← Home ← Back to /g/

Thread 106479494

89 posts 30 images /g/
Anonymous No.106479494 >>106479500 >>106479567 >>106479771 >>106479795 >>106479875 >>106480156 >>106480223 >>106480510 >>106481442 >>106481479 >>106481500 >>106483875 >>106484409 >>106486278 >>106486575 >>106488101 >>106488941 >>106491783 >>106491796
What is your DNS setup?
Anonymous No.106479500
>>106479494 (OP)
I run my own recursive resolver
Anonymous No.106479523 >>106481550
pihole > dnscrypt-proxy > cloudflare
Anonymous No.106479554
I don't remember.

I just checked and I was running some DNS locally, but actually last night I shut down the VM for it. But home internet was still working... so I have no idea. Maybe browser/os cache was enough that I didn't notice?
Anonymous No.106479567
>>106479494 (OP)
my own, which just recurses to cloudflare.
DoH usually slips by when some fuckass ISP feels like blocking cloudflare
Anonymous No.106479587 >>106481550
Ok it's back up now. PiHole > Google
I tried AdGuard when I ran on a pi, then stopped serving and just used AdGuard DNS for awhile, but after getting my vm set up I went back to pihole.
Anonymous No.106479734 >>106481550
Cloudflare.

[Resolve]
DNS=2606:4700:4700::1111#one.one.one.one 2606:4700:4700::1001#one.one.one.one
DNSOverTLS=yes
LLMNR=no
MulticastDNS=no
Anonymous No.106479761
pihole into opendns
Anonymous No.106479771 >>106481682
>>106479494 (OP)
Mullvad's "base" DNS server
https://mullvad.net/en/help/dns-over-https-and-dns-over-tls
Anonymous No.106479795
>>106479494 (OP)
adblock.dns.mullvad.net
Anonymous No.106479802 >>106479828 >>106479829 >>106481121 >>106486273 >>106490756
i just use google. the weird thing is when i visit torrent sites and fire up utorrent my internet suddenly cuts off.
Anonymous No.106479828
>>106479802
works on my machine
Anonymous No.106479829
>>106479802
Probably because utorrent has literal aids
Try qbitorrent
Anonymous No.106479842 >>106481550
Quad9
Anonymous No.106479849
base mullvad.
Anonymous No.106479854
dns.adguard-dns.com
Anonymous No.106479875 >>106488083
>>106479494 (OP)
I use NextDNS
Anonymous No.106479902
I round-robin between Cloudflare, Quad9, Adguard, and Mullvad via DoH/DoT
Only use their non-filtering servers because my router runs Adguard Home to do the DNS filtering for ads and trackers
Anonymous No.106480156
>>106479494 (OP)
bind to local privacy oriented provider
Anonymous No.106480223
>>106479494 (OP)
Local dnscrypt-proxy on every machine, mostly standard config but with a forwarding rule to forward Tailscale domain names to its resolver.
I used to run pihole but I realized it was redundant because I already had uBO deployed via enterprise policy on every machine.
Anonymous No.106480229 >>106481121
Google DN, because here in Spain the goverment and LaLiga block anything from cloudflare for "anti-pirate" reasons.
Anonymous No.106480276
The one of my isp with whatever dnsmasq does on my router.

I am not a fucking idiots routing even more of my traffic to giant glowdag corpos.
Anonymous No.106480510 >>106480522 >>106481121
>>106479494 (OP)
Censurfri and google.dns as a fallback, because European Utopia's dictatorship won't let you connect to the Soulseek and so on
Anonymous No.106480522
>>106480510
...over TLS, I forgot to mention, port 53 is redirected to the great firewall otherwise
Anonymous No.106480573
Anonymous No.106481121 >>106481489
>>106479802
>>106480229
>>106480510
Google, just like that?
Anonymous No.106481442
>>106479494 (OP)
adguard home running on my router
Anonymous No.106481479
>>106479494 (OP)
Quad9->Open-DNS
Anonymous No.106481489
>>106481121
sum people just dgaf
Anonymous No.106481500 >>106481516
>>106479494 (OP)
9.9.9.10:853
149.112.112.10:853

Accessed through TOR via personalDNSfilter.

Allowing TOR nodes to resolve is a hit and miss, so this is the better choice as clumsy as it seems.
Anonymous No.106481516 >>106481532
>>106481500
>through TOR
isn't the latency crazy high
Anonymous No.106481532 >>106481607
>>106481516
Not as high as you're thinking. Somwhere in the 400-600 ms range so it's very usable on my end.
Anonymous No.106481537 >>106481544
Why the fuck would any of you niggers use DNS over TLS
Anonymous No.106481544
>>106481537
Extra layer of privacy.
Anonymous No.106481550 >>106491723
>>106479842
>>106479523
>>106479587
>>106479734
CIA/Mossad
Anonymous No.106481607 >>106481616 >>106481657
>>106481532
Not as bad as I thought indeed, expected it to be close to a full second. Does you have any special DNS cache settings to mitigate the latency or does it hit the server on most queries?
Anonymous No.106481616
>>106481607
Do you run*
Anonymous No.106481657
>>106481607
Hits it on all queries. No dns caching anywhere. For me it's better to just reload when something doesn't resolve right away (hardly ever happens) than to wait for the flush.
Anonymous No.106481671
open.dns0.eu
Anonymous No.106481682
>>106479771
I use this but the ad blocking one.
Anonymous No.106481738 >>106481757
AdGuard Home server with DoH/DoT upstreams to Quad9 and Mullvad + fallback to Cloudflare
Anonymous No.106481757
>>106481738
>fallback to Cloudflare
>makes himself vulnerable to downgrade attacks by globohomo
Anonymous No.106481781 >>106481850 >>106481987 >>106482164
fuck mullvad
Anonymous No.106481850
>>106481781
their DNS doesn't even work on my system, just says it's invalid.
they're a joke, use controld or sb instead
Anonymous No.106481987 >>106482164 >>106482326
>>106481781
Their routing is bullshit. I'll get sent to Singapore for no reason despite being in the EU which would result in high latency like that.
https://mullvad.net/en/help/dns-over-https-and-dns-over-tls lists region specific servers you can use, though idk about reliability.
Anonymous No.106482139 >>106482343
when did everyone switch from pihole to adguard home anyways what happened
Anonymous No.106482164
>>106481781
>>106481987
yeah i get some bs long routes sometimes with them too. had a couple of blackouts too.
Anonymous No.106482326
>>106481987
Exactly! I'm from Germany, and this works best in my systemd-resolved:
DNS=185.213.155.123#de-fra-dns-001.mullvad.net
Remember to set up a FallbackDNS in case of an outage.
Anonymous No.106482343
>>106482139
About 5 years ago. The smell.
I ran pihole on a pi and it kept breaking itself. Adguard Home ran much better. I assume lots of people had issues with pihole, were lured by the promise of a simpler program with better performance, and switched.
Anonymous No.106482463 >>106482820 >>106483714 >>106483820 >>106484419
Quad9 is literally feds jfc you fucking morons
Anonymous No.106482820 >>106483714
>>106482463
It's known that the police operate it, so I would say the people who say they use quad9 are actually cops.
Anonymous No.106483714 >>106483724
>>106482463
>>106482820
Is it actually fedshit or is this some reverse psychology method being used by feds (if you are them) to deter brainlets like me to keep using cloudflair?
Anonymous No.106483724
>>106483714
***Cloudflare
Anonymous No.106483820
>>106482463
Everything is until the guys running it go to jail. That's the schizo standard, and that's why you don't access these servers directly.

Fed or not, it's still the most comprehensive, uncensored and reliable dns servers I've tried so far.
Anonymous No.106483875 >>106484234
>>106479494 (OP)
My Adguard Home keeps losing connection and must be restarted after a while, this didn't happen for months after I installed it and it was stable. I updated it several times and nothing get fixed wtf
Anonymous No.106484234 >>106484374
>>106483875
Yeah I have this issue right now too, just stopped using it and I'll see in a few months if it resolves itself
Anonymous No.106484374
>>106484234
Last time I checked their repo I didn't find anything about this, guess I'll go with PiHole in the meantime

>I'll see in a few months if it resolves itself
This is what I was doing while thinking the next update would fix something
Anonymous No.106484409
>>106479494 (OP)
Pihole > Cloudflare
Anonymous No.106484419 >>106484492 >>106486579
>>106482463
>Quad9 is literally feds
Yes and? I'm not a criminal, I don't search criminal search. Not everyone is a pedophile, pedro.
Anonymous No.106484447
postem
Anonymous No.106484492 >>106484795
>>106484419
Most NPC post I've read in months. kys
Anonymous No.106484795
>>106484492
Pedophile
Anonymous No.106486273
>>106479802
Anonymous No.106486278
>>106479494 (OP)
Just use a text file and paste IPs manually, are you a noob?
Anonymous No.106486457 >>106487992
you guys dont run your own recursive dns resolver?
Anonymous No.106486503
I tried running my own local dns for a while but eventually just settled for my ISP's. it's a relatively small, rural ISP not owned by any conglomerate and it seems decent enough, so it felt better than something like google or cloudfare
how would one go about measuring how bad it is anyway?
Anonymous No.106486575
>>106479494 (OP)
Bind running as a recursive resolver.
Anonymous No.106486579 >>106488231
>>106484419
>posted by a fed or a literal saru
Anonymous No.106487992 >>106488010
>>106486457
Why would I waste time on that?
Anonymous No.106488010
>>106487992
It's really only worth doing if:
a) You want to create and control DNS records within your local network
b) You want to block addresses and prevent them from resolving in the first place (Can also be done via a cloud provider tho)
Anonymous No.106488083
>>106479875
Anonymous No.106488101 >>106488231
>>106479494 (OP)
very glowing thread. im not gonna tell you by the way
Anonymous No.106488132
I don't recall what was set up.
Anonymous No.106488231
>>106488101
>>106486579
take your meds
Anonymous No.106488941 >>106488963 >>106489066
>>106479494 (OP)
How much does this even do, privacy wise? Even if your ISP can't see your DNS traffic, they'll still see your HTTP traffic, right?
Anonymous No.106488963
>>106488941
What does what do?
Anonymous No.106489066 >>106489390 >>106490240
>>106488941
HTTPS alone does not cover DNS. You need to use DoT or DoH. That being said just about every modern browser uses DoH and if your operating system has secure dns setup it'll defer to that.

But if your concern is your ISP / Cloudflare / Google / (Whatever DoH resolver you use) snooping on you then DoH does not fix that. DoH only prevents 3rd party observers seeing what you're doing, the endpoint (ISP, Cloudflare, etc) will still see your DNS request... as they need to in order to resolve it.

So it's a matter of "who do I trust more". Your ISP (They keep logs for police if subpoenaed, I forget how long but they do). Cloudflare, Google, etc. (Spoiler: Most probably keep logs for legal reasons).

Also yes, if you go to a http website your ISP, and everyone else, can snoop on it. Also even with https they can snoop on the IP destination. If you really care about full coverage for both https/http/dns you need a VPN. If you're a schizo you can probably find a VPN in some shithole that won't cooperate with the US. If you're not schizo it just gives a tiny peace of mind, but if the VPN provider keeps logs don't be surprised if they (the feds) can reconstruct what you did. Realistically if you're in that much shit you have lots of other things to worry about imo.
Anonymous No.106489293
pihole > cloudflared doh > quad9
Anonymous No.106489390
>>106489066
Two major uk isps are keeping all dns queries but won't say why. It's a good idea to consider a secure dns these days. At the very least you should all be putting dns on max protection with a custom dns in your browser settings.
Anonymous No.106490240
>>106489066
To avoid the whole logs issue I recommend dnscrypt-proxy, it will proxy your request to one of a few dozen servers (including upstream DoH, DoT and its own DNSCrypt protocol) so your queries are spread across multiple servers. It adds redundancy in case one goes down, and even if your queries are logged they would need to get them from all providers you use to get the full picture.

For snooping websites, HTTP is insecure, anyone on the wire (aka ISP) can see the full content of the webpages. For HTTPS, the content is encrypted, but they can see the IP (of course) and the hostname from the server name indication (SNI) field. Cloudflare is currently rolling out encrypted ClientHello (ECH) for all sites on their platforms, so if you use a modern browser then ISPs will no longer be able to see which site it is but that it's just a site on Cloudflare. Which is like every website nowadays.
>for all the shit cloudflare gets this is actually a rare instance where one entity having control of a large number of websites lets them deploy the same generic SNI across every website and defeat censorship
>a government wanting to block one site on cloudflare would have to block every site on cloudflare
Anonymous No.106490756 >>106491456 >>106491460
>>106479802
>utorrent
It's not 2009 anymore, get with the times grandpa
Anonymous No.106491456 >>106491460 >>106491511
>>106490756
what for? the downloaded files are 100% identical. i disregard your opinion of anything about computers now. you are retard, yes ?
Anonymous No.106491460 >>106491484
>>106490756
>>106491456
transmission, neegas
Anonymous No.106491484
>>106491460
newfremd, transmission can be manipulated

nobody can do anything
Anonymous No.106491511 >>106491542
>>106491456
>what for?
Adware, bloatware, got caught more than once for adding a bitcoin miner to the client.
But sure, you do you.
Anonymous No.106491542
>>106491511
i gots computer related ptsd as well, but it's from using macs. the web connects us across all operating systems, ain't that amazing? shared sufferihhhng
GLOW IN THE DARK NOTICER No.106491723
>>106481550
This.

Glowflare niggers out here shilling their shit. Kys niggers.
Anonymous No.106491783
>>106479494 (OP)
unbound.
Anonymous No.106491796
>>106479494 (OP)
Adguard
It just werks