5 ms·
It's pretty unusual for ISPs to do this. But Spectrum is big enough that it's a still a valid concern. Especially now that more and more people are using mobi
by lazyguy2 7y ago
It's pretty unusual for ISPs to do this. But Spectrum is big enough that it's a still a valid concern.
Especially now that more and more people are using mobile networks from people like AT&T and Verizon, and these companies are effectively scum of the earth.
The real solution is to have the OS itself deal with DNS privacy concerns, not the browser. Localhost DNS resolver with DNSSEC enabled that will bypass the default DNS settings and go out to 'trusted' DNS servers when DNSSEC fails. Maybe even use DoH if ISP blocks normal DNS traffic.
- eganist 7y agoVerizon does it.
- lvh 7y agoHm. I have AT&T and T-mobile, and both of them do it to me?
- ohples 7y agoFrom my understanding there is no reason a OS level resolver library can't support DoH, I am surpised we haven't seen whatever Linux uses add support for it. Or maybe it did and I missed it.
- heuxbzjnz 7y agounbound supports DoH.
- Avamander 7y agoDoesn't systemd-resolved support it?
- CameronNemo 7y agoDo they use Google DNS servers by default? Or is that just NTP? https://github.com/systemd/systemd/blob/master/meson_options.txt#L223 https://github.com/systemd/systemd/blob/master/meson_options...
- MrRadar 7y agoTo add to all the other replies, CenturyLink does this too. This is a major problem with US ISPs.
- Andrex 7y agoFrontier (8th-largest US broadband provider) has also done this in the recent past, not sure if they still do.
- mtgx 7y agoUnusual? Most/all of them do it.
- Kalium 7y ago> It's pretty unusual for ISPs to do this. But Spectrum is big enough that it's a still a valid concern. At least one major ISP owned by a German company does it. It's not that weird.
- CameronNemo 7y agoI do not think a full local resolver is necessary. E.g. stubby [0] can be set up to use a remote resolver via DNS over TLS (simpler than DoH, less of a hack, all the same crypto guarantees). That remote resolver can be CloudFlare, Quad 9/101, or self-hosted unbound instance. Then only the remote resolver has to worry about caching and DNSSEC, etc. [0] https://github.com/getdnsapi/stubby/blob/develop/README.md https://github.com/getdnsapi/stubby/blob/develop/README.md
- tptacek 7y agoJust a reminder that DNSSEC doesn't do much of anything to protect Internet privacy --- all it does is sign queries, it doesn't encrypt, and the signatures are with keys effectively escrowed to the owners of the TLDs (most frequently, world governments).