5 ms·
So choose a different one. You don't have to use your ISP's. The danger is in everyone using the same one, which is what you get if the browser vendors are choo
by zrm 5y ago
So choose a different one. You don't have to use your ISP's. The danger is in everyone using the same one, which is what you get if the browser vendors are choosing for everyone.
Better yet, give the browsers a way to detect this (e.g. generate a random domain known not to exist and make sure it gives NXDOMAIN) and switch to the other DNS only if the normal one is broken.
- ev1 5y agoYou don't get this choice in most of the US.
- L3viathan 5y agoYou don't have the choice of DNS server in most of the US?
- josephcsible 5y agoNot without DoH. If you just try to set a custom server to use for insecure DNS, it's trivial for your ISP to rewrite all of your insecure DNS queries to go to itself instead.
- vasachi 5y agoIt is actually really easy to ignore user's selected DNS server. Basically ISP can just inject responses, given that DNS is unauthenticated. I don't know if US ISPs do that, but it can be done.
- ev1 5y agoI know that both T-Mobile and Comcast have both ignored user selected non-DoH DNS settings by force in the past, either by DPIing port 53 traffic or static routing major public DNS servers toward their own resolvers.
- gsich 5y agoSo, do they still do it? This fearmongering about DNS selling pops up in every DNS thread here.
- 542458 5y agoI don’t really understand this perspective. “Sure, I’m using vulnerable technology, but nobody has exploited me lately that I know of” isn’t a statement that would get positive reception in any other netsec discussion.
- autoexec 5y agoyeah... it's not fear mongering when it's a thing that actually happens. Some ISPs collect and sell your data. I mean, they even paid congress to make it okay for them to do it. They sure can't be expected to keep their word https://arstechnica.com/tech-policy/2019/01/t-mobile-sprint-and-att-still-selling-your-location-data-report-says/ https://arstechnica.com/tech-policy/2019/01/t-mobile-sprint-...
- hulitu 5y agoAnd you really believe that "every ISP" sells your data, only Cloudfare is not doing it ? You know, Apple was a "privacy oriented company" until some years ago.
- eli 5y agoCloudflare promises that they don't in a legally binding document. Does your ISP do the same?
- autoexec 5y agoWell... I said "some ISPs" sell your data, not "every ISP", but I wouldn't put it past any of them. Personally, I don't trust cloudflare, I don't like efforts to kill ad-blocking, and I don't like further consolidating people's DNS traffic into the hands of a smaller and smaller number of providers. I've got the feature disabled for now. I wish someone like EFF would set up a DNS server supporting DoT. I'd pay for the service!
- leguminous 5y agoI used to have Spectrum "community wifi" (their service for apartment buildings). They were doing this as of last year. They even spoofed responses from root servers, which utterly broke things like `dig +trace`.
- dspillett 5y agoCapturing and redirecting DNS traffic is not difficult. You can do it yourself to force smart devices with hard-coded DNS settings to go via a local resolver that filters ads/stalking, so I have no doubt there are ISPs doing it to their customers to keep control for the purposes of tracking and NXDOMAIN hijacking.
- SparkyMcUnicorn 5y agoFor anyone looking for a quick and easy solution via NextDNS: https://github.com/nextdns/nextdns/wiki https://github.com/nextdns/nextdns/wiki I have it installed a few different places on a few networks (Ubiquity, DDWRT, OPNSense, DNSMasq), and it works as expected.
- eli 5y ago1) Literally yes in some cases, as others have pointed out. 2) I thought we were just talking about defaults? Firefox DoH lets you choose any server too
- clsec 5y agoNo, you don't. I have only one choice of ISP, Comcast. Comcast sniffs all DNS traffic to this day. Their DNS is hard-coded into their routers. I know they sniff because I have gotten DMCA notices while using a VPN. I had to spend quite some time setting things up to my VPN provider's recommendations to be able to use their DNS. I haven't received a DCMA notice since. And yes, I know a cheap router can easily fix this problem. I just haven't had the time..