5 ms·
DNSCrypt is a cool utility, but somewhat of a mixed bag, since OpenDNS serves up responses for invalid DNS records, in an effort to send you to website-unavaila
by navyrain 13y ago
DNSCrypt is a cool utility, but somewhat of a mixed bag, since OpenDNS serves up responses for invalid DNS records, in an effort to send you to website-unavailable.com
This hijacking (I am blanking on the technical term for it) really rubs me the wrong way. Is there a way to get around it?
- davidu 13y ago1) Anyone can run a DNSCrupt resolver... 2) You can create an account with us (free) and disable DNS redirection. This will get _much_ better / easier in the coming months as we continue to move away from ad revenue as a revenue stream. 3) This is a really old story. :-)
- finnn 13y agoHow about AAAA (IPV6) records? I've spoken with a number of people who are unable to resolve AAAA records because they made the mistake of using OpenDNS. So instead of seeing a v6 only site, they get a face full of ads
- wesley 13y agoCan't seem to find the setting to disable dns redirection, can you tell me where to look? Edit: OK, found it - free users need to go to advanced settings > domain typos and disable that.
- ef47d35620c1 13y agoIf you are trying to keep you children away from porn sites, you have to set that option: "Typo Correction is required for Web Content Filtering. You will lose 13 categories of blocking if you disable Typo Correction."
- davidu 13y agoThis will be resolved...soon.
- atmosx 13y agoMe too, that's why I use OpenNIC + unbound and now thinking of installing dnscrypt-proxy too for the local network to encryption between me and OpenNIC servers, since it's supported. note: I had a similar on another thread on HN, weird :0
- blibble 13y agodon't use their service? easier said than done I know... my commuter train's wifi uses "Open"DNS, and most interesting websites are blocked (reddit, anything gaming related, etc), and the block pages are filled with their obnoxious advertising. I've been saying this for years, but I can't wait for DNSSEC to put people like OpenDNS out of business (isn't it odd they want to FUD the waters by pushing DNSCrypt?)
- pstack 13y agoWhy do you want to put OpenDNS out of business? They offer a decent free service that is faster and more reliable than your ISP's nameservers usually are and they offer you a lot of control. Don't like having NXDOMAIN redirected? Disable it. Want to filter out and be alerted on queries that seem to be due to known malware and phising and botnets? Select that option. Want to limit access to websites with certain content? Select what you want to filter (I only filter out the Web Spam, Parked Domain, and Typo Squatting categories). Filter out nothing, if you prefer. Are you a public library or academic institution or a work place and you have to restrict certain content? Select the porn or social networking or adware or other sections (yeah, this might rub people the wrong way, but OpenDNS is giving the administrator of a given network the control over their network to do what they want with it). Really hate doubleclick? Add them to the bocked domain list on opendns. I really fail to see why anyone would have significant problems with OpenDNS. I've been using them for years and I'm a software engineer who requires things to work as expected on my network for testing and debugging -- and OpenDNS hasn't ever been a problem for me, so I'd really like to know what legitimate problems people have with it (other than the fact that, like Comcast or any other provider of a service, they could theoretically be collecting data on you and utilize it in some nefarious fashion, which I just assume of all services free or paid these days).
- blibble 13y agowhilst I can't choose my DNS provider on the train, at home I choose an ISP that is capable of running a recursive name server (if they can't run this very basic part of the service, I dare to think what the rest of it would be like...) I'm still not sure why the practise of deliberately returning spoofed garbage in response to legitimate queries is seen as an acceptable practise.
- pstack 13y agoOpenDNS allows you to disable interception of NXDOMAIN. Just go to your Customization settings and make sure "Enable NX Domain Redirection" is unchecked. Ex: http://i.imgur.com/UxjoLkA.png http://i.imgur.com/UxjoLkA.png I invite correction, if I'm wrong, but I don't believe the option requires being a paying customer of their service.
- da_maire 13y agoDnsmasq's bogus-nxdomain flag will do what you want, but it's not a good long-term solution. You'd be better off just using a DNS service that doesn't hijack responses.