Add non-OPENNIC DNS resolvers? #1028

Closed
opened 2019-07-13 21:35:25 +00:00 by Mikaela · 7 comments
Mikaela commented 2019-07-13 21:35:25 +00:00 (Migrated from github.com)

Currently only OpenNIC is supported and they don't have any DoH servers that Firefox (or issue #785) would need. Should more DNS providers be added so there would be something which Firefox TRR instructions could link to?

I guess the DNS page would also need VPN-style warnings and I fear this could possibly promote centralization. Maybe there would be a big warning on hosting your own at first and suggestions for software to do it?

  • DNS.watch suggested in https://github.com/privacytoolsIO/privacytools.io/issues/513 (public resolver)

  • Quad9 non-profit and OK looking privacy policy (public resolver) (warning: malicious domain filtering)

  • AdGuard DNS, for-profit, but OK looking privacy policy, however Cloudflare and blocked bbc.com yesterday or so, not-14-eyes (public resolver with adblocking (warning: you don't control the blacklist))

    • edit: AdGuard DNS is also missing DNSSEC support which would prevent the DNS server from lying, but I guess the point of AdGuard DNS is to lie especially about advertising domains, but I guess there should be a warning about missing DNSSEC regardless in addition to not controlling the blacklist.
  • https://blahdns.com/ mentioned in #785 (public resolver)

  • https://www.privacytools.io/providers/dns/#dns

EDIT: DNS server software moved to #1055

Currently only OpenNIC is supported and they don't have any DoH servers that Firefox (or issue #785) would need. Should more DNS providers be added so there would be something which Firefox TRR instructions could link to? I guess the DNS page would also need VPN-style warnings and I fear this could possibly promote centralization. Maybe there would be a big warning on hosting your own at first and suggestions for software to do it? * [ ] DNS.watch suggested in https://github.com/privacytoolsIO/privacytools.io/issues/513 (public resolver) * [ ] Quad9 non-profit and OK looking privacy policy (public resolver) (warning: malicious domain filtering) * [ ] AdGuard DNS, for-profit, but OK looking privacy policy, however Cloudflare and blocked bbc.com yesterday or so, not-14-eyes (public resolver with adblocking (warning: you don't control the blacklist)) * edit: AdGuard DNS is also missing DNSSEC support which would prevent the DNS server from lying, but I guess the point of AdGuard DNS is to lie especially about advertising domains, but I guess there should be a warning about missing DNSSEC regardless in addition to not controlling the blacklist. * [ ] https://blahdns.com/ mentioned in #785 (public resolver) * https://www.privacytools.io/providers/dns/#dns EDIT: DNS server software moved to #1055
nitrohorse commented 2019-07-14 02:20:41 +00:00 (Migrated from github.com)

Should more DNS providers be added so there would be something which Firefox TRR instructions could link to?

I really like this idea 👍

> Should more DNS providers be added so there would be something which Firefox TRR instructions could link to? I really like this idea :+1:
Atavic commented 2019-07-21 18:05:13 +00:00 (Migrated from github.com)

There's a trend by some privacy aware people that goes like this: are you afraid that someone will monitor you? So, use a service from another country or a different continent to cover you up. This is a statement that's highly valued for VPN users and torrent users that get seedboxes in far-away countries. I follow this trend for my DNS and Mail. I live in central europe and both my DNS and Mail are located in eastern europe.
For DNS, one could have a look at https://www.grc.com/dns/benchmark.htm if speed is a problem (but most of the time it is not).

There's a trend by some privacy aware people that goes like this: are you afraid that someone will monitor you? So, use a service from another country or a different continent to cover you up. This is a statement that's highly valued for VPN users and torrent users that get seedboxes in far-away countries. I follow this trend for my DNS and Mail. I live in central europe and both my DNS and Mail are located in eastern europe. For DNS, one could have a look at https://www.grc.com/dns/benchmark.htm if speed is a problem (but most of the time it is not).
Mikaela commented 2019-07-21 18:16:01 +00:00 (Migrated from github.com)

I think distant DNS may be a problem for CDN and thus average users. In case of Finland the situation is going to be the opposite with preferring foreign DNS as if the DNS traffic crossed borders, it would be free for mass surveillance to monitor. Here I however assume that DNSCrypt/DoT/DoH is not being used (and it may not matter that much anyway as #785 is still there to shout SNIs in plaintext in most of cases).

I think distant DNS may be a problem for CDN and thus average users. In case of Finland the situation is going to be the opposite with preferring foreign DNS as if the DNS traffic crossed borders, it would be free for mass surveillance to monitor. Here I however assume that DNSCrypt/DoT/DoH is not being used (and it may not matter that much anyway as #785 is still there to shout SNIs in plaintext in most of cases).
Mikaela commented 2019-07-24 07:32:28 +00:00 (Migrated from github.com)

Is there a limit that the section can only contain three recommended or can more be added? Should the DNS servers be visible on top or put to Worth Mentioning? I would be happy with worth mentioning as it would be less work, but would that be weird to link to from the Firefox page?

https://github.com/privacytoolsIO/privacytools.io/issues/785#issuecomment-514514909 bumbed me on this.

Oh and should there be a note on Quad9 that it has been founded by law enforcement which concerns some people on Reddit?

Is there a limit that the section can only contain three recommended or can more be added? Should the DNS servers be visible on top or put to Worth Mentioning? I would be happy with worth mentioning as it would be less work, but would that be weird to link to from the Firefox page? * https://www.privacytools.io/providers/dns/#dns https://github.com/privacytoolsIO/privacytools.io/issues/785#issuecomment-514514909 bumbed me on this. Oh and should there be a note on Quad9 that it has been founded by law enforcement which concerns some people on Reddit?
Mikaela commented 2019-07-24 19:27:50 +00:00 (Migrated from github.com)

Mikaela: I think ideally we would switch sections to cardv2.html like how browser addons are currently setup which would allow us to recommend more than 3 as needed without messing up the layout.

Says @JonahAragon

> Mikaela: I think ideally we would switch sections to cardv2.html like how browser addons are currently setup which would allow us to recommend more than 3 as needed without messing up the layout. Says @JonahAragon
Mikaela commented 2019-07-25 07:19:51 +00:00 (Migrated from github.com)

I kind of like how the current XMPP section is done, could I copy that kind of layout for this?

I kind of like how the current XMPP section is done, could I copy that kind of layout for this?
Mikaela commented 2019-07-25 13:32:58 +00:00 (Migrated from github.com)

DNS.watch is missing DoT/DoH, so I am excluding it from my upcoming PR.

DNS.watch is missing DoT/DoH, so I am excluding it from my upcoming PR.
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#1028
No description provided.