6 ms·
I do not understand why more people don't switch to a decentralized DNS such as OpenNIC (https://www.opennic.org https://www.opennic.org) Governments have abus
by anonymousisme 5y ago
I do not understand why more people don't switch to a decentralized DNS such as OpenNIC (https://www.opennic.org https://www.opennic.org)
Governments have abused their control of DNS. A distributed system (with trust and safeguards) is the better way.
- gizdan 5y agoBecause no one knows about it. But also, looking at their list of servers, the majority is offline. Assuming this is because any person can run one, it's probably the reason. On top of the above, the likes of Google are enforcing their DNS servers. For example, I run AdGuard Home with it's DHCP functionality. I am unable to rely on the DHCP settings on my Android phone because Google forces the first DNS server to be 8.8.8.8 with (as far as I can tell) no way to disable this. I think at least for the foreseeable future the solution is to run Unbound and stop relying on DNS resolvers combined with a firewall that redirects all DNS records AdGuard Home/PiHole. This is obviously not a solution to the general public.
- ryuuchin 5y agoI can't speak to Google forcing DNS, I don't know if this is true. However, it will respect the private DNS option (DNS-over-TLS) which you can point to whatever you want (like NextDNS for filtering).
- anonymousisme 5y agoLots of tech giants are forcing DoH so their apps can phone home despite safeguards such as pi-hole. There's not a lot that you can do about that (if they are using certificate pinning, which they probably are). You can however do something about 8.8.8.8 (and 8.8.4.4). Just put a static route in your firewall that points those to your DNS of choice (or to a black hole).
- gizdan 5y agoI'm still in the stages of setting up a fullt featured firewall at home, but I wonder what would happen if you block doh/dot addresses completely in such cases. Something to try in the future when I have my home network set up properly I guess.
- KozmoNau7 5y agoYou can block all outgoing requests to ports 53 and 853 for DNS and DoT respectively. That's the easy part. For DoH, you either have to block port 443 (bad idea), or block the IPs of all known DoH providers. Then you can run for example a Pi-Hole and add a firewall rule to allow outgoing DNS traffic only for that. And of course that will not stop device/app makers from using nonstandard ports or even tunnelling their DNS traffic through other protocols.
- sofixa 5y ago> I am unable to rely on the DHCP settings on my Android phone because Google forces the first DNS server to be 8.8.8.8 with (as far as I can tell) no way to disable this. Which Android version and skin? I'm on an Android 10, MIUI12 device and the DHCP-provided DNS server is the one used ( AdGuard successfully blocks ads on websites, apps when on my phone, until i disable it).
- zamadatix 5y agoIf everyone used OpenNIC what would be different about this case?
- anonymousisme 5y agoWhat would be different is that an individual or organization running a OpenNIC DNS would not necessarily be subject to a court order from Germany. There's not much that can be done when governments fiddle with the root DNS servers, but methods could be developed to retain historical records, and revert to them in the event of censorship.
- amoshi 5y agoHow was your experience with them? Mine wasn't too great a few years ago - I switched, everything was great, had that nice fuzzy feeling inside that I'm using a pro-freedom/anti-censorship DNS, until a couple of months later when the DNS server just stopped responding. Surely I must've simply been unlucky I thought, so I switched to another instance but the same thing happened a few months later. I love the idea in principle but it didn't seem to work for me in reality.
- duskwuff 5y agoOpenNIC isn't "decentralized" or "distributed" in any meaningful sense. It's the same architecture as ICANN DNS circa 2000, but run by hobbyists. (And in practice, it's mostly hosted on cheap cloud servers. No anycast IPs, no load balancing -- just few enough users that they haven't had to deal with any serious scaling issues yet.)