6 ms·
Introducing DNSCrypt (Preview Release)
- zaroth 13y agoI was thinking about tunneling all UDP coming out of my servers to a disposable address, with the intent of drop all inbound/outbound UDP, or even seeing if I could get my upstream to always drop all inbound UDP, in order to mitigate DDoS. Perhaps this is an easy way to achieve that for DNS at least. Not sure how many other protocols are necessary to tunnel from a server which is only responding to HTTPS, and installing security updates.
- xxdesmus 13y agoThis was released ....at least a year ago. Am I missing something? The newest code/content is at http://dnscrypt.org/ http://dnscrypt.org/
- sp332 13y agoNope, it's at least 2 years old http://web.archive.org/web/20111207064744/http://www.opendns.com/technology/dnscrypt/ http://web.archive.org/web/20111207064744/http://www.opendns...
- dmunoz 13y agoIs there anything new here? DNSCrypt as a preview has been available for a good while now. Clicking through to their GitHub, I see that dnscrypt-proxy was last updated 4 days ago, and then the two clients: dnscrypt-osx-client 11 days ago yet dnscrypt-win-client more than a year ago, with various issues that have not been responded to, oldest being a year old as well. I point this out mainly because I gave dnscrypt a shot more than a year ago on windows and it severely borked my internet in a non-obvious way which had nothing to do with DNS. For days I was limited to ~25kbps speeds. I had disable dnscrypt at this point, and was on the verge of phoning my ISP to report a problem when I finally fully removed the windows client and the problem resolved itself. Playing with preview release software can seriously suck sometimes.
- IvyMike 13y ago> Is there anything new here? I believe this is a response to the "The free wifi on the bus hijacked my DNS" story that was on the front page earlier today. Edit: this one https://news.ycombinator.com/item?id=7047682 https://news.ycombinator.com/item?id=7047682
- navyrain 13y agoDNSCrypt is a cool utility, but somewhat of a mixed bag, since OpenDNS serves up responses for invalid DNS records, in an effort to send you to website-unavailable.com This hijacking (I am blanking on the technical term for it) really rubs me the wrong way. Is there a way to get around it?
- davidu 13y ago1) Anyone can run a DNSCrupt resolver... 2) You can create an account with us (free) and disable DNS redirection. This will get _much_ better / easier in the coming months as we continue to move away from ad revenue as a revenue stream. 3) This is a really old story. :-)
- finnn 13y agoHow about AAAA (IPV6) records? I've spoken with a number of people who are unable to resolve AAAA records because they made the mistake of using OpenDNS. So instead of seeing a v6 only site, they get a face full of ads
- wesley 13y agoCan't seem to find the setting to disable dns redirection, can you tell me where to look? Edit: OK, found it - free users need to go to advanced settings > domain typos and disable that.
- ef47d35620c1 13y agoIf you are trying to keep you children away from porn sites, you have to set that option: "Typo Correction is required for Web Content Filtering. You will lose 13 categories of blocking if you disable Typo Correction."
- davidu 13y agoThis will be resolved...soon.
- 13y ago
- gararapa 13y agoThese versions are really old. For the latest version, go to http://dnscrypt.org/ http://dnscrypt.org/.
- crator 13y agoDNS privacy and signature verification is a good thing, but what about combatting random domain name confiscations? The attackers already do it for so-called copyright infringement, but they could do it for any reason, if they wanted to. So, what about thoroughly decentralizing the DNS system and getting rid of the centralization of corruption at ICANN? Isn't that more urgent nowadays?
- drdaeman 13y agoNamecoin?
- Nux 13y agoThis seems to be a DNSCurve implementation.
- mike-cardwell 13y agoBare in mind, when using DNSCrypt with OpenDNS you're actually reducing your overall level of privacy. Now two companies can see what sites you're visiting: your ISP and OpenDNS. Your ISP doesn't need to see your DNS queries in order to know what sites you're visiting. They can see the IP's that you're sending packets to. They can see the HTTP "Host" header for HTTP. They can even see the hostname for HTTPS because of SNI.
- pstack 13y agoThree. Don't forget the website, itself. Well, maybe four or five or ten. Don't forget all of the advertisements and beacons on the site you're visiting. Well, maybe also Google, if you're using Chrome. Oh, and maybe everybody, unless everything you're doing is always encrypted and it's through a VPN service that doesn't maintain any logging and isn't subject to government subpoena and can be thoroughly trusted. Frankly, if your ISP can see it, then who cares who else along the chain does? Nobody else providing a service that can see your data is going to do anything with it that Comcast, Cox, Sprint, Verizon, AT&T, CenturyLink, and Frontier isn't already doing.
- mike-cardwell 13y agoNone of the examples you have supplied are equivalent or relevant. My point stands: If you use DNSCrypt+OpenDNS in order to try and hide your browser history from your ISP, not only will you not succeed, but you will make matters worse.
- pstack 13y agoRight. My point was simply that there's little point to them being concerned about their ISP in the first place if they're exposed elsewhere along the chain (unless they're simply worried about being locked-down from accessing certain servers for some reason, I guess?).