Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tenta
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Show HN: Tenta Browser 2.0. Run-your-own VPN and decentralized trust protocol
(tenta.com)
6 points
by
tenta
8y ago
|
0 comments
2.
▲
DNSCrypt vs DNS-over-TLS? What's the difference and why TLS is better.
(tenta.com)
10 points
by
tenta
9y ago
|
1 comments
3.
▲
by
tenta
9y ago
Some parts have unit tests. In addition, the "stresser" component, runs a resolve on the top million domain names, and we run this on every push on our development fork. This provides a real workout. We certainly need to produce a
4.
▲
by
tenta
9y ago
Setting the log level has effects, but only on an internal wrapper package that neatly zips up the nitty gritty of setting up the logger.
5.
▲
by
tenta
9y ago
Well, we didn't rewrite BGP in go, we used the excellent OSRG library for that. We played with several of the open source BGP libraries, but these inevitably result in a giant mess of configs and scripts holding things together, and fu
6.
▲
by
tenta
9y ago
Not currently no. First of all, there's sort of two parts to "DNSCrypt", the typical DNSCrypt, which is Client<->Recurosor, and DNSCurve, which is Recursor<->Authority. The implementation is complex, and not well
7.
▲
by
tenta
9y ago
This appears to be in the same universe (DNS with TLS in a shiny new language). It looks like Tenta DNS currently supports more features around scaling and production use, while Trust DNS includes a client component.
8.
▲
by
tenta
9y ago
Largely the same as vs PowerDNS. We've designed this to be an all-in-one for running a performant and secure server with BGP. However, we use the excellent miekg/dns library for the DNS wire protocol, which is related to (sponsor
9.
▲
by
tenta
9y ago
And thank you for PowerDNS. We got to the point with this where we wanted the convenience and easy parallelism of go, but we've used powerdns many times over the years, and it's been a great contribution to the net.
10.
▲
by
tenta
9y ago
We've previously used a redis-replicated backend to powerdns. The fact that it was pluggable was awesome. We'd love to support something like that one day. For now, however, our eye is firmly on recursion. If a golang DNS server
11.
▲
by
tenta
9y ago
Servers are located in Amsterdam, Miami, Seattle and Singapore. Since the resolvers are new, there's a lot of global cache to fill up. In addition, if you'd be willing to share, visit https://nstoro.com/api/v1
12.
▲
by
tenta
9y ago
You can certainly make two configs, an authoritative only and a recursive only and just run two copies. However, while we cannot strictly control how goroutines are allocated, each module (recursor, resolver, nsnitch) run as their own littl
13.
▲
by
tenta
9y ago
We natively work a BGP, making it easy and practical to do things like "anycast" (announcing the same IP address from multiple datacenters), or using BGP for load balancing or failover. Looking at large and successful DNS provider
14.
▲
by
tenta
9y ago
authoritative features we don't support yet. We have a slack webhook to help us know when it's running and when it's not. It lets us know if we have server errors. All anonymous of course. The only other place we use json is
15.
▲
by
tenta
9y ago
Knot DNS is authoritative only. Our main focus has been recursive support and full security support. We haven't used knot dns, but it has an excellent reputation. At the moment, knot dns is more suitable for authoritative hosting (our
16.
▲
by
tenta
9y ago
thanks! also vs coreDNS, we support actually running as a recursive or authoritative resolver. CoreDNS is appropriate (excellent, in fact) for running for service discovery, but not suitable for running as a public resolver.
17.
▲
by
tenta
9y ago
Tenta browser business model is the opposite of most browsers. We don't care about ads. It's simply based on protecting data. We have a built-in VPN that's always free to use in-browser only, but if you want to expand VPN cov
18.
▲
by
tenta
9y ago
ah, in some cases VPN providers push DNS options too, in which case your system DNS will be overridden. Can you check whether that's the case?
19.
▲
by
tenta
9y ago
thanks! We appreciate it. Yeah mainly not open source and AFAIK, it's authoritative only.
20.
▲
by
tenta
9y ago
PowerDNS provides the standard by which other DNS resolvers are judged. It's an amazing, stable product. Our biggest features compared to PowerDNS are that we provide DNS-over-TLS, we're written in memory safe golang (which is als
21.
▲
by
tenta
9y ago
We support full recursion, including DNSSEC validation and chaining up to the roots. CoreDNS is an awesome product, but it's much more focused on service discovery
22.
▲
by
tenta
9y ago
Can you let me know which browser you're using? Also I'm assuming you're running the test site with our DNS settings or another DNS? Also do you have a VPN running?
23.
▲
Show HN: Golang DNS server, including DNSSEC and DNS-over-TLS
(github.com)
283 points
by
tenta
9y ago
|
64 comments
24.
▲
by
tenta
9y ago
We've just open sourced the API that powers our Browser Privacy Test Tool, written in Golang: https://github.com/tenta-browser/nsnitch . As you know, many of the best VPNs today offer a secure DNS solution, but jus
25.
▲
Show HN: Snitches get stitches. See what data recursive nameservers are leaking
(tenta.com)
3 points
by
tenta
9y ago
|
1 comments
26.
▲
by
tenta
10y ago
After beta, we'll allow direct downloads of the apk. During this test phase, it's just easier for us to manage the tester feedback with the Play store admin tools.
27.
▲
by
tenta
10y ago
We're starting with Android first (we'll make that clear on the site) and iOS second. Then we'll decide what platforms to prioritize next. Regarding the second question, the short answer is that we plan to support this. It&#x
28.
▲
by
tenta
10y ago
I just answered this question above. check out my response to user niij. If you have further questions though, let me know.
29.
▲
by
tenta
10y ago
On the UA string, thats a good suggestion. We can look how much device info we need to send and add some settings for that. On the privacy question, it sounds like the zone you used was connected to a local connection instead over the VPN c
30.
▲
by
tenta
10y ago
Mainly because we're still getting beta feedback and in development. We're on version 0.99.5 and working toward 1.0, so depending on what beta testers tell us, there could potentially be sections of the app that change completely
More ›