical sectors, if the damage is not severe enough that the data can't be recovered with many, many, repeat readings.
I listened to his podcast Security Now for the better part of a decade while commuting and found that he really enjoys getting to the root of whatever he's talking about and _usually_ (not always) does a pretty good job of explaining complex technical subjects verbally. He has always come across as quite humble to me, and _every_ episode began with a list of corrections from the previous episode. When he does make mistakes, at least he admits them.
Maybe you are not old enough to remember or be aware of how ridiculous he used to be. He's been pretty quiet the last decade, likely due to getting batted down every time he would pop up with some nonsense.
No personal grudge, just the advantage of experience. I'm hardly alone in holding this view. If you did some research, and listened to some actual security podcasts, you might learn a little bit more regarding all this.
Such as... what? Who do you think knows more than he does and/or what has he said that is incorrect?
But hey, you do you.
From outside, it looks like you have a grudge against them, but brought no actual reason. Thanks for your input I guess.
Before you shut me down as well, I learned of Gibson Research in this very thread. I'm no paid actor.
I also suggested people can google if they want to learn more.
Next time you're a random passerby to an argument you see me involved in, please just keep passing by.
Can't elaborate on anything except some kind of claimed secret knowledge that the rest of us plebes must obviously not have
Sad, really
Stop.
He's not a "favorite podcaster"
But nice try at casting aspersions instead of answering the question
Yes, I would recommend it. Running Unbound means you don't have to trust anyone's upstream DNS servers. Disadvantage is maybe slightly slower resolution, as you don't get to take advantage of the upstream server's caching.
https://wiki.alpinelinux.org/wiki/Using_Unbound_as_an_Ad-blo...
All outbound port 53 TCP/UDP is also forwarded at the firewall through this setup.
Never had any problems with either - I have both selected in case one has issues so that I don't need to immediately deal with "Daaaad the internet's not working!"
Their DNS privacy policy seems acceptable to me, as they’re not using it for ad data: https://developers.google.com/speed/public-dns/privacy
Google obviously has many concerns, but they’re trustworthy enough to follow their own privacy policy lest they get smited by governments.
Example: They can see that I have visited Wikipedia, but not what articles I’ve read. (Other sites will leak more info due to the nature of their subdomains, but it doesn’t bother me personally.)
lots of hits on hackernews and jsoneditoronline.org and I can say with a reasonable degree of certainty that you're in IT or Dev. gonna start sending you ads that reflect that.
likewise, hits to missile-gayboy.jp -- a site that used to be hosted by my old employers -- also sends some pretty clear messages. I don't need to know what you're looking at specifically there but it's a japanese site that caters to a specific niche; I can sure make some assumptions.
hell, at work we don't even collect a lot of specifics on our endpoints -- domain queries are often enough to catch bad behavior
In theory EDNS Client Subnet (ECS) is supposed to work around this problem, but a) according to https://www.cdnplanet.com/blog/which-cdns-support-edns-clien... Akamai only supports this with Google and OpenDNS and b) alternative DNS providers might not support ECS anyway, whether explicitly for privacy reasons or otherwise…
Which means I'd basically have to set up a custom DNS resolver in order to special-case queries for anything hosted on Akamai's CDN…
Both my AdGuard server and the unbound in my Opnsense router use Quad9 over DoT
AdGuard Home Server also point to Opnsense unbound to resolve local addresses
All port 53 traffic not directed at my AdGuard is redirected to it. All port 53 traffic not to or from my adguard or opnsense is blocked.
All DoT and DoH traffic not to or from my AdGuard or Opnsense is blocked.
I also have a second AdGuard Home instance hosted in a VPS that i use for my mobile devices when outside my home network. I use a whitelist of ClientIDs so only my devices can use this server, weak authentication but it has worked so far.
My home network is configured so that my devices will be redirected to my internal AdGuard server when at my home network and so they will use my public AdGuard server automaticaly when they are anywhere else.
My firefox, edge and chrome at my laptops have a similar configuration using their own DoT/DoH resolver. For the OS i let it use whatever the DNS from the local network.
In the near future i plan on replacing the Quad9 with my own recursive server hosted in the same VPS.
This way, if I ever forget my browsing history, I can ask either company to remind me ;)
Seriously though, they're both fast (especially Cloudflare) and reliable, and won't do DNS injection attacks like local ISPs do. Not really concerned about the privacy angle since I already use Chrome and Google Searched logged in.
I would generally recommend using anything other than your ISP's DNS servers.
AdGuard has a pretty good list of available providers: https://adguard-dns.io/kb/general/dns-providers/
[1] https://dnsdist.org/ [2] https://0xerr0r.github.io/blocky/
See https://localroot.isi.edu/about/ for one site that will let you register to receive a DNS Notify when the root zone changes.
In the EU/aligned countries, selling your data and injecting shit into DNS is very much a frowned on thing. More over, as there is competition, you can migrate away to some other ISP that isn't shit.
I currently use my ISP's DNS as an upstream, as they are reliably, fast and not shit. I'm temtped by adding a pi-hole. But I've not fully tested it yet, and I'm reluctant to migrate away from pfsense's DNS, as I have lots of local hosts that need resolving.
This is the same reason I don't use a VPN by default at home.
- Google 8.8.8.8
- Cloudflare 1.1.1.1
Anyone have issues with PIA's dns?
I'm in the process of taking control of my network again, after having a more laissez-faire attitude towards network access. I'll probably install something like opensense on top of my edgerouter.
I use Quad9 (9.9.9.9) and Freenom (80.80.80.80)
4.2.2.2
4.2.2.3
And devices -> NextDNS as a fallback.
I see a lot of mentions for Pi-Hole, which is more or less the same thing as AdGuard Home. I just like AdGuard Home a little bit more:
- single binary go app
- easy to run in nonroot container (Pi-Hole only started supporting this last year)
- Native support for DoH upstream resolver
- YAML as configuration language with good versioning scheme and skew practices.
@jedisct1, it would be great if there was an option to default to a ODoH/anonymized DNS setup mostly out the box.
Really, installing Unbound is piece of cake both on Windows and Linux.
Probably asking too much, but I want to ‘apt install unbound-quickstart’ and know sane defaults are configured. If anything goes wrong, I can delete a single config file or uninstall the package to go back to system defaults.
I'm literally just did this:
dnf install unbound
systemctl enable --now unbound
nmtui (because I'm lazy) to point DNS to 127.0.0.1
After reboot (again I'm lazy) I got: $ dig news.ycombinator.com
; <<>> DiG 9.16.23-RH <<>> news.ycombinator.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29106
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;news.ycombinator.com. IN A
;; ANSWER SECTION:
news.ycombinator.com. 1 IN A 209.216.230.240
;; Query time: 74 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Tue Oct 24 16:07:11 GMT 2023
;; MSG SIZE rcvd: 65
I think you... just misunderstood something years ago. You don't need 'quickstart' for thisOn Windows it's the same - download package, install it, configure 127.0.0.1 as primary DNS
It's not hard. It uses minimal resources. It can be enhanced with ad-block lists similar to pi-hole so your whole network benefits.