4 ms·
can someone explain why using your ISP's DNS server is not recommended as hinted by the submissions' title? seems to me that it really depends on the service q
by alternize 12y ago
can someone explain why using your ISP's DNS server is not recommended as hinted by the submissions' title?
seems to me that it really depends on the service quality of the ISP. if you're lucky and have a good ISP, wouldn't using its servers be faster (less hops)? are there other arguments for using different servers?
- dice 12y agoMany ISPs hijack DNS NXDOMAIN results to serve ads to their customers. https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_ISPs https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_...
- Gracana 12y agoWhat I hate most about DNS hijacking is that it ends up tainting my browser's URL autocompletion list. If I go to "news" instead of "news.ycombinator.com" because I didn't wait for the completion, my ISP will serve up a valid resulting page... and my autocomplete will be happy to take me to "news" again and again after that.
- tokenizerrr 12y agoIt is annoying, but know that you can remove entries from the autocomplete list (in Chrome at least) by selecting it using the arrow keys and using shift+delete.
- Gracana 12y agoI recall having trouble with that in chrome. I seem to get inconsistent results removing history items in firefox, too. I dunno. shrug
- ChikkaChiChi 12y agoOpenDNS will block known adware, spyware, and malware sites at the expense of serving up custom pages when addresses don't resolve. Some ISPs do this at no additional benefit to the customer. Caching and speed are the other most likely reasons.
- sp332 12y agoRight now, if you make a free account on the OpenDNS website, you can configure it to give you normal NXDOMAIN records instead of ads. And they just announced that they're going to do away with all ads, since they never really liked having them and they're getting enough money from paying customers now. https://news.ycombinator.com/item?id=7819150 https://news.ycombinator.com/item?id=7819150
- bigbugbag 12y agoAnd once you have an account they can link it with your usage of their DNS and get a better price when they sell the data. As stated by its cofounder in the "no more ads" post, OpenDNS is a "revenue oriented company" so it seems the logic behind this option existing for registered user sis that they get more money from selling registered user data than from showing ads.
- deleted 12y ago[deleted]
- bigbugbag 12y ago« They also keep permanent logs of all queries, which could be subpoenaed by a government entity. Their joke of a privacy policy allows them to sell your logs to "Affiliated Businesses", which pretty much means anybody. Not that it really matters - they could amend their privacy policy tomorrow morning and be selling your info by the afternoon.» -- seizurebattlerobot http://beta.slashdot.org/comments.pl?sid=1297613&cid=28640723 http://beta.slashdot.org/comments.pl?sid=1297613&cid=2864072...
- justizin 12y agoEDIT: fixed DNS IP. Technically, there may be an advantage to using a 'closer' DNS server with 'less hops', but many national ISPs don't push DNS servers to all POPs. DNS infrastructure at large ISPs tends to be heavily loaded and is scaled based on demand. It's common, and many wifi routers do this for you by default, to run a local caching nameserver which uses some other ISP nameservers as 'forwarders'. You create less demand upstream as well as getting faster response if you do this. Obviously you should also be concerned about creating load on DNS services provided by someone you have no relationship with. Some might even consider it rude. In addition to OpenDNS, Google runs free DNS servers at 8.8.8.8 and 8.8.4.4, but obviously there are concerns with relying upon Google to provide all of the internet's infrastructure. What we should really all be talking about is decentralized, peer-to-peer DNS, or a system of forwarders we all provide from places like Linode and DigitalOcean, both of which I've used to provide off-site secondary and tertiary DNS for large networks. We should be looking at NameCoin, not just leeching off some other random ISP.
- mclarke 12y ago8.8.4.4 should be the second google ip address.
- justizin 12y agothanks, fixed.
- scott_karana 12y agoPersonally, I find it obnoxious that OpenDNS hijacks nonresolving domains and uses them as "search pages", but to each their own. Nothing is worse than trying to SSH into a server with a domain typo, and thinking it exists...
- rhubarbquid 12y agoDidn't they just announce they were going to stop doing that?
- ams6110 12y agoWhen a suboena is presented to your ISP demanding your DNS logs, there won't be anything for them to disclose.
- drdaeman 12y agoAre ISPs obliged to keep such logs in any country out there? I work for one in Russia (quite unhealthy country for Internet those days), and AFAIK we're only supposed to keep accounting records (i.e. times, assigned IP addresses etc.)
- bigbugbag 12y agoIf luck gave you a ISP offering a good DNS service there is still a matter of privacy and escaping surveillance. Laws ordering ISP to keep logs of their customer activity are becoming increasingly common around the world. By using a different DNS server your ISP DNS server has no logs to show for your DNS activity. It is good privacy practice to split the data about your internet activities across different providers to make it more difficult to track you. For example if you use google services for web search, then you should not use google for your email (ideally your should host your own email). But the sad state of reality is that ISP DNS are often poor, whether it is hijacking DNS for profit or blocking domains following judge's orders or local laws.
- Spittie 12y agoYour ISP can already easily track what you browse/requests, it's not like the DNS logs give them more information (and unless you use DNSCrypt or similar, they can just see the DNS traffic anyway). On the contrary, by using a different DNS server you're giving your data both to your ISP (you have to) and a 3rd party.
- melville_X 12y agoThat's why VPNs exist. A VPN without an external DNS service is pretty pointless if you're concerned about ISP snooping.
- Spittie 12y agoWell, then if all the DNS traffic is proxyed through a VPN your ISP can't know who made that query, making it pretty much useless. And if you're worrying about DNS leaks, your ISP is still able to read that traffic even when using a different DNS provider (assuming no DNSCrypt or similar). 3rd party DNS servers can be useful, I just don't see any additional value to your privacy when not coupled with DNSCrypt/DNSCurve.
- mike-cardwell 12y ago"It is good privacy practice to split the data about your internet activities across different providers" Not really. Now both your ISP and your DNS provider know what sites you're visiting. All you're doing is increasing your attack surface.
- belorn 12y agoUsing an ISP DNS server is similar to the old telephone system where you talked to an "operator" in order to connect the call to someone. Rather than keeping track of peoples number yourself, this third-party will do it for you. So, when is it that you do not want to call an operator to patch every call you make? Ask yourself this question, knowing that the operator keeps a list of every incoming and outgoing call. Know that they sometimes also lie and say that the party you are calling is not reachable, while in fact the operator simply refuses to connect you. Some operators will even send you to a telemarketer in order to monetize poorly stated questions. On the positive side, it is faster. Asking your ISP for every DNS resolving does sometime give an increase speed by shaving a few milliseconds the first time you connect to a website. Depending on what you prioritize, that is either worth it, or not.