722 karma · joined April 26, 2013
People can get detained, deported and humiliated for no reason and with no resource. Specially foreigners trying to go through.
Sucuri: DNS, WAF and CDN
NOC.org: DNS, WAF and CDN
For my young kids ( under 10 ), I am very strict on what they can see and do online. Screen time, CleanBrowsing, and app restrictions enabled.
For my teenager, it is a bit different. More conversation, more privacy and more spending time teaching her about computers, security, privacy, etc. She chose to install CleanBrowsing, an ad blocker, all on her own to protect herself.
Good luck!
But still love Firefox.
What I try is to solve a small piece of the problem I am trying to solve to get more familiar with it before committing.
- 1.1.1.1
- Neustar DNS
- AdGuard DNS
But they don't block Quad9 or CleanBrowsing that also do not send the EDNS subnet. Very curious way of blocking itself out of the Internet. OpenDNS blocks it (sends to their block page):
https://dnsblacklist.org/?domain=archive.is
Would love to hear from someone from archive.is what is going on.
That goes into the argument that DNS (domain name lookup) should be a system and network-level setting, not an App-based setting.
But I don't think we are ever going back to that direction. The arguments and benefits for running one locally are not enough the trouble as well.
Performance? Due to DNS caching at the resolver level, it is probably faster to use Google's 8.8.8.8 or CloudFlare's 1.1.1.1, than anything local (where all dns requests are a MISS).
Privacy? With DNS over TLS/DNS over HTTPS, your ISPs can't see what you are doing. If you run DNS locally, they can. Yes, they will see all the requests your resolvers are doing to the auth DNS servers.
Security? Some good resolvers, like Quad9 or CleanBrowsing will block malicious domains. CleanBrowsing will also help blocking adult content if you have kids. I don't think maintaining such control is practical for most people (pi-hole helps, but still hard to keep it updated and find good enough databases to use).
I would love a de-centralized web, but it is pretty hard to go back.
Whatever luck you get on your first job or whatever your pays more, becomes the problems you are solving.
Your ISP can see the IP addresses and all the meta data for your traffic. With the current way DNS is setup, they can modify the responses and re-route you any where they want.
With HTTPS and encrypted DNS, it makes a lot harder for them to inject content or redirect you without browsers warnings.
* Google: 8.8.8.8 * Quad9.com: 9.9.9.9 * http://OpenDNS.com: 208.67.222.222 * https://CleanBrowsing.org: 185.228.168.168
Results:
New York:
64 bytes from 8.8.8.8: icmp_seq=2 ttl=60 time=1.62 ms
64 bytes from 9.9.9.9: icmp_seq=2 ttl=60 time=0.924 ms
64 bytes from 208.67.222.222: icmp_seq=2 ttl=60 time=1.18 ms
64 bytes from 185.228.168.168: icmp_seq=2 ttl=57 time=1.93 ms
Montreal:
64 bytes from 8.8.8.8: icmp_seq=2 ttl=55 time=13.0 ms
64 bytes from 9.9.9.9: icmp_seq=2 ttl=56 time=16.7 ms
64 bytes from 208.67.222.222: icmp_seq=2 ttl=56 time=16.5 ms
64 bytes from 185.228.168.168: icmp_seq=2 ttl=50 time=9.18 ms
Dallas:
64 bytes from 8.8.8.8: icmp_seq=1 ttl=61 time=1.09 ms
64 bytes from 9.9.9.9: icmp_seq=1 ttl=59 time=29.8 ms
64 bytes from 208.67.222.222: icmp_seq=1 ttl=58 time=1.03 ms
64 bytes from 185.228.168.168: icmp_seq=1 ttl=57 time=1.29 ms
Paris:
64 bytes from 8.8.8.8: icmp_seq=2 ttl=56 time=4.61 ms
64 bytes from 9.9.9.9: icmp_seq=2 ttl=56 time=6.71 ms
64 bytes from 208.67.222.222: icmp_seq=2 ttl=56 time=4.60 ms
64 bytes from 185.228.168.168: icmp_seq=2 ttl=54 time=3.85 ms
Tokyo:
64 bytes from 8.8.8.8: icmp_seq=1 ttl=59 time=1.10 ms
64 bytes from 9.9.9.9: icmp_seq=1 ttl=55 time=65.7 ms
64 bytes from 208.67.222.222: icmp_seq=1 ttl=57 time=1.57 ms
64 bytes from 185.228.168.168: icmp_seq=1 ttl=59 time=0.551 ms
Only New York and Paris were close. Their performance in Tokyo & Dallas were sub optimal. OpenDNS has a much better performance and closer to Google than quad9.But I will still try it out and hope they keep supporting it.
OpenBSD -> Secure & minimal Server
OpenBSD doesn't have the isolation and hardening on the desktop apps, as Qubes has.