Why aren't you using the most secure DNS yet?

Why aren't you using the most secure DNS yet?

Attached: index.png (886x260, 29K)

Other urls found in this thread:

tools.ietf.org/html/draft-vixie-dnsext-dns0x20-00
tenta.com/blog/post/2017/12/dns-over-tls-vs-dnscrypt]
github.com/bhanupratapys/dnswarden
quad9.net/faq/#Does_Quad9_support_doh
dns.quad9.net/dns-query
twitter.com/SFWRedditVideos

>9.9.9.9
ftfy

Because archive.is doesn't work
I don't care whose fault it is point is it doesn't work

(((1.1.1.1)))

no thanks, israel. i use dnscrypt.

I am using DNS over TLS. But it sure as hell isn't coming from Cloudflare. Or Quad 9 or Google.

For the anons who actually know what's going on with DNS these days, how do you verify that you're browsing as securely/privately as possible?

Attached: esni.png (1115x351, 32K)

Azire has free DNS servers with no logging

Attached: dns.jpg (1220x304, 31K)

well for DNS specifically when I set it up I sshed into my router and sniffed my DNS traffic with tcpdump to make sure it was encrypted like I thought it was. I also turned on verbose logging in unbound to verify the same thing. both of these indicated that TLS was happening so I figured it was good.

>most secure DNS
>third party
>cloudflare
Why hello cloudflare shill.

I can't stream chunked/encrypted TV or movies using it. Everything just times out.

>trusting cloudflare after the multiple outages these past 2 months
lol

>Secure
Good one.

I use opennic

unlacky number

But I am using dns.watch, user.

>He doesn't use 9.9.9.9

>Censorship is a feature!
Just wait until Jow Forums gets added to the shitware list.

I know right, I can't wait to be free from this place!

link?

sudo pacman -S unbound

not using a host file
olololololo

Welcome to zoomer edition of 4chins, we provide you no links and just say nigger.

can't you just a set a fallback DNS?
exactly those features. you can also try tools.ietf.org/html/draft-vixie-dnsext-dns0x20-00 if you use pfsense to forward your DNS queries
you could also try making your own DNS server and using the authoritative servers instead, but that's kind of bad manners imo

I'm using opennic on my own homeserver

Cos I can't put 1.1.1.1 into my dns settings on Android

retard

Takes one to know one

My custom rom uses 1.1.1.1 instead of Google's 8.8.8.8

it's under advanced, you have to turn on manual configuration iirc. cloudflare also hawks an app for it
this is cool but unfortunately i get high latency to it

I'm using adguard's dns

But I DO use AdGuard DNS, you pathetic non-paid shill.

>can't you just a set a fallback DNS?
Fallback DNS doesn't work because it loads a Cloudflare error page rather than failing to connect at all

Indeed. A lot of talk about DNSs here but nobody mentions dnscrypt. Same goes for a lot of topics on Jow Forums. It's on reddit level.

their websites/links are broken af and do they really need a wiki for 2 pages

that's really strange. i have cloudflare
and archive.is loads fine for me. picrel are my DNS settings on my resolver
i use dns over tls on my resolver box, and apparently [tenta.com/blog/post/2017/12/dns-over-tls-vs-dnscrypt] that's better for privacy

why don't you, user?

Attached: 00192.png (397x267, 15K)

Because it is said to steal some of your data although its still a speculation

you can't steal data, you can only copy and aggregate it. theft means you're depriving someone else of something.

you're thinking of cloudflare

Because I use my own

For me it's quad9 over https

based

github.com/bhanupratapys/dnswarden

Thank me later

just write one.one.one.one
but I don't suggest you to use it, use adblock-dot.dnswarden.com instead. yes, type that on your android's dns address. Also don't be a brainlet next time.

>Secure

Is DNS over HTTPS a meme? I've seen people recommend against that. Been using quad9.

Yes, your ISP still knows which sites you visit. HTTPS already does the job.

it closes off one very common avenue for ISP spying and censorship. They can still sniff SNI though. ESNI will solve this but isn't yet widely deployed.

some people say that HTTP is bloat and port 443 shouldn't be overloaded like that, if you're sympathetic to this thought but still want your DNS queries encrypted there's DNS over TLS. Several resolvers support both (which is easy since they use different ports)

This looks kinda good, I'll give it a try, thanks user.

Same reasons as and .
I use Quad9.

I'm using DNS-over-HTTPS with quad9. see quad9.net/faq/#Does_Quad9_support_doh

in firefox you can just set:
network.trr.uri = dns.quad9.net/dns-query
network.trr.bootstrapAddress = 9.9.9.9
network.trr.mode = 3
and it should work.

Isn't trr mode 2 recommended over 3?

2 falls back to unsecure if trr doesn't work. 3 doesn't.
safety vs usability.

I use DNS over TLS with stubby.

This. Just run Unbound on your router and query those root servers.