ISP: 1ms to Cloudflare
Cloudflare: 10ms to Cloudflare
Thank you for your attention to this matter.
Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
ISP: 1ms to Cloudflare
Cloudflare: 10ms to Cloudflare
Thank you for your attention to this matter.
Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
You can set the DNS server of your entire LAN using Network options without setting it on the individual devices. It’s up to the end-device whether it uses it or not, but 99%-ish do.
Your DNS traffic to Cloudflare is routed via anycast. If Cloudflare is sending this DNS query (eg to an authoritative DNS server), the IP address it uses for this is not going to be the anycast one. These IPs are geolocatable and Cloudflare even publishes feeds of their approximate location. The response you get will be geolocated based on the IP that Cloudflare is using to send traffic to the authoritative.
Cloudflare explicitly does not use ECS (the edns extension to provide client subnets to authoritatives): https://developers.cloudflare.com/1.1.1.1/faq/#does-1111-sen...
If you use a Unifi router you can use it for this purpose (and caching) by broadcasting its IP as the default DNS server using Network options. It caches/forwards/filters any requests according to how you setup DNS in Firewall settings.
* for the countries/ISPs that don't also hijack all DNS
https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_...
Encrypted DNS isn't an "any day now", basically every platform and browser and provider supports it, and 100% of my household's DNS requests are opaque to anyone watching the wire. And basically every system like Cloudflare supports ECH, so SNI isn't a thing for the vast majority of sites.
The fact that they could perform DPI doesn't change the reality that most ISPs probably aren't doing it, unless mandated by law, because it's expensive and in my main country of residence they can't sell that data to offset the cost.
I'm surprised to see such lack of nuance coming from you.
It's taken a conspicuously long time to even begin to see a solution to the glaring privacy issues with SNI. Even just counting the length of time we've been aware of the problem of SNI being used for censorship and eavesdropping[1], it's over a decade, and ECH's is status is still very experimental in most web server software (and ECH is kind of a janky hack even after how long this has been discussed back and forth, the ESNI debacle, and so on).
Had me in stiches