Use other DNS servers than your ISP's
chaz6.com
chaz6.com
They have no obligation to provide DNS services except to Level 3 customers[1], they don't like providing those services, and they have been known to hijack DNS requests to inject ads and other services[2] for unauthorized users.
[0] http://www.tummy.com/articles/famous-dns-server/
[2] And if you're a Level 3 customer, you're probably not using this list
[2] http://james.bertelson.me/blog/2014/01/level-3-are-now-hijac...
The request hijacking briefly appeared earlier this year, but they seem to have stopped doing it.
seems to me that it really depends on the service quality of the ISP. if you're lucky and have a good ISP, wouldn't using its servers be faster (less hops)? are there other arguments for using different servers?
https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_...
Caching and speed are the other most likely reasons.
As stated by its cofounder in the "no more ads" post, OpenDNS is a "revenue oriented company" so it seems the logic behind this option existing for registered user sis that they get more money from selling registered user data than from showing ads.
Technically, there may be an advantage to using a 'closer' DNS server with 'less hops', but many national ISPs don't push DNS servers to all POPs. DNS infrastructure at large ISPs tends to be heavily loaded and is scaled based on demand.
It's common, and many wifi routers do this for you by default, to run a local caching nameserver which uses some other ISP nameservers as 'forwarders'. You create less demand upstream as well as getting faster response if you do this.
Obviously you should also be concerned about creating load on DNS services provided by someone you have no relationship with. Some might even consider it rude.
In addition to OpenDNS, Google runs free DNS servers at 8.8.8.8 and 8.8.4.4, but obviously there are concerns with relying upon Google to provide all of the internet's infrastructure.
What we should really all be talking about is decentralized, peer-to-peer DNS, or a system of forwarders we all provide from places like Linode and DigitalOcean, both of which I've used to provide off-site secondary and tertiary DNS for large networks. We should be looking at NameCoin, not just leeching off some other random ISP.
Nothing is worse than trying to SSH into a server with a domain typo, and thinking it exists...
Take a look at dnschain [0], which allows you to query Namecoin domains using standard DNS or HTTP:
$ dig @dns.dnschain.net otokar.bit
[....]
;; ANSWER SECTION:
otokar.bit. 527 IN A
109.190.29.155
[...]
[0] https://github.com/okTurtles/dnschainI work for one in Russia (quite unhealthy country for Internet those days), and AFAIK we're only supposed to keep accounting records (i.e. times, assigned IP addresses etc.)
Laws ordering ISP to keep logs of their customer activity are becoming increasingly common around the world. By using a different DNS server your ISP DNS server has no logs to show for your DNS activity.
It is good privacy practice to split the data about your internet activities across different providers to make it more difficult to track you. For example if you use google services for web search, then you should not use google for your email (ideally your should host your own email).
But the sad state of reality is that ISP DNS are often poor, whether it is hijacking DNS for profit or blocking domains following judge's orders or local laws.
On the contrary, by using a different DNS server you're giving your data both to your ISP (you have to) and a 3rd party.
And if you're worrying about DNS leaks, your ISP is still able to read that traffic even when using a different DNS provider (assuming no DNSCrypt or similar).
3rd party DNS servers can be useful, I just don't see any additional value to your privacy when not coupled with DNSCrypt/DNSCurve.
Not really. Now both your ISP and your DNS provider know what sites you're visiting. All you're doing is increasing your attack surface.
So, when is it that you do not want to call an operator to patch every call you make? Ask yourself this question, knowing that the operator keeps a list of every incoming and outgoing call. Know that they sometimes also lie and say that the party you are calling is not reachable, while in fact the operator simply refuses to connect you. Some operators will even send you to a telemarketer in order to monetize poorly stated questions.
On the positive side, it is faster. Asking your ISP for every DNS resolving does sometime give an increase speed by shaving a few milliseconds the first time you connect to a website. Depending on what you prioritize, that is either worth it, or not.
A better solution would be to have a distributed p2p DNS instead of the current one.
Anyway, I am totally all for a distributed p2p DNS, at least as a replacement for root servers.
DNS is a distributed, p2p system. The ability to add records that can be globally retrieved is not ad-hoc, but you didn't mention that in your requirement. </obligatory_pedantry>
Anycast solved this ages ago. Also, the TTL on most TLDs is 172800 seconds, so you'll have NS entries cached for the 'com' 'org' 'gov' etc. GTLD servers almost immediately and then never bother the root servers again for two days.
Rough translation of the reason some of it is crossed-out: Due to a software error, DNSSEC validation is currently disabled. The DNS server with the IP address 87.118.85.241 is (currently) no longer available. In the future, there will certainly be three servers again.
And if you install a VPN server there, and VPN clients on your mobile equipment, then you can also access that nameserver from anywhere.
Some of these support DNSSEC and Namecoin.
http://www.verizon.com/support/residential/internet/highspee...
Sorry, that's a terrible joke, let's hope people filter egress traffic with IP's that don't match their network from their ISP's.