3 ms·
As an EU citizen, I'm happy that we're starting to have more infra and are less reliant on countries outside of EU. However, I'm skeptical of their "privacy-foc
by zerof1l 1y ago
As an EU citizen, I'm happy that we're starting to have more infra and are less reliant on countries outside of EU. However, I'm skeptical of their "privacy-focused" slogan. Most likely they mean that your data won't leave EU. However, EU itself does a lot of tracking and blocking.
The only true private DNS server is the one you own. It should be a recursive DNS server configured with DNS root zone and DNSSEC. So it would first contact one of the root DNS servers (obtained from ICANN), validate the authenticity of the response ensure it is not tampered with using DNSSEC, and then proceed to call the next server in the chain until the query is fully resolved. Such DNS server would bypass all censorships.
Also nice is that more and more root servers already support DoT meaning that the request and response would be encrypted preventing intermediaries like your ISP from seeing the data.
As a last resort, your DNS server can be hosted outside of the country on a server and then you'd connect to it over DoT or DoH.
- whatevaa 1y agoIf you are the only one connecting to that server, there is no privacy here, you can be easily traced.
- immibis 1y ago[flagged]
- immibis 1y agoFlagged comment said: Depends if you bought your server with Bitcoin. (In which case, remember that your server host will be raided by the gestapo, so make sure you have adequate redundancy) I suppose I have to elaborate to not get it deleted by moderators. If you bought a server with sufficiently anonymized bitcoins, your connections can be traced to the server but they don't know whose server it is. However, hosting providers that allow people to buy servers with sufficiently anonymized bitcoins tend to be raided by the gestapo because of the other kinds of things that some people like to run on servers bought with sufficiently anonymized bitcoins. So you should have redundancy in place.
- tptacek 1y agoDNSSEC does nothing to prevent DNS censorship, besides maybe, in some rare cases (given how little of the domain space is signed) telling you that it's happening.