What DNS service are you using?

Discussion in 'privacy technology' started by Frankfree, May 12, 2019.

  1. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    I understand what you mean about public and thought better of it after I posted.

    What do you set it up on? A secondary PC in your home or what? Thanks.
     
  2. Beyonder

    Beyonder Registered Member

    Joined:
    Aug 26, 2011
    Posts:
    545
    I've considered getting my own if the public Pi Hole turns out to work well.

    I'm also not super worried about the privacy and security of the Public Pi Hole. I feel the odds of my site visits being scanned are lower if it's a private person instead of a massive corporation.
     
  3. RioHN

    RioHN Registered Member

    Joined:
    Mar 14, 2017
    Posts:
    117
    Location:
    Here
    I have it running on a Raspberry Pi. They're cheap and use barely any power so can be left running 24/7 in most situations.

    I guess it depends on how much you trust the person hosting it. Pi-Hole comes with lots of nice logging and graphing functionality making it very easy to see a history of DNS requests a specific IP has made. If there's only a handful of people using the service you stand out way more than when using a service with thousands of requests per second.

    Regarding security, as it's a DNS server it would be pretty easy to redirect connection attempts to fake versions of a website in order to steal login credentials.
     
  4. Beyonder

    Beyonder Registered Member

    Joined:
    Aug 26, 2011
    Posts:
    545
    I don't use my computer for anything important. If someone wants to steal my Wilders account, that's fine by me :)
     
  5. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    I know zero about a Rasberry Pi. Guess I need to look into this.
     
  6. guest

    guest Guest

    My VPN one or Cleanbrowsing DOH.
     
  7. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,246
    Location:
    Among the gum trees
    Clean Browsing Security filter.
     
  8. Stefan Froberg

    Stefan Froberg Registered Member

    Joined:
    Jul 30, 2014
    Posts:
    747
    My own. Dynamic SSH tunnel to my rented VPS.
    Outbound traffic blocked for everything except for ssh connection so no leaks possible.
     
  9. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Been checking out NextDNS.
     
  10. A_mouse

    A_mouse Registered Member

    Joined:
    Jul 29, 2019
    Posts:
    94
    Location:
    A field
    I use DNSCrypt on auto so hop around whatever is the fastest resolver.
    The common problem with the service sometimes not loading seems to be related to checking for a working connection.
    If you are not connected it fails.
    It can help to set the service to load delayed so it gives a bit more time.
     
  11. deBoetie

    deBoetie Registered Member

    Joined:
    Aug 7, 2013
    Posts:
    1,832
    Location:
    UK
    Quad9 with DoT running on a pfSense router with pfblockerng. Sweet.

    Use VPN & their DNS when out and about on the phone.
     
  12. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    I am trying this out today. Are you on the free or paid plan Krusty?
     
  13. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,246
    Location:
    Among the gum trees
    Just the free option, Mr Trooper.
     
  14. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Gotcha. It was blocking some sites for me like Reddit, so I went back to NextDNS for now.
     
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,246
    Location:
    Among the gum trees
    Are you sure you configured the Security filter? You didn't use the Family or Adult filter?

    IPv4 address: 185.228.168.9 and 185.228.169.9
    IPv6 address: 2a0d:2a00:1::2 and 2a0d:2a00:2::2

    https://cleanbrowsing.org/
     
  16. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,246
    Location:
    Among the gum trees
    Family Filter
    Blocks access to all adult, pornographic and explicit sites. It also blocks proxy and VPN domains that are used to bypass the filters. Mixed content sites (like Reddit) are also blocked. Google, Bing and Youtube are set to the Safe Mode. Malicious and Phishing domains are blocked.

    IPv4 address: 185.228.168.168 and 185.228.169.168
    IPv6 address: 2a0d:2a00:1:: and 2a0d:2a00:2::

    https://cleanbrowsing.org/filters#family
     
  17. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Krusty thanks! I inadvertently entered the wrong IP. My eyes or bad (or am just getting old), lol.

    Cheers man!
     
  18. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,246
    Location:
    Among the gum trees
    He he. I know the feeling. All good mate. The Security filter shouldn't block too much, or at least it doesn't for me.

    Enjoy!
     
  19. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  20. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,009
    Location:
    Member state of European Union
  21. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    Yes, it is. I had to apologize to their CEO on HN about that ;)

    And more and more VPN services are doing the same. It's very cool :)
     
  22. pasmal

    pasmal Registered Member

    Joined:
    Jan 25, 2015
    Posts:
    55
    Came across this study on which DNS provider does better malware and phishing blocking:
    https://www.skadligkod.se/general-security/phishing/malicious-site-filters-on-dns-in-2020/

    Quad9 came out on top with an impressive 92%+. However, only 24 links were used. The author says that these links were about 1-3 days old, so you could use this to infer how often the provider updates their internal lists.

    The other providers in the test included CleanBrowsing, AdguardDNS, OpenDNS and Cloudflare.

    Important to note that Adguard also covers ad blocking as well to an extent.
     
  23. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Thank you for sharing this results :thumb: - I guess it's time to test Quad9 :)
     
  24. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,640
    Location:
    USA
    I've been using Quad9 for a while. I'm pleased with it so far. At least compared to anything else. It's fast and reliable and supports DoH.
     
  25. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Thnx, I've set it as custom DoH server in Firefox.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.