3 ms·
Maybe, but most ISPs are lazy/cheap and can't do a full-take packet capture of all customers data at the same time. The ones that I have seen usually have a cu
by offmycloud 6y ago
Maybe, but most ISPs are lazy/cheap and can't do a full-take packet capture of all customers data at the same time. The ones that I have seen usually have a custom or logging DNS server that associates each domain request with a customer account. So yes, in many cases, changing your DNS server is enough to avoid the larger DNS sniffing operations. You should also use an IP check query to make sure that you are really using the DNS server you think, and that you're not being DNATed back to your ISP's DNS server.
- Skunkleton 6y agoDNS is super trivial to redirect. I've been on ISPs that redirect _all_ DNS traffic to their servers regardless of where it was sent. The best solution here is to switch to DoH. Of course then your DoH provider gets to log all of that sweet info instead.
- Spivak 6y agoNot if you run your own DoH endpoint on a VPS!
- Skunkleton 6y agoI have my own unbound running on a VPS. My network intercepts all port 53 traffic, filters out ad servers, and then forwards over wireguard to my VPS. I should probably enable DoH as well. I'm feeling kind of lazy about it though.
- n1try 6y agoI think ceasing to use your ISP provider's unencrypted DNS services will already bring quite some boost in privacy for the average internet user. That's why I recently switched to using DNSCrypt (https://github.com/DNSCrypt/dnscrypt-proxy https://github.com/DNSCrypt/dnscrypt-proxy) with one of the public providers listed here: https://dnscrypt.info/public-servers https://dnscrypt.info/public-servers (pick one run by some university or internet activism organization).
- Skunkleton 6y agoIt also brings an increase in recaptcha puzzles lol