6 ms·
> I don't want to use the ISP's dns however. Careful. Even if you point at a different dns resolver, your ISP still gets to see this traffic, and it can still
by Skunkleton 6y ago
> I don't want to use the ISP's dns however.
Careful. Even if you point at a different dns resolver, your ISP still gets to see this traffic, and it can still MITM it. This is not theoretical, it is trivial. Many ISPs do it.
- zamadatix 6y agoConfidentiality isn't the only form of trust, many are simply annoyed with "features" such as wildcard catch-alls that direct you to ad/search pages instead of saying the domain doesn't resolve.
- philsnow 6y agoI use non-ISP dns servers for a variety of reasons. I've tested and found 1.1.1.1 faster than my ISP dns in the past. Some people use e.g. opendns because they want to use that for keeping track of what dns names are being queried from inside their networks. I actually do use my ISP's dns for some names (particularly netflix), because only they know the names of their internal cache boxes. I have a dnsmasq configuration that sends queries that end in `netflix.com` to the ISP dns and others to 8.8.8.8/1.1.1.1 or whatever.
- fomine3 6y ago> I actually do use my ISP's dns for some names (particularly netflix) Oh it looks like good setup, I'll try it.
- JdeBP 6y agoTo those who are complacently assuming "Well, the ISPs in my country do not do that.": One of the larger ISPs in the United Kingdom does that. * https://news.ycombinator.com/item?id=24280536 https://news.ycombinator.com/item?id=24280536 I've seen no evidence that Virgin Media intercepts UCP/TCP port 53 traffic, however. It just runs rigged proxy DNS servers and farms them out over DHCP. I've seen several reports that the Virgin Media "click here to disable" mechanism is a placebo that actually does nothing at all, including what that message was a reply to.
- Skunkleton 6y agoSome ISPs intercepted DNS and redirect it. You might think you are using 1.1.1.1 or whatever, but you might not be.
- asveikau 6y agoI am using TLS. The OpenBSD box has its own dhcpd and dns server. The leases it offers point to itself for dns in the LAN. Then it makes forwarded queries over TLS.
- gen3 6y agoWhat are you using to do DNS over TLS?
- 0xdeadb00f 6y agoI would assume unwind, as they're using OpenBSD. https://man.openbsd.org/unwind.conf https://man.openbsd.org/unwind.conf lists some Do-T-related config options.
- asveikau 6y agoActually unbound. I forget why I chose this over unwind. I had a reason once. Set it up years ago and didn't touch the config files. Maybe the initial setup predated unwind and I had something working already...? Totally off topic, but I was thinking of replacing it with something I wrote myself. I had some downtime earlier this year and I wrote a forwarding dns server that can speak TLS on both ends. Was simple to do. But needs some polishing before I throw it on github or use it at home.
- 0xdeadb00f 6y agoHey, that's really cool!
- teunispeters 6y agodnsmasq, unwind and others all support DNSSEC If you can get a DNS path with DNSSEC, this bypasses the ISP's ability to manipulate your DNS. Of course, DNS over HTTP is another solution to the same, for browsers. Of course one could also tunnel through. (YMMV again with trust paths but eyes open helps)
- tptacek 6y agoIt doesn't matter how much of your own software supports DNSSEC: if the sites you talk to on the Internet don't explicitly support it, DNSSEC does nothing for you. This is a problem, because most sites on the Internet don't support it. Several of the most important sites on the Internet, with some of the largest security teams in the industry, have said they don't intend ever to support it. On the other hand, DNS over HTTPS defeats ISP DNS interception regardless of who supports it, which is why so many more people use it than use DNSSEC, which is moribund.