46 ms·
Ask HN: Neutral DNS servers?
Hi HN - Here’s a question that I hope will generate some useful comments, suggestions and links.
Background for question: I normally run an internal DNS resolver with an upstream pool of 10-15 providers. These are normally a mix of Global Anycast servers (Quad9 etc) with some OpenNIC, YandexDNS etc thrown in towards the end to cover the ‘chilling effects’ blackholes.
Currently Yandex DNS is pinging a timeout (either due to black-holing or DDOS’ing depending on where I connect To/From).
My question to HN is this – Given my ‘Information Wants To Be Free’ viewpoint, are there any DNS equivalents of Switzerland (WWII, Neutral to all parties) providers?
- neilalexander 5y agoYou could just run a recursive resolver yourself by using the root hints. You don't need to delegate your DNS queries onto a third-party resolver like Quad9. https://www.iana.org/domains/root/files https://www.iana.org/domains/root/files
- NotAWorkNick 5y agoThanks for that, appreciated. I'll be honest- I'm just a 'little guy' in the food chain so I always figured that doing something like that was for the ISP level folks <edit to clarify, I mean connecting to a Zone 1 Resolver. I wasn't aware that one could download the Root Hints File directly (Thanks!). One quick question though - After taking a quick skim of it the list seems to be extremely 'Western-Centric' (reference link https://www.internic.net/domain/named.root https://www.internic.net/domain/named.root)
- icedchai 5y agoThe root servers are anycasted. Each one of those root server IPs corresponds to N physical servers at diverse networks / locations all over the world.
- tylersmith 5y agoThe canonical DNS system itself is extremely Western-Centric.
- kfrzcode 5y agoAs are many Western inventions
- contingencies 5y agoDNS[0] is only a decentralized hierarchy with caching, a class of system which pre-dates the digital era as the de-facto means of political and military organization in any human society larger than a village or town. DNS as a directory system for IP is could itself be viewed as a direct philosophical descendant of military insignia (perhaps via the then-popular branch-tangent of the telephone book, itself ex-telegraph, and postal system) and these could all be in effect traced back to at least Roman society[1], I don't think arguing this is a "western" invention is very convincing or useful. Any ancient army or polity of any size would have had an equivalent, which would then include ancient Egypt, China[2], India, Mesopotamia[3], Mesoamerica, etc. Actually, come to think of it, the comparative study of ancient postal systems would be pretty interesting.[4] [0] Original DNS RFC1035 https://datatracker.ietf.org/doc/html/rfc1035 https://datatracker.ietf.org/doc/html/rfc1035 (1987) [1] Somewhat cheekily as the inventor of DNS has a Greek surname. https://en.wikipedia.org/wiki/Paul_Mockapetris https://en.wikipedia.org/wiki/Paul_Mockapetris [2] 2000+ years ago and mature enough to have QoS+max-TTL/hop: http://libgen.rs/scimag/10.1163%2F9789004292123 http://libgen.rs/scimag/10.1163%2F9789004292123 (pp17-48) + where I write this. [3] Evidenced to 9th century BC https://www.ucl.ac.uk/sargon/essentials/governors/thekingsroad/ https://www.ucl.ac.uk/sargon/essentials/governors/thekingsro... [4] Start by fixing https://en.wikipedia.org/wiki/Timeline_of_postal_history https://en.wikipedia.org/wiki/Timeline_of_postal_history
- kortilla 5y agoBy that same token the internet was invented by the first person to hand gesture to another one. You can’t dilute DNS down to a directory because there were/and are already other directory protocols.
- qeternity 5y agoWalking gets you from A to B just like a car, so actually the first bipeds really invented the automobile.
- aaomidi 5y agoThey are western centric, and unfortunately, in this current state of the web they're still essentially the authority on DNS. Alternatively, you can maintain the NSes for all the TLDs you are particularly interested in, and alert yourself if they change to something you don't recognize. Finally, keep in mind that whatever you do, you need to have multiple vantage points to the internet. There's not a lot stopping your ISP from not delivering you to the right host when you try to talk to it. E.g. your ISP can fake the DNS responses.
- endymi0n 5y ago> They are western centric, and unfortunately, in this current state of the web they're still essentially the authority on DNS. I‘m curious to see your evidence on that or which future state you would see as a more fortunate one.
- jka 5y agoQuestioning why the distributed cluster runs on nodes 'a' and 'b' alone doesn't necessarily imply that nodes 'c', 'd' and 'e' are any better or worse, today or in future.
- aaomidi 5y agoIf I knew the answer to this I would be very rich and probably have my name on multiple textbooks of solving decentralized computing problems.
- lapinot 5y ago> I'm just a 'little guy' in the food chain so I always figured that doing something like that was for the ISP level folks A lot of people are running recursive resolvers at home (like pi-hole stuff, or most people running some custom openwrt router/modem). I'm running one on my laptop (my resolver is localhost) and it works great. > After taking a quick skim of it the list seems to be extremely 'Western-Centric' It is, but that's what the internet is. But by running your own recursive resolver you can control your cache and a lot of the data doesn't change often. If you're extra paranoid you can cache the record data (or even archive the history) for ccTLD (or even all TLDs). For stuff (domains) you're interested in you can also hard-code or otherwise program "non-standard" ways to resolve the ips (by somehow populating a local database that overrides recursive resolution), like pi-hole/safebrowsing blocklists, stuff from institutions or CDNs you trust.
- DavideNL 5y agoAlthough querying the root servers directly is always unencrypted right? So your ISP can see and might manipulate all queries at will?
- CaliforniaKarl 5y agoIn addition to the root hints, you should also download the DNSSEC anchor key (available on the same site as the root hints). That will let you detect manipulations of records that are DNSSEC-signed. Otherwise, you could spin up your recursive resolver on your cloud, VPS, or other hosting provider of choice, and then use that.
- Arnavion 5y agoRight, DNSSEC will solve the "manipulate" problem, but it won't solve the "see" problem. But whether that's a concern is up to you. You could run your resolver on a VPS and speak DoT / DoH to that, which shifts the leak from your ISP to your VPS provider.
- tptacek 5y agoIt doesn't solve the "manipulate" problem we're talking about here, either: nothing about DNSSEC prevents a DNS server (or middlebox) from denying results to a disfavored domain; it only (situationally) prevents them from redirecting it somewhere else. (And, of course, it only works if you're running your own recursive server; it does nothing whatsoever in the 8.8.8.8-type use case).
- schleck8 5y agoControlD, DNS.sb and LibreDNS for instance. The latter two are open source. I think non-disciminating DNS providers are rather the norm and not an exception though.
- NotAWorkNick 5y agoReally? Then your experience differs greatly from mine (EU based). My usual mix of 'fastest anycast' upstreams’ are reliably black-holing a lot of .ru domains right now (Rightly or wrongly is a ‘nother question for a ‘nother day). P.S, YMMV and obviously does :)
- ev1 5y agoAre you sure it's not Runet dropping traffic incoming?
- tambeb 5y agoCould you give a couple of examples of the black holing you've seen?
- ajsnigrutin 5y agoIn slovenia, at least these two are blocked at the DNS level: https://www.rt.com/ https://www.rt.com/ https://sputniknews.com/ https://sputniknews.com/
- ajsnigrutin 5y agoInterestingly enough, the 'academic network' (arnes) that covers schools etc., and also some government entities is not blocking it, but atleast two out of the three largest commercial ISP are (can't test the third, since it's locked to their customers' IPs only).
- schleck8 5y agoBecause the russian media mafia (tacc, rt, sputnik and the like, which are all either directly state-owned or via the state-owned tv novosti) are about to be banned in all EU countries where they are still available, and the ISPs might have banned them pro-actively.
- celsoazevedo 5y agoIf you already run your own DNS resolver, query the root servers directly. No need to trust DNS providers when you can do the same thing yourself.
- walrus01 5y agobased on the OP's description of yandex and what I presume to be their location it's not impossible that some time in the future unencrypted 53/udp traffic leaving and entering the country may be blocked or messed with
- celsoazevedo 5y agoIn that case maybe something like DNSCrypt[0] and a 3rd party provider makes sense. On top of the encrypted connection, DNSCrypt has the option to proxy queries to improve privacy. This only helps if they're not doing any advanced blocking though. If I remember correctly, when Russia blocked Telegram, they were blocking their IPs, not just DNS queries. If the rumours of a "RuNet" are true, then they probably need something more advanced (eg: a VPN with traffic obfuscation, Tor, etc). --- [0] https://github.com/DNSCrypt/dnscrypt-proxy https://github.com/DNSCrypt/dnscrypt-proxy
- antipooting 5y ago
- nfriedly 5y agoI know this isn't quite what your asking for, but one idea is to set up a Pi-hole + unbound: https://docs.pi-hole.net/guides/dns/unbound/ https://docs.pi-hole.net/guides/dns/unbound/ Unbound is basically your own private DNS resolver and then Pi-hole lets you filter out whatever "junk" you don't want.
- drexlspivey 5y agoUnbound will also pre-fetch your most common lookups prior to the TTL expiring so it's probably even faster than querying a third-party resolver
- egamirorrim 5y agoI don't know if it's an obvious question or not, but how does performance compare with your own unbound vs quad1/8/9? I imagine it's slower in general?
- nfriedly 5y agoI'm not personally running unbound, just a Pi-hole that up-stream's to my ISP's DNS, so I can't answer you from first-hand experience. But, according to drexlspivey, unbound will pre-fetch common queries, so it probably ends up being faster on average - https://news.ycombinator.com/item?id=30646020 https://news.ycombinator.com/item?id=30646020
- lapinot 5y agoI never measured anything, but i'm running a recursive resolver on my laptop since a couple years (knot resolver) and never had any performance problem.
- justsomehnguy 5y agohttps://news.ycombinator.com/item?id=30649709 https://news.ycombinator.com/item?id=30649709
- khimaros 5y agofor anyone running OpenWRT, unbound + adblock works well and is trivially configurable via the LUCI web interface.
- nobody9999 5y ago>My question to HN is this – Given my ‘Information Wants To Be Free’ viewpoint, are there any DNS equivalents of Switzerland (WWII, Neutral to all parties) providers? Presumably the root and authoritative servers. Which is why I use a local recursive resolver rather than any upstream/third party resolvers. You should try it. It's easy and fun!
- jiveturkey 5y agohuh. Why aren't you simply querying the roots and from there the SOA for any domain?
- vetinari 5y agoIt is very easy to hijaack port 53 traffic, so you might not talk to DNS server you think you do. Heck, I did that at home for Chromecast and other devices that hardcode their DNS.
- btdmaster 5y agohttps://www.opennic.org/ https://www.opennic.org/ and downstream providers from there are quite good: https://servers.opennic.org/ https://servers.opennic.org/
- hansel_der 5y agonote that opennic provides an alternative dns-root, inlcudes new/fun/special tld's, and is hence considered more of an excentric option. ymmv
- kseistrup 5y agoYou could try Uncensored DNS: https://blog.uncensoreddns.org/ https://blog.uncensoreddns.org/
- kseistrup 5y agoSee also Public DNS Server by Country: https://dnschecker.org/public-dns https://dnschecker.org/public-dns
- c0l0 5y agoI run and use https://resolv.us.to/ https://resolv.us.to/ - you may do the latter, too.
- yegor 5y agoShameless self promotion: Try Control D - https://controld.com/free-dns https://controld.com/free-dns There are many different types of resolvers, blocking and unfiltered. We're adding global ECH support in the coming weeks. There is also a paid plan if you need more control.
- stranded22 5y agoPersonally, I use nextdns on a paid plan (£17/year). Full control, can change to no logs, or logs stored in Switzerland. They have a free plan too
- rsync 5y agoI do this. I have my own resolver on my own server running unbound and it gets service from my paid nextdns account. Sort of like having a pihole but it is available from anywhere and I don’t have to run a rpi…
- irq 5y agoThis setup is intriguing. I'm curious, is there any latency penalty going this way vs using your own pihole + 1.1.1.1 or 8.8.8.8 instead of nextdns?
- deleted 5y ago[deleted]
- hansel_der 5y agoso your unbound instance is doing caching, mixing and stipping edns before forwarding the queries to nextdns resolvers?
- upnick 5y agoYou might want to look up "geo-politically stable" web hosting. Aside from that, Epik.com has traditionally been quite supportive of free speech (even if it's Trump supporters).
- nmjohn 5y agoGiven you only mention censorship/chilling effect and not privacy - why isn't 8.8.8.8 sufficient? Have there been instances of domains it censored and stopped resolving that I'm not aware of? I guess I'm confused on the benefit (theoretical or practical) one would get by using that variety of resolvers. Is it just to prevent theoretical censorship at the DNS level?
- charcircuit 5y agoSame with 1.1.1.1 (the case where archive.is used to not work was archive.is's nameserver purposefully being configured to return bad results to 1.1.1.1)
- tambeb 5y agoMy question exactly. In another comment here I asked for some examples for the claim that some .ru domains were being black holed.
- nimbius 5y agoGoogle DNS should at this point be considered harmful. Devs love to hardcode it in resolvd because 'user experience' but there's ample evidence its just analytics. Quad 1 cloudflare is reliable doh but comes from a company with a history of bloviating nonsense about internet freedom only to eagerly capitulate to Twitter lynchmobs and blacklist a customer or ten. https://dnscrypt.info/public-servers/ https://dnscrypt.info/public-servers/ will give you a nice list of doh to try out. Ymmv however as many are sporadic.
- aaomidi 5y agoI know what you're referring to (systemd-resolved "defaulting" to Google DNS). That "default" is a compile-time value, if you use something like gentoo you get to be in full control of what that default value is.
- cyounkins 5y agoCan you point to the evidence that Google DNS is used for analytics?
- nimbius 5y agohttps://en.m.wikipedia.org/wiki/Google_Public_DNS https://en.m.wikipedia.org/wiki/Google_Public_DNS Google stated that for the purposes of performance and security, the querying IP address will be deleted after 24–48 hours, but Internet service provider (ISP) and location information are stored permanently on their servers.
- amarshall 5y agoMore specific details on logging: https://developers.google.com/speed/public-dns/privacy https://developers.google.com/speed/public-dns/privacy
- b112 5y agoAnother person responded with info, but at this point, shouldn't we assume every single thing Google does, is for analytics? At this point, the onus is to prove thing $x is not used for Google analytics.
- nix23 5y ago>Given my ‘Information Wants To Be Free’ viewpoint, are there any DNS equivalents of Switzerland That's exactly why Quad9 changed it's HQ to Switzerland: https://www.switch.ch/news/quad9-moves-to-Switzerland/ https://www.switch.ch/news/quad9-moves-to-Switzerland/
- sp332 5y agoQuad9's default 9.9.9.9 address blocks malware, but the alternate 9.9.9.10 does not. https://www.quad9.net/service/service-addresses-and-features https://www.quad9.net/service/service-addresses-and-features
- moltke 5y agoThe DNS (as it exists today) is supposed to be the equivalent of Switzerland. The internet community has said over and over again they're not interested in censoring the internet or removing any group of people from it. It sounds like what you really want is your own recursive resolver.
- BrandoElFollito 5y agoQuestion after reading (very interesting) answers: what is the downsize using the root servers instead of the well-known ones? (1.1.1.1, 8.8.8.8, ...) Is it the cache that improves resolution speed in a meaningful way?
- cyounkins 5y agoThey are used in different ways - search for recursive resolver vs caching public resolver. Running your own recursive resolver will almost certainly be slower, on the order of 2x latency. I should test it... Also, DNS-over-HTTP and DNS-over-TLS are not available with all DNS servers, but can be readily enabled to secure the last mile when the upstream public resolver supports it.
- loxias 5y agoIt's really not that hard to just run your own DNS server locally. Then you're not beholden to anyone. I recommend it.
- pabs3 5y agoI just do this to get a neutral DNSSEC supporting recursive DNS resolver: apt install unbound
- matoro 5y agoI use dnscrypt-proxy[0] which round-robins to a bunch of upstream servers, plus encryption. [0] https://github.com/DNSCrypt/dnscrypt-proxy https://github.com/DNSCrypt/dnscrypt-proxy
- snovv_crash 5y agoYou could try using a DNS provider that's actually in Switzerland...
- mike_d 5y ago103.196.38.3 103.196.38.8 Globally anycasted plain vanilla name resolution. I don't publicize it because I don't have anything to gain from more users, but you are free to use them.
- hansel_der 5y ago> I don't publicize it but you did ... thx anyway :)
- axiosgunnar 5y agoNote that even Switzerland could not stay neutral this time and enacted severe sanctions against Russia. Maybe staying neutral has the higher cost to a free society (and thus „information wanting to be free“) in the long term?
- amitbakhru 5y ago1.1.1.1 1.0.0.1
- hansel_der 5y agosquatting on someone elses couch is generally not considered 'making a home for oneself'