4 ms·
For privacy concerned netizens, especially UK based ones, I highly recommend checking out DNSCrypt[0]. It securely tunnels all your DNS requests to an endpoint
by ymse 10y ago
For privacy concerned netizens, especially UK based ones, I highly recommend checking out DNSCrypt[0]. It securely tunnels all your DNS requests to an endpoint of your choice.
I've used it for about two years and it's very reliable, even on a laptop. I do recommend using it in conjunction with a caching DNS recursor such as Unbound[1] to save bandwidth.
It also works great on OpenWRT if you have that luxury.
For UK residents, please also consider changing to an ISP that cares about your online rights. I only know this one: http://aaisp.net.uk http://aaisp.net.uk
0: https://dnscrypt.org https://dnscrypt.org
1: https://unbound.net https://unbound.net
- anexprogrammer 10y agoThere's also http://zen.co.uk http://zen.co.uk Only know of those two free of shaping, blocking and bad support beloved of all the other UK ISPs. Their blog is consistently anti surveillance.
- teh_klev 10y ago+1 for A&A. I've used them for years. The owner's blog is also worth a read: http://www.revk.uk/ http://www.revk.uk/
- CommanderData 10y agoThis could easily become illegal for circumventing state censorship. It might already be in places like China (if DNS tunneling helps stop censorship at all)
- mike-cardwell 10y agoNot happy with only your ISP and government knowing where you're going online? Install DNSCrypt and add some more third parties to the mix. [edit] From DNSCrypt's own front page: Please note that DNSCrypt is not a replacement for a VPN, as it only authenticates DNS traffic, and doesn't prevent "DNS leaks", or third-party DNS resolvers from logging your activity. The TLS protocol, as used in HTTPS and HTTP2, also leaks leaks websites host names in plain text, rendering DNSCrypt useless as a way to hide this information.
- ymse 10y agoThis is true. It's more of a DNS MITM protection rather than privacy fix. There are other uses of DNS than just HTTP(S) traffic though: but I'm sure these mass surveillance entities sit on massive reverse DNS databases anyway, rendering the effort mostly useless.