▲ 178 ▼ Google, Cloudflare & Cisco Will Poison DNS to Stop Piracy Block Circumvention * TorrentFreak (torrentfreak.com) submitted 2 years ago by reddthat@reddthat.com to c/piracy@lemmy.dbzer0.com 27 comments fedilink hide all child comments Run your own unbound or bind resolvers!
[–] domi@lemmy.secnd.me 8 points 2 years ago (2 children) Is it possible to get unbound to talk to the root servers via TLS/HTTPS by now? I'm currently using Quad9 because they support DNS over TLS and DNS over HTTPS. permalink fedilink source hideshow 4 child comments replies: [–] NullGator@lemmy.ca 5 points 2 years ago (1 child) Yes its possible 👍 Use: forward-zone: forward-addr: 9.9.9.9@853#dns.quad9.net permalink fedilink source parent hideshow 2 child comments replies: [–] domi@lemmy.secnd.me 3 points 2 years ago (1 child) That is what I'm doing currently but now unbound doesn't talk to the root servers anymore, it sends all queries to Quad9. Both scenarios are not ideal because you always end up with one entity knowing all your queries. permalink fedilink source parent hideshow 2 child comments replies: [–] NullGator@lemmy.ca 1 point 2 years ago Perhaps you could configure more than unbound service behind a loadbalancer. Each unbound instance is configured to use different upstream dns servers. Double check if unbound doesn't allow you to randomly hop between dns upstreams first, but the above solution should work if that's unavailable atm. permalink fedilink source parent [–] out@lemmynsfw.com 1 point 2 years ago (1 child) Not sure you would even need encryption. Surely It can't be illegal to ask the root servers (and all the other DNS servers involved, because the root servers only have IPs for TLD DNS servers) for IPs permalink fedilink source parent hideshow 2 child comments replies: [–] domi@lemmy.secnd.me 3 points 2 years ago (1 child) Not illegal but it leaves all your DNS lookups in plain text with your ISP, which just doesn't sit right with me. Not that the ISP in my country would care. permalink fedilink source parent hideshow 2 child comments replies: [–] NullGator@lemmy.ca 1 point 2 years ago Also introduces the possibility of DNS poisoning permalink fedilink source parent
[–] NullGator@lemmy.ca 5 points 2 years ago (1 child) Yes its possible 👍 Use: forward-zone: forward-addr: 9.9.9.9@853#dns.quad9.net permalink fedilink source parent hideshow 2 child comments replies: [–] domi@lemmy.secnd.me 3 points 2 years ago (1 child) That is what I'm doing currently but now unbound doesn't talk to the root servers anymore, it sends all queries to Quad9. Both scenarios are not ideal because you always end up with one entity knowing all your queries. permalink fedilink source parent hideshow 2 child comments replies: [–] NullGator@lemmy.ca 1 point 2 years ago Perhaps you could configure more than unbound service behind a loadbalancer. Each unbound instance is configured to use different upstream dns servers. Double check if unbound doesn't allow you to randomly hop between dns upstreams first, but the above solution should work if that's unavailable atm. permalink fedilink source parent
[–] domi@lemmy.secnd.me 3 points 2 years ago (1 child) That is what I'm doing currently but now unbound doesn't talk to the root servers anymore, it sends all queries to Quad9. Both scenarios are not ideal because you always end up with one entity knowing all your queries. permalink fedilink source parent hideshow 2 child comments replies: [–] NullGator@lemmy.ca 1 point 2 years ago Perhaps you could configure more than unbound service behind a loadbalancer. Each unbound instance is configured to use different upstream dns servers. Double check if unbound doesn't allow you to randomly hop between dns upstreams first, but the above solution should work if that's unavailable atm. permalink fedilink source parent
[–] NullGator@lemmy.ca 1 point 2 years ago Perhaps you could configure more than unbound service behind a loadbalancer. Each unbound instance is configured to use different upstream dns servers. Double check if unbound doesn't allow you to randomly hop between dns upstreams first, but the above solution should work if that's unavailable atm. permalink fedilink source parent
[–] out@lemmynsfw.com 1 point 2 years ago (1 child) Not sure you would even need encryption. Surely It can't be illegal to ask the root servers (and all the other DNS servers involved, because the root servers only have IPs for TLD DNS servers) for IPs permalink fedilink source parent hideshow 2 child comments replies: [–] domi@lemmy.secnd.me 3 points 2 years ago (1 child) Not illegal but it leaves all your DNS lookups in plain text with your ISP, which just doesn't sit right with me. Not that the ISP in my country would care. permalink fedilink source parent hideshow 2 child comments replies: [–] NullGator@lemmy.ca 1 point 2 years ago Also introduces the possibility of DNS poisoning permalink fedilink source parent
[–] domi@lemmy.secnd.me 3 points 2 years ago (1 child) Not illegal but it leaves all your DNS lookups in plain text with your ISP, which just doesn't sit right with me. Not that the ISP in my country would care. permalink fedilink source parent hideshow 2 child comments replies: [–] NullGator@lemmy.ca 1 point 2 years ago Also introduces the possibility of DNS poisoning permalink fedilink source parent
[–] NullGator@lemmy.ca 1 point 2 years ago Also introduces the possibility of DNS poisoning permalink fedilink source parent