An open DNS recursive service for free security and high privacy
68 points - yesterday at 8:13 PM
SourceComments
Habgdnv yesterday at 9:50 PM
Just a quick note for the unsuspecting:
I run two local DNSes, one recursive and one forwarding.
The forwarding one uses few services, like 1.1.1.1, 8.8.8.8, 9.9.9.9, etc.
One day I noticed inconsistent responses and started investigating. Turns out that by default 9.9.9.9 have "protection" and for your safety will lie and return NXDOMAIN or something else, for some dangerous domains, taking into account their definition of "dangerous". I am not saying that this is bad, probably lots of non-HN people don't want to run their DNS or anything related and just want a tablet that works because they don't even have laptop. It just hit me hard because I did not expected filtering on these servers.
greyface- yesterday at 8:49 PM
Sending every single query to a centralized third party is hard to square with "high privacy". I prefer to run my own local recursive resolver.
LeoPanthera today at 1:10 AM
In California, from Xfinity Cable, Google’s DNS consistently has the lowest latency.
From AT&T fiber, Cloudflare’s 1.1.1.1 is always the fastest, though Quad9 is a very close second.
It’s interesting that it’s different from different ISPs.
Cider9986 yesterday at 10:49 PM
quad9 is recommended by Privacy Guides. There's also other recommendations.
Linserin yesterday at 11:55 PM
Quad9 DNS sometimes returns a CDN node with obviously slower response and higher delay, so I have rarely used it since then.
annoyingnoob yesterday at 8:42 PM
I tried Quad9 at our business for a while, about a year. I ended up moving to something else due to latency. I'm not sure if it was a routing issue or what but there were a lot of timeouts and slow responses. I have not had these issues with other providers.
woadwarrior01 today at 12:51 AM
What are the odds that it's a honeypot?
siramikvarze yesterday at 8:45 PM
[dead]