5 ms·
Is there a way to use OpenDNS from any location and permanently opt out of their NXDOMAIN hijacking? I know you can configure it from their website but you can
by sixcorners 15y ago
Is there a way to use OpenDNS from any location and permanently opt out of their NXDOMAIN hijacking? I know you can configure it from their website but you can only control your own domains so it doesn't work when you access a wifi hub. You also have to run that daemon all the time which seems like a slightly bigger privacy concern.
> We don’t persist logs for our users without accounts and configured networks, I’m not sure Google makes the same statement.
Does that mean that both my DNS requests AND my HTTP requests to whatever webserver is intercepting my requests to test.invalid (http://guide.a.id.opendns.com/?url=test.invalid http://guide.a.id.opendns.com/?url=test.invalid) are not being logged? Does that mean my requests on wifi hubs that are configured with OpenDNS are being logged?
What does it mean to discourage automated DNS lookups? What else do I use it for? dig?
Couldn't one argue that it is a good idea to keep the number of companies that have access to your information low? From that perspective wouldn't it be prudent to use Google for everything?
- sirn 15y ago> We don’t persist logs for our users without accounts and configured networks, I’m not sure Google makes the same statement. I think the main point here is persist; OpenDNS probably logs all your requests but they will discard it after x days.
- pbhjpbhj 15y ago>NXDOMAIN hijacking // You and waffle_ss both mention this, can you expand on what problem you're facing. I use OpenDNS because of the filtering abilities and because I found on test that they were marginally faster for me than Google. Next to never do I see their domain redirect page and whenever I have it's always had the domain I've been after at the top of the page - for example, http://guide.opendns.com/?url=ycambinator.com http://guide.opendns.com/?url=ycambinator.com. Yes it has a couple of text-ads but for the 2-3s you're on the page I can't see that I really have any problem with this at all ... it's way less intrusive than the ads on most websites now. So what's the issue? Is it really akin to being robbed at gunpoint?
- chc 15y agoYou seem to be taking offense to something that wasn't said. The term "hijacking" is used here in much the same sense as "signal hijacking" or the program Audio Hijack. The relevant part of the "hijack" imagery is forcibly taking over the way a transport. It essentially means they are causing DNS requests to return against-spec responses.
- pbhjpbhj 15y agoHyperbole blah-blah-blah. >they are causing DNS requests to return against-spec responses // That's part of their service. If there was no way to switch it off then I can understand being annoyed but you can just choose to use your ISP's DNS. It just appeared to me that both comments concerning this were of the form "ZOMG they has borken my internetz"; could be I read the tone wrong. So anyway, for the service that OpenDNS are offering is it wrong of them to simplify the situation for users making mistakes entering domain names in their browser?
- chc 15y agoI think "wrong" is a good word for it. Users typing things into an address field in a Web browser is not the only use case for DNS, but this breaks DNS for the whole system, which is the wrong solution. Correcting mistakes in the address field is something browsers should take care of. Firefox and Chrome both do — I know Safari doesn't, and I can't remember what IE does. In fact, Chrome has to employ a rather ugly hack to work around this behavior from noncompliant DNS servers.
- pbhjpbhj 15y ago>not the only use case for DNS // Of course. But I think that's exclusively the use case that OpenDNS target in their consideration of non-resolving domains.
- sixcorners 15y agoIt's really just a quirk that I would rather not deal with. If I run dig on a hostname, that means I want to know about whatever records are associated with that hostname. If I try to get a program to connect to an invalid hostname I want it to say that's the problem instead of waiting a minute or two for the connection attempt to time out. It's also kind of backwards. If I want that kind of functionality, shouldn't that be in the browser? Hmm.. minor correction.. It seems that, with OpenDNS, test.invalid returns NXDOMAIN, test.invali gives me 67.215.65.132. Oh well. When I made that other post I assumed they would be the same.