7 ms·
I think normally you pair 1.1.1.1 with 1.0.0.1 and, if I understand this correctly, both were down.
by Gieron 1y ago
I think normally you pair 1.1.1.1 with 1.0.0.1 and, if I understand this correctly, both were down.
- moontear 1y agoJust pair 1.1.1.1 with 9.9.9.9 (Quad9) so you have fault tolerance in terms of provider as well.
- rvnx 1y agoQuad9 is reselling the traffic logs, so it means if you connect to secret hosts (like for your work), they will be leaked
- Demiurge 1y agoIs this true? They claim that they don't keep any logs. Do you have a source?
- jeffbee 1y agoThey don't claim that. Less than a week ago HN discussed their top resolved domains report. Such a report implies they have logs.
- Demiurge 1y agoFrom their homepage: > How Quad9 protects your privacy? > When your devices use Quad9 normally, no data containing your IP address is ever logged in any Quad9 system. Of course they have some kinds of logs. Aggregating resolved domains without logging client IPs is not what the implication of "Quad9 is reselling the traffic logs" seems to be.
- jeffbee 1y agoWe're not discussing IP addresses, we are discussing whether their logs can leak your secret domain name.
- Demiurge 1y agoThats more clear, I get your point now. Again, though, that's not how most people would read the original comment. I've never even contemplated that I might generate some hostnames existence of which might be considered sensitive. It seems like a terrible idea to begin with, as I'm sure there are other avenues for those "secret" domains to be leaked. Perhaps name your secret VMs vm1, vm2, ..., instead of <your root password>. But yeah, this is not my area of expertise, nor a concern for the vast majority of internet users who want more privacy than their ISP will provide. I am curious though, do you have any suggestions for alternative DNS that is better?
- jeffbee 1y agoI use Google DNS because I feel it suits my personal theory of privacy threats. Among the various public DNS resolver services, I feel that they have the best technical defenses agains insider snooping and outside hackers infiltrating their systems, and I am unperturbed about their permanent logs. I also don't care about Quad9's logs, except to the extent that it seems inconsistent with the privacy story they are selling. I used Quad9 as my resolver of last resort in my config. I doubt any queries actually go there in practice.
- daneel_w 1y agoCould you show a citation? Your statement completely opposes Quad9's official information as published on quad9.net, and what's more it doesn't align at all with Bill Woodcock's known advocacy for privacy.
- gruez 1y agoSee: https://quad9.net/privacy/policy/ https://quad9.net/privacy/policy/ It doesn't say they sell traffic logs outright, but they do send telemetry on blocked domains to the blocklist provider, and provides "a sparse statistical sampling of timestamped DNS responses" to "a very few carefully vetted security researchers". That's not exactly "selling traffic logs", but is fairly close. Moreover colloquially speaking, it's not uncommon to claim "google sells your data", even they don't provide dumps and only disclose aggregated data.
- daneel_w 1y agoDisagree that it's fairly close to the statement "they resell traffic logs" and the implication that they leak all queried hostnames ("secret hosts, like for your work, will be leaked"). Unless Quad9 is deceiving users, both statements are, in fact, completely false. https://quad9.net/privacy/policy/#22-data-collected https://quad9.net/privacy/policy/#22-data-collected
- gruez 1y ago>and the implication that they leak all queried hostnames ("secret hosts, like for your work, will be leaked"). The part about sharing data with "a very few carefully vetted security researchers" doesn't preclude them from leaking domains. For instance if the security researcher exports a "SELECT COUNT(*) GROUP BY hostname" query that would arguably count as "summary form", and would include any secret hostnames. >https://quad9.net/privacy/policy/#22-data-collected https://quad9.net/privacy/policy/#22-data-collected If you're trying to imply that they can't possibly be leaking hostnames because they don't collect hostnames, that's directly contradicted by the subsequent sections, which specifically mention that they share metrics grouped by hostname basis. Obviously they'll need to collect hostname to provide such information.
- sophacles 1y agoIm sorry... what is a secret hostname that is publicly resolvable? The very idea strikes me as irresponsible and misguided.
- notpushkin 1y agoIt could be some subdomain that’s hard to guess. You can’t (generally) enumerate all subdomains through DNS, and if you use a wildcard TLS certificate (or self-signed / no cert at all), it won’t be leaked to CT logs either. Secret hostname.
- rvnx 1y agoExamples: github.internal.companyname.com or jira.corp.org or jenkins-ci.internal-finance.acme-corp.com or grafana.monitoring.initech.io or confluence.prod.internal.companyx.com etc These, if you don't know the host, you will not be able to hit the backend service. But if you know, you can start exploiting it, either by lack of auth, or by trying to exploit the software itself
- Quad9 1y agoWe are fully committed to end-user privacy. As a result, Quad9 is intentionally designed to be incapable of capturing end-users' PII. Our privacy policy is clear that queries are never associated with individual persons or IP addresses, and this policy is embedded in the technical (in)capabilities of our systems.
- rvnx 1y agoIt is about the hostnames themselves like: git.nationalpolice.se but I understand that there is not much choice if you want to keep the service free to use so this is fair
- staviette 1y agoIs that really a concern for most people? Trying to keep hostnames secret is a losing battle anyways these days. You should probably be using a trusted TLS certificate for your git hosting. And that means the host name will end up in certificate transparency logs which are even easier to scrape than DNS queries.
- moontear 1y agoYou would probably use wildcard certificates to NOT leak those subdomains
- baobabKoodaa 1y agoWindows 11 does not allow using this combination
- snickerdoodle12 1y agoHuh? Did they break the primary/secondary DNS server setup that has been present in all operating systems for decades?
- antonvs 1y agoDNS over HTTPS adds a requirement for an additional field - a URL template - and Windows doesn't handle defaulting that correctly in all cases. If you set them manually it works fine.
- snickerdoodle12 1y agoWhat does that have to do with plain old dns?
- antonvs 1y agoNothing, but Windows can automatically use DNS over HTTPS if it recognizes the server, which is the source of the issue the other commenter mentioned.
- AStonesThrow 1y ago[dead]
- lxgr 1y agoHow so? Does it reject a secondary DNS server that’s not in the same subnet or something similar?
- antonvs 1y agoIt's using DNS over HTTPS, and it doesn't default the URL templates correctly when mixing (some) providers. You can set them manually though, and it works.
- Aachen 1y agoI became a bit disillusioned with quad9 when they started refusing to resolve my website. It's like wetransfer but supporting wget and without the AI scanning or interstitials. A user had uploaded malware and presumably sent the link to a malware scanner. Instead of reporting the malicious upload or blocking the specific URL¹, the whole domain is now blocked on a DNS level. The competing wetransfer.com resolves just fine at 9.9.9.9 I haven't been able to find any recourse. The malware was online for a few hours but it has been weeks and there seems to be no way to clear my name. Someone on github (the website is open source) suggested that it's probably because they didn't know of the website, like everyone heard of wetransfer and github and so they don't get the whole domain blocked for malicious user content. I can't find any other difference, but also no responsible party to ask. The false-positive reporting tool on quad9's website just reloads the page and doesn't do anything ¹ I'm aware DNS can't do this, but with a direct way of contacting a very responsive admin (no captchas or annoying forms, just email), I'd not expect scanners to resort to blocking the domain outright to begin with, at least not after they heard back the first time and the problematic content has been cleared swiftly
- mnordhoff 1y agoYou should email them about the form and about your domain. Their email address is listed on the website. <https://quad9.net/support/contact/ https://quad9.net/support/contact/> Sometimes the upstream blocklist provider will be easy to contact directly as well. Sometimes not so much.
- ajdude 1y agoI've been the victim of similar abuse before, for my mail servers and one of my community forums that I used to run. It's frustrating when you try to do everything right but you're at the mercy of a cold and uncompromising rules engine. You just convinced me to ditch quad9.
- Aachen 1y agoIn the ticket I just opened (see sibling thread), I asked which blocklist my domain was on. Maybe let's see what comes out of it, perhaps they can improve the process (e.g. drop that blocklist, or notify the abuse record of domains which they're blocking so that domain owners are at least aware of where they can go to fix things) I don't see contact info on your profile or website/blog, but I can post here what the outcome is Edit: I love your blog's theme btw!
- Algent 1y agoYeah pretty much. In a perfect world you would pair it with another service I guess but usually you use the official backup IP because it's not supposed to break at same time.
- lillecarl 1y agoI would rather fall back to the slow path of resolving through root servers than fall back from one recursive resolver to another.
- rvnx 1y ago8.8.8.8 + 1.1.1.1 is stable and mostly safe
- baobabKoodaa 1y agoWindows 11 does not allow using this combination
- heraldgeezer 1y agoit does if you set it on the interface
- ziml77 1y agoThis is what I do. I have both services set in my router, so the full list it tries are 1.1.1.1, 1.0.0.1, 8.8.8.8, and 8.8.4.4