7 ms·
Cloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error mess
by gsa 5y ago
Cloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error message. I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away.
[0] https://community.spotify.com/t5/Desktop-Windows/Random-Stopping-with-CloudFlare-DNS-1-1-1-1/td-p/5190900 https://community.spotify.com/t5/Desktop-Windows/Random-Stop...
- nobody9999 5y ago>I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. Since you're already using a pi-hole, why not just roll your own recursive DNS server. The additional network traffic to do so is insignificant. That way, you don't have to rely on someone else to resolve your DNS queries -- or deal with spats like that. I've been meaning to do so for a while, but life has interrupted. As I'm going through an ISP change ATM, I will do so soon. And I won't ever look back. Edit: Since your post got me thinking about it, I just now went ahead and set up my recursive resolver and pointed my pi-hole at it. Took about 10 minutes on an existing VM.
- zrobotics 5y agoEh, not the GP but I had tried that and switched back to 1.1.1.1 with hosts rules for specific sites to fallback to 8.8.8.8. Running my own DNS just proved to be too much of a troubleshooting headache, since if a site was broken it was one additional step. The pihole itself has been almost no trouble, but the diy DNS would occasionally fail to resolve a site. If I'm at home, the last thing I really want to do in the evening is troubleshoot network issues. It was a fun project to setup, and I did learn more than I expected I would. I can recommend it as a weekend project, but not as a long-term solution.
- nobody9999 5y ago>Running my own DNS just proved to be too much of a troubleshooting headache, since if a site was broken it was one additional step. The pihole itself has been almost no trouble, but the diy DNS would occasionally fail to resolve a site. If I'm at home, the last thing I really want to do in the evening is troubleshoot network issues. A fair point. That said, note the edit on the comment to which you replied. I've been running my own authoritative DNS for (personal) domains I own for 15 years or so and have spent very little time managing that. I also run my own internal DNS servers (hybrid BIND/AD DNS) without issue. As such, I don't expect to have many issues with a simple recursive resolver. That said, I understand your point of view and know that managing DNS isn't for everyone. However, I'd rather perform my own DNS lookups rather than relying on my ISP(s), Google or Cloudflare. Yes, my ISP could capture every single recursive query, but I'd rather have them do that than just log every DNS query I make. No, it doesn't significantly add to my privacy, but (IMHO) it's better than the alternative.
- icedchai 5y agoI also run my own DNS servers, both internal caching resolvers and external authoritative, and and have done so since 1996. I run BIND. It takes almost zero maintenance. DNS is one of the easiest services to operate.
- Brybry 5y agoI use Pi-Hole + Unbound forwarding to Cloudflare/Quad9 over TLS. It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.
- nobody9999 5y ago>It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. I love DNSSEC, but am not in favor of DoH/DoT. Mostly because I can't control DoH/DoT requests emanating from my network, as they're already encrypted and can't be differentiated from standard HTTPS traffic. That's an issue (and will become a much bigger one as time passes) because vendors can use DoH/DoT to bypass local DNS controls like Pi-Hole, and short of blocking TCP/443, there's nothing you can do about it. Which is, IMNSHO, a big reason why DoT/DoH was developed. >Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled. Your ISP can surveil whatever they want and there isn't much you can do about it unless you use a VPN.
- Forbo 5y agoIf you can't control where your device is making DNS requests then it's not your device. It's the manufacturer's surveillance capitalist revenue generator. We need more devices that actually respect the user.
- Brybry 5y agoI don't think my ISP can easily intercept the content of DoT DNS requests. They would need a valid certificate for 1.1.1.1#cloudflare-dns.com or 9.9.9.9#dns.quad9.net from a trusted (by me) CA, correct? Now obviously that's not impossible but is a VPN any better in that scenario?
- 5y ago