🗄️ DNS provider suggestion | Lelux.fi #1208

Open
opened 2019-08-24 09:54:11 +00:00 by Mikaela · 7 comments
Mikaela commented 2019-08-24 09:54:11 +00:00 (Migrated from github.com)

Basic Information

Name: Lelux
Filtering: No
Privacy policy: https://lelux.fi/privacy/
Protocols: DoT (853)
Server/Location: Luxembourg
Source: -
Type: hobby project?
Website: https://lelux.fi/resolver/

Description

Recommended by #1206 as a backup so if we list it, I guess we should also list this or it will get recommended by someone sooner or later.

Required features:

  • supports DoH or DoT
  • supports DNSSEC
  • doesn't log IP addresses during normal operation
    • I think this is the case judging by "Haproxy TCP/HTTP logs are disabled. No IP addresses are collected." but I am not sure on query log verbosity 1, so leaving unchecked and research required

Desired features

  • supports QNAME minimization
## Basic Information **Name:** Lelux **Filtering:** No **Privacy policy:** https://lelux.fi/privacy/ **Protocols:** DoT (853) **Server/Location:** Luxembourg **Source:** - **Type:** hobby project? **Website:** https://lelux.fi/resolver/ ## Description Recommended by #1206 as a backup so if we list it, I guess we should also list this or it will get recommended by someone sooner or later. ### Required features: <!-- DoH and DoT are supported natively by platforms like Firefox and Android 9+ --> * [x] supports DoH or DoT <!-- We love DNSCrypt, but there is already https://github.com/DNSCrypt/dnscrypt-resolvers which is directly supported by dnscrypt-proxy, so we don't consider useful to list providers only supporting it. --> * [x] supports DNSSEC <!-- https://dnssec.vs.uni-due.de/ can test your current DNS provider. --> * [x] doesn't log IP addresses during normal operation <!-- If your suggestion logs, please compare its privacy policy with other servers on our table that keep logs. --> * I think this is the case judging by "Haproxy TCP/HTTP logs are disabled. No IP addresses are collected." but I am not sure on query log verbosity 1, so leaving unchecked and research required #### Desired features * [x] supports QNAME minimization <!-- if you have access to the dig command, `dig +short txt qnamemintest.internet.nl` -->
ProgressiveArchitect commented 2019-08-25 07:46:00 +00:00 (Migrated from github.com)

It seems silly to add another DNS server to an already packed list, especially when it doesn't support all the features that would make it fully privacy focused.

It seems silly to add another DNS server to an already packed list, especially when it doesn't support all the features that would make it fully privacy focused.
Mikaela commented 2019-08-25 08:42:51 +00:00 (Migrated from github.com)

I haven't been in contact with the admin (yet) nor tested support for the features it doesn't advertise. Or are you able to confirm that it's indeed missing features we require?

I haven't been in contact with the admin (yet) nor tested support for the features it doesn't advertise. Or are you able to confirm that it's indeed missing features we require?
Amolith commented 2019-08-25 16:42:01 +00:00 (Migrated from github.com)

Unbound verbosity level 1 simply provides the admin with some high-level operational information. I've documented that in my privacy policy under DNS services though you can also run man unbound.conf and search for verbosity to read it yourself.

His setup is the same as mine too; on Debian, DNSSEC validation and QNAME minimisation are both enabled by default.

EDIT

The wording on both of our policies was inaccurate; previously, they said "Unbound query logs are enabled" and now they say "Unbound debug logs are enabled". Verbosity is set to 1 by default and neither of us modified that.

Unbound verbosity level 1 simply provides the admin with some high-level operational information. I've documented that in my [privacy policy](https://nixnet.xyz/privacy/) under DNS services though you can also run `man unbound.conf` and search for `verbosity` to read it yourself. His setup is the same as mine too; on Debian, DNSSEC validation and QNAME minimisation are both enabled by default. ## EDIT The wording on both of our policies was inaccurate; previously, they said "Unbound **query** logs are enabled" and now they say "Unbound **debug** logs are enabled". Verbosity is set to 1 by default and neither of us modified that.
Mikaela commented 2019-09-14 18:35:38 +00:00 (Migrated from github.com)

@Amolith do you have contact to Lelux.fi? Their SSL certificate has expired ~24 hours ago and I was pinged about this in our Matrix room.

@Amolith do you have contact to Lelux.fi? Their SSL certificate has expired ~24 hours ago and I was pinged about this in our Matrix room.
Amolith commented 2019-09-14 23:43:08 +00:00 (Migrated from github.com)

@Mikaela I do and I just sent him a message about it.

@Mikaela I do and I just sent him a message about it.
Amolith commented 2019-09-15 21:16:19 +00:00 (Migrated from github.com)

@Mikaela He renewed the certificate a few hours ago.

@Mikaela He renewed the certificate a few hours ago.
freddy-m commented 2021-01-23 12:50:53 +00:00 (Migrated from github.com)

@privacytools/editorial I'm in favour of adding this.

@privacytools/editorial I'm in favour of adding this.
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#1208
No description provided.