Shutting down our public encrypted DNS

271 points - yesterday at 6:50 PM

Source

Comments

pbhjpbhj yesterday at 7:03 PM
>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead.

Brilliant.

mentalgear yesterday at 7:53 PM
I'm always wondering whether those centralized privacy services are not the easiest first target for three-letter-agencies to infiltrate to gain access to the most relevant users to track - and what currently would prevent them from doing so if they haven't already ? Maybe, as with the case of many TOR nodes , they might be running them.
iamnothere yesterday at 8:08 PM
Quad9 is a reasonable choice given the stance on privacy and the similar jurisdiction (Mullvad would probably face the same takedown orders as Quad9), but really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver. Unbound is a great choice.

Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Your resolver’s DNS queries could be piped through Mullvad or Tor if you want additional privacy.

david_shaw yesterday at 10:53 PM
It's not that I don't trust Quad9 or dns.sb or any of the others, it's just that I trust Mullvad more.

Sad to see this going away, but I assume this is so Mullvad can focus on their primary services.

ianmurrays yesterday at 7:34 PM
Does anyone know of good alternatives that also block ads? Seems Quad9 doesn't.
1vuio0pswjnm7 yesterday at 7:36 PM
These was one of the fastest DoH services for pipelined queries over single TCP connection

IME, it was much faster than Quad9 for this purpose

First Mullvad shuts down its Google search proxy

Now its DoH service

What's next

drnick1 yesterday at 9:28 PM
> Running a privacy-focused public DNS service is a highly specialized undertaking

This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].

[0] https://github.com/hagezi/dns-blocklists

0dayz today at 1:20 AM
That's a shame, even if I remember their DNS service being a bit unstable (it would at various points not be able to resolve or flat out it was down).
0xbadcafebee yesterday at 10:11 PM
The old heads out there might remember a time when, rather than everyone using one service provider (ex. for Linux binaries/source), we all mutually agreed to use independently run mirrors closer to us. We sort of had to because of bandwidth and latency limits. But it meant that there were a thousand different people providing the same service. Impossible to censor everyone, everyone shares the load, too many places to hack if you wanted to massively compromise, and the users won.

DNS is harder to do that way because it's hard to have limits on DNS. Perhaps DNS could be adapted with QUIC, to allow fast, encrypted DNS that's easier to rate-limit, and then it'd be easier for average people to run public mirrors with limits.

em-bee yesterday at 7:06 PM
disappointing, because alternatives matter too. quad9 and other well known servers are potentially blocked by some countries, so the more lesser known services there are the better.
nullmatrix yesterday at 7:40 PM
Their founder supports Nazis.
deleted yesterday at 9:26 PM
deleted yesterday at 7:20 PM
colincowardly today at 12:38 AM
[dead]