10 ms·
Quad9 public DNS moves to Switzerland
- Proven 6y ago> Switzerland has a legal privacy regime harmonized with the European-standard General Data Protection Regulation. Who gives a crap about GDPR - I don't plan to sue my DNS provider and the fact that they are in Swiss is good enough for me. I don't use Quad9 because they have built in security (potential for censorship - is Parler.com in their opinion a "safe" site?) I use 1.1.1.1.
- lawl 6y agoI'm not convinced, and I'm a swiss citizen. Germany frankly seems to do better. Germans go out on the streets, while swiss people are way more content with whatever shady surveillance shit the government does. E.g. We have the mandatory data retention bullshit, I'm not sure if this is covered by this law, but if it is they'd have to save all logs for 6 months. Iirc the germans successfully fought this. Btw. these records can be stored outside of switzerland. Smells like a PR stunt without any substance.
- tumblewit 6y agoSome of the dns like clean browsing use german servers and netherlands from my testing.
- DyslexicAtheist 6y agoThe recently discussed Quantum Terra AG has its HQ in CH even only 3 out of the claimed 80 people are based in CH. It seems companies think that the location-reputation will rub off on the product. Also ProtonMail is another company which until today benefits from having a letter-box presence so they can profit from the "data-center inside the Swiss mountain meme". Security made in <foo> is always a PR stunt. Deutsche Telecom, 1&1 and others tried it by pouring huge sums into an "Email made in Germany" campaign that only benefited a particular consulting company. It utterly failed because their geo-fencing idea was technically unenforcable. CH is more dangerous because the same idiotic ideas brought to Switzerland will often take off. Most EU security companies I know would not easily consider CH as a great location unless it has something to do with business strategy: 1) tax, 2) location of a holding company see #1, or 3) sell into the CH market. On the other hand many non EU based security start-up CEO's often talk about it as it had some security benefit. But as you say this is a huge lie since data protection has nothing to do with banking secrecy and even when the latter is in question a New Mexico LLC is a much more secretive vehicle than a Swiss GmbH/Srl [0] https://de.wikipedia.org/wiki/E-Mail_made_in_Germany https://de.wikipedia.org/wiki/E-Mail_made_in_Germany [1] https://www.telekom.com/en/media/media-information/archive/deutsche-telekom-web-de-and-gmx-launch-e-mail-made-in-germany-initiative-359276 https://www.telekom.com/en/media/media-information/archive/d...
- lawl 6y ago> Security made in <foo> is always a PR stunt. I mean to a degree. There's other talk about some countries wanting to require backdoors in end to end encryption products. If you're in a country that doesn't have that and offer an E2E product, i mean yeah, that can be a selling point. And you should probably point out that your regulated in a country that doesn't require backdoors. But in this case, the laws in Switzerland are frankly just... shit between the mandatory data retention (BÜPF) and DNS censorship under the guise of preventing gambling (Glücksspielgesetz). Yeah, it's a negative for me if my DNS is regulated here.
- bwoodcock 6y agoIt seems like perhaps you haven't actually looked at what the announcement was about? The entire point of the relocation was that the laws you're discussing were found not to apply. https://www.quad9.net/privacy/compliance-and-applicable-law/ https://www.quad9.net/privacy/compliance-and-applicable-law/
- lawl 6y agoThanks, I don't see a link to that from the submitted Press release. I don't think it's fair to ask me if I haven't actually looked when I did in fact read the press release. No, I did not spend extra time to click around, because I simply didn't care that much. In any case I'm glad this doesn't fall under these shit laws (yet).
- sschueller 6y agoProtonMail doesn't even know what the Swiss Flag looks like: https://twitter.com/sschueller/status/1309429286655479808 https://twitter.com/sschueller/status/1309429286655479808 took them for ever to "fix" it (The flag might show the correct cross now but it should be square!).
- Shacklz 6y agoAs a Swiss, I never got the insistence on the square thingie... A lot of Swiss flags that people fly on their poles aren't a square either, and nobody cares. Actually, I'd prefer it if it weren't square, it always gives me this odd-one-out impression in lists of flags
- tssva 6y agoI agree that this announcement is mostly a PR stunt. I find it more likely that the truth is more along the lines that the Quad9 foundation found themselves with a lack of funding from the original founders and SWITCH agreed to provide additional funding but required them to relocate to Switzerland to do so.
- bwoodcock 6y agoNope, SWITCH was engaged after the country decision was made. The country selection process took the better part of five years. SWITCH was engaged in July of 2019. SWITCH has contributed labor, but has put up no money. Quad9 is, as always, a starving non-profit, because when money comes in, it gets spent to provide service, but it's more comfortable now than at any point in the past. So essentially every single assertion in your post is false, no? Did I miss something?
- forks34 6y agoAnd what did protesting do? BND is still helping the NSA, Americans still kill People via Rammstein. Unlawfully that is.
- tgragnato 6y agoNot that anyone in Europe can criticise... Looking at my country, Italians in Sigonella let go much worse, and the US is very proud of it.
- j3th9n 6y agoEven a "9-eyes" country like the Netherlands doesn't have a data retention law in place anymore since 2015. I wonder which one is better then.
- bwoodcock 6y agohttps://www.quad9.net/privacy/compliance-and-applicable-law/ https://www.quad9.net/privacy/compliance-and-applicable-law/
- IdontRememberIt 6y agoIn Switzerland, a policeman investigating a criminal offense (délit penal), can simply request all the data about someone without the need of an explicit Juge order... How is it that great?
- throwaway5033 6y agoNot true, a public prosecutor can, not a police officer. A police officer may request the data on behalf of a public prosecutor. Every canton is organized somewhat differently, so it depends on the canton who does the actual work in the end. The letter often states the case number opened by the public prosecutor. Depending on the organization, the public prosecutor will ask the police in writing what to request.
- deleted 6y ago[deleted]
- IdontRememberIt 6y agoWe also though so. The General Prosecutors of several Cantons politely made us understood that we were wrong (in case of criminal offense). All our competitors provide the data without obstruction. We also now comply.
- herbst 6y agoThats simply wrong
- IdontRememberIt 6y agoUnfortunately. :(
- IdontRememberIt 6y agoHistorically, the data protection law (LPD) was more intended to protect the individual vs the State, than the individual vs private companies. This was due to the Secret files Scandal in 1989 (https://en.wikipedia.org/wiki/Secret_files_scandal https://en.wikipedia.org/wiki/Secret_files_scandal ). Regulators are now working on aligning the aging laws with the European GDPR to better protect individuals against private companies.
- fefe23 6y agoI love the Swiss, I really do, but their reputation has been in tatters since the Crypto AG fiasco. Crypto AG basically sold backdoored crypto hardware to foreign governments, at the behest of CIA and BND (German foreign intelligence agency). It recently came to light that the Swiss knew and let it happen. In fact, the Swiss government also bought machines from them, on a wink wink nudge nudge sort of understanding that they would get the non-compromised ones. Now this company could still be excellent, but that would not be because it is Swiss. I have no reason to distrust their claims. However I would like to point out that they give you censored DNS data, with supposed malware sites being removed. Be aware of this when you use them. Their web site is very up front about it.
- thisiscorrect 6y ago"I love the Swiss, I really do, but their reputation has been in tatters since the Crypto AG fiasco." Crypto AG is certainly an awful event but this seems like an impossible standard to hold a nation of millions to. Which country doesn't have some equivalent scandal?
- joveian 6y agoI agree that wasn't a good way to put it but it might not be entirely irrelevent to mention Crypto AG considering Quad9 is sponsored by the Manhattan DA and City of London Police. https://www.manhattanda.org/our-work/signature-projects/global-cyber-alliance/ https://www.manhattanda.org/our-work/signature-projects/glob...
- bwoodcock 6y agoQuad9 is not sponsored by either the Manhattan DA nor the City of London Police. Both are users of Quad9, neither is a sponsor of Quad9.
- joveian 6y agoGlobal Cyber Alliance is at least listed as a founding organization: https://quad9.net/about/sponsors/ https://quad9.net/about/sponsors/ When you are that closely connected to US and UK government, don't be surprised whan people don't trust you.
- paulcarroty 6y agoGreat news, 'cause I had the issue with their DoT servers several weeks ago - 3-5s latency. Now using Cloudflare. P.S. Another free alternative capable to cut off ads&porn - https://cleanbrowsing.org/ https://cleanbrowsing.org/
- middleclick 6y agoHas the case for Switzerland's strong privacy laws been established and more importantly, has it been tested?
- throwaway9d0291 6y agoI'm not sure what you're asking for specifically. The Swiss data protection act is here [0] and is reasonably comprehensive, especially compared to the US, in which data protection is essentially nonexistent. As for it being tested, I can assure you that it's taken very seriously. One ruling that demonstrates that is [1], in which Switzerland's highest court ruled that an individual's right to privacy has higher precedence than a copyright-owner's right to police copyright infringement. There's also a constitutional right to privacy [2], though the Swiss constitution is a little different to the American one. One notable and enormous hole in Switzerland's record however is the BÜPF [3], which, as I understand it, requires ISPs to log DNS requests, among other things. That shouldn't be relevant here though, so long as Quad9 doesn't become a telecommunications provider. [0]: https://www.fedlex.admin.ch/eli/cc/1993/1945_1945_1945/en https://www.fedlex.admin.ch/eli/cc/1993/1945_1945_1945/en [1]: https://www.swissinfo.ch/eng/privacy-triumphs-in-internet-piracy-test-case/28307028 https://www.swissinfo.ch/eng/privacy-triumphs-in-internet-pi... [2]: https://www.fedlex.admin.ch/eli/cc/1999/404/en#art_13 https://www.fedlex.admin.ch/eli/cc/1999/404/en#art_13 [3]: https://www.fedlex.admin.ch/eli/cc/2018/31/en https://www.fedlex.admin.ch/eli/cc/2018/31/en
- nokya 6y agoWhile famous worldwide, the Swiss data protection law only states what is forbidden and what is permitted. It doesn't include any mention on what happens when you break the rules. It has many "ifs" but not a single "then". It's like a parent threatening a child not to do something in the hope that the child never responds with "or what?" Authorities have issued several advisories against global actors but whether or not they decide to comply is purely based on political agenda. In my opinion, the answer to your question (was the resilience of the Swiss data protection law tested) is no, simply because it can't be tested.
- tumblewit 6y agoI made an open source DoT/DoH app for iOS called PrivateDNS (more lists and turning off on wifi coming soon just submitted for review) that includes Quad9. However from India I get very high latencies accessing some of the DNS (needed for testing my app) especially the adblocking one. NextDNS is good since it has local servers. But otherwise pretty much Google and Cloudflare is the only option that works well with Cloudflare sometimes flaky. At home I can have PiHole + unbound but I would like to have a decent fast adblocking dns while on mobile data (whenever I am outside anyway these days) because wireguard is really high latency for me and my home internet is worse than mobile sometimes.
- gzer0 6y agoHave you considered creating a wireguard tunnel to your home network?
- tumblewit 6y agoWhen i'm on mobile data I can barely get it to send imessage. I have a Pi4 right now on which I plan to install it (diet pi seems to have really easy setup for wire guard since i had trouble on the raspios aarch64 lite image, i think headers were missing) but for now nextdns seems to be okay. NextDNS has their own app for iOS but I sometimes have trouble on that too so i just switch DNS and see what works best. The ISP DNS are definitely worse than anything.
- adamdoran 6y agoYou need to install linux-headers-rpi to build wireguard on Raspberry Pi OS - should be good then.
- tumblewit 6y agoYes actually I tried it last when the raspios 64 beta was just released and didn't have an SSD for the pi (SD cards are really slow). I plan on adding another pi for building and one for DNS so that if the Pi is compiling it won't slow down any DNS queries (which it shouldn't but you never know).
- TZubiri 6y agoWhile I apreciate this from a perspective of neutrality. I think expecting privacy in a DNS is a pathological expectation, like expecting that all communications be encrypted.
- nokya 6y agoFully agree. But hey, we need to start with something...and the sheep wants cheap and easy answers.
- deleted 6y ago[deleted]
- mellamoyo 6y agoQuad9, like most global DNS providers uses anycast to provide redundancy and low latency. My connection to them still terminates in Chicago. If my DNS queries are answered in the US, surely they are under some type of US Gov authority and regulation? I think I agree with others, seems like a publicity stunt with very little real-world impact.
- bwoodcock 6y agoIf your ISP is sending your queries to the US, perhaps you should ask your ISP why they're doing that? Did you read the applicable law section of the privacy policy? And you honestly don't think that's better than US law?
- pupdogg 6y agoBoy, I love their website. It's so fast and snappy when it comes to browsing. A hard to find gem nowadays since most sites are infected with trackers and third-party ad engines.
- deleted 6y ago[deleted]
- post-factum 6y agoLooking at https://dnscrypt.info/public-servers https://dnscrypt.info/public-servers, why quad9 doesn't have both DNSSEC and nofilter at the same time?
- chronogram 6y ago9.9.9.9 is supposed to have a filter against malware, phishing and exploit websites. That’s supposed to be its unique selling point.
- post-factum 6y agoI understand that, but similarly to cloudflare/nextdns they could just provide unfiltered anycast service (with DNSSEC).
- bwoodcock 6y agoBecause that's a combination of features that less than a hundred-thousandth of a percent of users have ever expressed an interest in. And we don't have infinite resources.
- post-factum 6y agoUh, thanks for the efforts and the answer. Anyway, in case you'll consider this feature to be implemented, count my +1 :).
- vinay427 6y agoI'm not sure this will affect my latency here in Zurich. Quad9 is already impressive with a 2ms ping, which is surprisingly a bit faster than Google DNS and a few other major providers from my home.
- bwoodcock 6y agoWe did just turn up a third Zurich location two weeks ago, in Equinix ZRH4, so our presence there is pretty robust; on par with New York, London, Singapore, San Jose, and Los Angeles.
- teloli 6y agoThe point is not if Switzerland is better than the US or Saudi Arabia. What is crucial is sovereignty: giving away all EU dns requests to the US by using google public dns or cloudflare is a huge loss of sovereignty for EU countries. The American government would never accept, say, if Chrome were to send American DNS queries to a non-US entity by default. EU countries shouldn’t accept that either.
- albertgoeswoof 6y agoSwitzerland isn’t in the EU
- teloli 6y agoWhen it comes to geopolitical spheres of influence, which is what digital sovereignty is about, it doesn’t matter. Switzerland is part of Schengen, the European single market, the EFTA, ... It’s Europe.
- WarOnPrivacy 6y agoI'd like to thank Quad9 for being an adversary to bad actors, like my government.
- throwaway5033 6y agoWhat some people may underestimate is the hands-off approach by the Swiss authorities. In short, in Switzerland you don't land in jail if you don't kill someone or do a bank robbery. If you don't have the data, you don't have it. I prefer to deal with the Swiss authorities than with the German authorities (which take things much more serious). And Crypto AG was founded by a foreigner who was not even trusted by the Swiss military. Do you really think that in a small town like Baar CIA and BND agents visit and nobody knows who the company belongs to? In serious, you must have watched too many James Bond movies. Yes, what is not ok that nobody stepped in from the military intelligence and kicked them out.
- herbst 6y agoThis ive used and abused the swiss flag for my projekts before. Mainly to underline the fact that i do not log and cant easily be forced to. No GDPR conformity but that sweet privacy
- p1mrx 6y agoDid they get a short IPv6 prefix (2620:fe::/48) by chance, or did they have to pull strings at ARIN? In any case, Sprint (2600::/29), Vodafone (2a00::/22), and Korea Telecom (2400::/20) are currently winning that game.
- bwoodcock 6y agoNot by chance, no, had to wait for a new block to open, and apply at the beginning of allocation of the new block.