HNHacker News
TopNewBestAskShowJobs

DesertBattery

14 karma · joined October 24, 2016

submissionscomments
DesertBattery··on Yandex warns of bond repayment and supply risks
You're wrong. People getting angry at West and talking about war. Including nuclear.
DesertBattery··on Wireguard VPN: Typical Setup (2017)
I have no idea what happened.
DesertBattery··on Wireguard VPN: Typical Setup (2017)
They work on it https://github.com/WireGuard/wireguard-windows/commits/maste....
DesertBattery··on Wi-Fi Alliance introduces Wi-Fi 6
> 802.11ac is a 5-GHz-only technology

https://www.cisco.com/c/dam/en/us/products/collateral/wirele...

DesertBattery··on 1.1.1.1: Fast, privacy-first consumer DNS service
Aren't o-o.myaddr.l.google.com is intended for troubleshooting and should show correct ECS? o-o.myaddr.test.l.google.com always show correct ECS.
DesertBattery··on DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

  dig @9.9.9.11 +short
  ;; connection timed out; no servers could be reached
  dig @9.9.9.12 +short
  ;; connection timed out; no servers could be reached
DesertBattery··on DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS
Should, but does not.

  dig @8.8.8.8 o-o.myaddr.test.l.google.com txt +short 
  "74.125.46.11"
  "edns0-client-subnet 94.181.44.185/32"
  dig @9.9.9.10 o-o.myaddr.test.l.google.com txt +short
  "2620:171:57::240"
DesertBattery··on 1.1.1.1: Fast, privacy-first consumer DNS service
I have static public /32. My ISP intercepting DNS traffic for censorship purposes. But i strongly doubt that this traffic is forwarded somewhere.

  [user@v-fed-1 ~]$ dig txt o-o.myaddr.test.l.google.com @8.8.8.8 +short
  "173.194.98.4"
  "edns0-client-subnet 94.181.44.185/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.test.l.google.com @8.8.8.8 +short
  "173.194.98.4"
  "edns0-client-subnet 94.181.44.185/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.test.l.google.com @8.8.8.8 +short
  "173.194.98.4"
  "edns0-client-subnet 94.181.44.185/32"

  [user@v-fed-1 ~]$ dig txt edns-client-sub.net @8.8.8.8 +short
  "{'ecs_payload':{'family':'1','optcode':'0x08','cc':'RU','ip':'94.181.44.0','mask':'24','scope':'0'},'ecs':'True','ts':'1522656335.56','recursive':{'cc':'FI','srcip':'74.125.74.4','sport':'40964'}}"
  [user@v-fed-1 ~]$ dig txt edns-client-sub.net @8.8.8.8 +short
  "{'ecs_payload':{'family':'1','optcode':'0x08','cc':'RU','ip':'94.181.44.0','mask':'24','scope':'0'},'ecs':'True','ts':'1522656336.4','recursive':{'cc':'US','srcip':'74.125.46.4','sport':'51510'}}"
  [user@v-fed-1 ~]$ dig txt edns-client-sub.net @8.8.8.8 +short
  "{'ecs_payload':{'family':'1','optcode':'0x08','cc':'RU','ip':'94.181.44.0','mask':'24','scope':'0'},'ecs':'True','ts':'1522656337.96','recursive':{'cc':'US','srcip':'74.125.46.4','sport':'54992'}}"

127.1 is a DNS-over-HTTPS proxy.

  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @127.1 +short
  "173.194.98.11"
  "edns0-client-subnet 94.181.44.0/24"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @127.1 +short
  "173.194.98.11"
  "edns0-client-subnet 94.181.44.0/24"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @127.1 +short
  "173.194.98.6"
  "edns0-client-subnet 193.151.48.130/32
Some story from other (business) connection.

  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.74.3"
  "edns0-client-subnet 37.113.134.30/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.4"
  "edns0-client-subnet 85.29.165.14/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "173.194.98.13"
  "edns0-client-subnet 77.234.25.49/32"
DesertBattery··on 1.1.1.1: Fast, privacy-first consumer DNS service
Load balancing of ECS?
DesertBattery··on 1.1.1.1: Fast, privacy-first consumer DNS service
I think i have questions to Google:

  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.8"
  "edns0-client-subnet 92.223.114.166/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.11"
  "edns0-client-subnet 176.36.247.0/24"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.74.3"
  "edns0-client-subnet 94.181.44.185/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.8"
  "edns0-client-subnet 92.223.114.166/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.74.3"
  "edns0-client-subnet 94.181.44.185/32"
DesertBattery··on 1.1.1.1: Fast, privacy-first consumer DNS service
ISP can do anything with you DNS traffic. That's why Cloudflare DNS support DNS-over-TLS.
DesertBattery··on 1.1.1.1: Fast, privacy-first consumer DNS service
Quad9 not friendly to CDN.

  $ dig +short @8.8.8.8 icnerd-1e5f.kxcdn.com
  p-rumo00.kxcdn.com.
  188.42.31.172
  $ dig +short @1.1.1.1 icnerd-1e5f.kxcdn.com
  p-rumo00.kxcdn.com.
  188.42.31.172
  $ dig +short @9.9.9.9 icnerd-1e5f.kxcdn.com 
  con-na00.kvcdn.com.
  p-ussj00.kxcdn.com.
  209.58.130.199
  $ dig +short @9.9.9.10 icnerd-1e5f.kxcdn.com
  con-na00.kvcdn.com.
  p-ussj00.kxcdn.com.
DesertBattery··on 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?
It does.

  $ dig @9.9.9.10 +dnssec +short verisignlabs.com
  72.13.58.64
  A 8 2 3600 20180413202737 20180330202737 31485 verisignlabs.com. KrnT9i6qytaYWDZWThBmBwc6anOmawNxJTxmSlpaY3L7Yfupga9FS70l 8nMVp8ggbEtA+CnS9AbNwObkPaYvk3nFpDvo4C+2hg+PECsP1HVTgGxl G3eblfnYAMNfYzLYlfUnSBgM7kLSIXY4rLBxsl01KiPJYezNhmQ53KYf ygs=
DesertBattery··on 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?
Not exactly the answer to your question but Cloudflare DNS support DNS-over-TLS. You can use Stubby (getdns) to encrypt your DNS queries.
DesertBattery··on F.lux v4
Don't know about other OEMs but Xiaomi's implementation is awful.