Secure your DNS Queries with Encrypted DNS

Поділитися
Вставка
  • Опубліковано 1 гру 2024

КОМЕНТАРІ • 109

  • @jacobarrowood3587
    @jacobarrowood3587 4 роки тому +176

    Thumbnail game is on point

    • @Maebbie
      @Maebbie 4 роки тому +10

      its gonna be a sad day when he sells out

    • @otistheo7746
      @otistheo7746 3 роки тому +4

      I know Im randomly asking but does anybody know a way to get back into an Instagram account?
      I was stupid lost the login password. I would appreciate any tips you can give me

    • @roasted.cheese
      @roasted.cheese 2 роки тому +13

      @@otistheo7746 try clicking on "reset your password" 😐😐

    • @kubba_x86_64
      @kubba_x86_64 2 роки тому +1

      @@otistheo7746 The best option would be not to go on instagram at all.

  • @darklytravelingboxofficial6622
    @darklytravelingboxofficial6622 4 роки тому +47

    You upload more frequently than all of the linux channels..... my favorite

  • @maxv3286
    @maxv3286 4 роки тому +316

    URLs are bloated just use IPs lol

  • @hedgeearthridge6807
    @hedgeearthridge6807 3 роки тому +12

    Switched off from Cloudflare, switched to encrypted European DNS servers in Germany and Finland. Much better!

    • @JamesQHolden
      @JamesQHolden 2 роки тому +1

      Which server

    • @vc5xf
      @vc5xf 7 місяців тому

      Torille!! 🎉

  • @TheJackiMonster
    @TheJackiMonster 4 роки тому +59

    There is also a possible alternate to DNS in general inside of GNUnet called GNS. But I think it needs more adoption to make practical use of it.

    • @_modiX
      @_modiX 2 роки тому +2

      bring this into the ETH network and it will drive itself, also: aren't you automatically sharing files as a peer when starting the gnunet-arm? I'm not sure what kind of files are going around in that network.

    • @TheJackiMonster
      @TheJackiMonster 2 роки тому +8

      @@_modiX You might share data in the DHT which could be a part of a file. However it is usually encrypted as well.
      I don't think that is worse than hosting a blockchain with files in it which are not encrypted and won't be ever deleted because of the chain concept.

  • @maxim1152
    @maxim1152 3 роки тому +8

    Use application manager if you're not comfortable with the terminal. Then let's vim into this file...

  • @jtnkathuria
    @jtnkathuria 4 роки тому +21

    Thank you.. this is fabulous. but I have a question.. instead of setting DNS IP per device can't I use IP directly in Router settings?

    • @MentalOutlaw
      @MentalOutlaw  4 роки тому +30

      Yes, you can. And that would cause all devices connected to your router to use these DNS settings.

    • @jtnkathuria
      @jtnkathuria 4 роки тому +3

      Thanks.. but what I mean.. in router itself..changing the DNS settings to point to custom DNS provider such as Cloudflare or nextDNS..
      Any ways.. I will try it tomorrow as well to check it out

    • @samtheman1868
      @samtheman1868 Рік тому

      @@jtnkathuria so did it work?

  • @NeoFromMatrix-999
    @NeoFromMatrix-999 4 роки тому +9

    what do u do professionally bruh ? You seem knowledgeable , i have seen a lot of your videos and wondered what can i do more to be like you.

    • @gradientO
      @gradientO 3 роки тому

      Works at a startup

  • @wb3123
    @wb3123 2 роки тому +8

    So I followed all the instructions as best as I could and qname minimization is also enabled on my resolver but when I go and test the encryption on the cloudflare site, I don't pass the "Secure SNI" test. Maybe things have changed since the video was released. Bummer!

  • @wlole1406
    @wlole1406 4 роки тому +8

    Great video as always, thank you.

  • @shredwerd009
    @shredwerd009 2 роки тому +4

    why not just use pihole and unbound in containers on a raspberry pi? (or anything that can run your containers)

  • @Scranny
    @Scranny 3 роки тому +4

    sorry for the newbie question, but why is it not sufficient to configure the new DNS server address in the browser's settings (under "Secure DNS" or "DNS over HTTPS") or is this something different?

  • @springbok4015
    @springbok4015 4 роки тому +4

    Aren’t German data laws quite strict under the EU and GDPR? Would they still be allowed to log your DNS queries?

    • @bob80808
      @bob80808 3 роки тому +1

      (Not fact-checking what I'm saying) Probably, 'cause legally they have to log everything they do. It gets deleted in x amount of time tho, they *should* only use the logs in case some gubernamental force asks for them.

    • @CrisCheese_
      @CrisCheese_ Рік тому

      There is probably some fine print in some privacy policy that has been accepted stating they are allowed to log your data and keep it for x amount of years

  • @danx033
    @danx033 2 роки тому +2

    The picture for Tumblr with the fupa 🤣

  • @scoringdigitsson.5194
    @scoringdigitsson.5194 3 роки тому +3

    but once we visit a website with encrypted dns, isp can still see the websites, hence can log our online activities and sell data to government or 3rd party right? so whats the point?

    • @kinich_
      @kinich_ Рік тому

      They can only see the IP you're connect to at that point
      Although idk if they actively query the matching domain name for that IP
      Maybe it depends on your ISP

  • @TheyWhomTheGodsDetest
    @TheyWhomTheGodsDetest 2 роки тому +1

    Very helpful video. Thank you.

  • @bonkmaykr
    @bonkmaykr 4 роки тому +2

    Another amazing video

  • @victormagro2530
    @victormagro2530 4 місяці тому

    Hello Mental Outlaw, a question; I use Stubby dns on Linux mint, and when using Firefox or LibreWolf after logging in, they do not load, they do not open a first connection; I am forced to go to networks, disconnect and reconnect from the network, and NOW, suddenly they load and I no longer see

  • @mikerollin4073
    @mikerollin4073 2 роки тому +1

    Great stuff as usual

  • @luigitech3169
    @luigitech3169 4 роки тому +7

    Amazing video! Thanks.
    Is there something like that for Android? Is Encrypted DNS only something per computer or is also possible to do for the entire LAN?

    • @RosalioRedPanda
      @RosalioRedPanda 4 роки тому +3

      As far as I know for the LAN you can do this with a pihole. I don't know too much about pihole but I'm pretty sure. Privacytools.io on their DNS page have android options listed.

    • @doomsdaymachiene91
      @doomsdaymachiene91 3 роки тому +1

      set your DNS trough your router directly in the settings, and for the DoH trough your browser configuration.

    • @gradientO
      @gradientO 3 роки тому +1

      DNS over TLS, which is a encrypted option, is available in Android 9 plus versions, search private DNS in settings

  • @Mojo_DK
    @Mojo_DK 3 роки тому +4

    Hey maybe this is a noob question but I would appreciate the help :)
    Does changing my DNS Server actually do anything when I use a VPN or don't I just use the VPN DNS in that case?

    • @richmail
      @richmail 2 роки тому +3

      you use the VPN's DNS server

    • @haveaniceday7950
      @haveaniceday7950 2 роки тому

      @Tux does that effect the privacy or security of vpn in any way?

    • @CrisCheese_
      @CrisCheese_ Рік тому

      ​@haveaniceday7950 the data will be anonymized as they won't have a clue who exactly from the VPN service is using the DNS

  • @haveaniceday7950
    @haveaniceday7950 2 роки тому +1

    What about DNSCloak and quad9?

  • @davidyoder5890
    @davidyoder5890 4 роки тому +3

    The "127 range" is not a loopback. 127.0.0.1 is the loopback address to the localhost.

    • @Sh-ws5jd
      @Sh-ws5jd 2 роки тому +5

      The entire 127.x.x.x is a loopback to your machine. Try pinging a random 127 address

  • @benjaminbrady2385
    @benjaminbrady2385 4 роки тому +2

    Oligopolies of power are just monopolies of power without the bad name :(

  • @jonathanrealman8415
    @jonathanrealman8415 4 роки тому +11

    Anti ADL video, based & redpilled

  • @Bruh-vp6qf
    @Bruh-vp6qf 3 роки тому +1

    Nice and succinct

  • @reddot3893
    @reddot3893 8 місяців тому

    Hey, why encrypt the dns traffic if the requests after are not encrypted, we can just take the IP of the requests and guess the URL. And if we use a VPN to encrypt these packets then the DNS requests are also encrypted by the VPN so a public unencrypted DNS would be enough

    • @evilleader1991
      @evilleader1991 2 місяці тому

      You could use anonymized DNS with dnscrypt

  • @riemannspupil5095
    @riemannspupil5095 4 роки тому +1

    Your thumbnails are like Luke Smith's.

    • @riemannspupil5095
      @riemannspupil5095 4 роки тому

      @Lee Smith don't think Luke even knows this channel exist.

  • @TXPer
    @TXPer 4 роки тому +6

    my isp is blocking custom dns :(

    • @doomsdaymachiene91
      @doomsdaymachiene91 3 роки тому +2

      is that even possible?? host your own DNS server then

    • @TXPer
      @TXPer 3 роки тому +3

      @@doomsdaymachiene91 yes it is possible, they blocking port 53. I thought to host my own dns but first i need to by psu to my secondary pc

    • @martint5340
      @martint5340 3 роки тому +2

      What country are you in? Sounds like a terrible ISP.

    • @TXPer
      @TXPer 3 роки тому

      @@martint5340 Poland

    • @martint5340
      @martint5340 3 роки тому

      @@TXPer damn... that’s bad new for Poland... you can’t change to a more freedom respecting ISP?

  • @MysticMylesZ
    @MysticMylesZ Рік тому

    3:48 I mean they know we visit but do they know who we are 🤔
    Browser info
    Cookies
    Location
    Device info
    Wifi Info
    Login Info
    🤔 am I missing anything?

  • @PepinCZ
    @PepinCZ 4 роки тому +10

    Not really a great way to hide your traffic from your ISP. The ISP can still make up what websites you are connection to solely from the IP addresses, but now you are also giving your DNS query data to a third party.

    • @BurgerKingHarkinian
      @BurgerKingHarkinian 4 роки тому +5

      And if the IP wasn't enough, they can just look into the data that has been transmitted or in case of an TLS connection, they can easily figure it out by looking at the certificate that the server sends to you in the beginning of the connection.

    • @transforgoku
      @transforgoku 3 роки тому +2

      So setting an encrypted DNS is useless if I'm not my own ISP, that's what you're saying?

    • @lksw42439
      @lksw42439 3 роки тому +2

      1) Third party doesn’t have your name, address, etc. 2) This makes it harder and is targeting people that use VPN but leak their DNS.

    • @JamesQHolden
      @JamesQHolden 2 роки тому

      @@zyan983 Which VPN\Proxy?

    • @JamesQHolden
      @JamesQHolden 2 роки тому

      @@lksw42439 that doesn’t make any sense

  • @perplexity000
    @perplexity000 4 роки тому

    09:14 I don't have a DE (I like to live on hard-mode), would I add "nameserver 127.0.0.1" to the /etc/resolv.conf file and comment out what's currently there? could you help me to configure this through the terminal?

    • @vladimirvparfenov3935
      @vladimirvparfenov3935 3 роки тому +1

      if your /etc/resolv.conf isnt managed by anything else, then yeah. put that at the very start. if you use DHCP for network settings it'll typically overwrite your resolv.conf so you have to add a "prepend domain-name-servers 127.0.0.1" into the dhclient configuration.

  • @danarj5713
    @danarj5713 4 роки тому

    what if we used DNS over https will do the same purpose?

  • @VanishingTacos
    @VanishingTacos 8 місяців тому

    I'm my own DNS server 👌

  • @Android-47
    @Android-47 6 місяців тому

    Still a good method in 2024 ?

  • @tesses50
    @tesses50 2 роки тому

    is it ok to have unencrypted on local network

  • @livingcodex9878
    @livingcodex9878 3 роки тому +3

    Er hat Deutsch gesagt. Kommentarsektion erobert.

  • @davidyoder5890
    @davidyoder5890 4 роки тому

    So with qname minimization, DNS queries take exponentially longer... Got it.

    • @davidyoder5890
      @davidyoder5890 4 роки тому

      Why not just use Cloudflare or a DNSSEC service (which Cloudflare also has).

    • @vanquishedcanadian6424
      @vanquishedcanadian6424 2 роки тому

      That means u have to trust cloudfare to not pull glowie spygate bs on u

  • @dr-deep8353
    @dr-deep8353 2 роки тому

    Can you make a Video about DNS ober QUIC?

  • @FlyinZX10R
    @FlyinZX10R Рік тому

    What about using a VPN?

    • @LibreGlider
      @LibreGlider 10 місяців тому

      VPN just moves the problem; instead of your ISP seeing all your traffic, your traffic is now going through a set of servers in another country. Using something like Quad9 combined with Wireguard would be best.

  • @donbolillo3812
    @donbolillo3812 Рік тому

    >that pic to represent tumblr
    LMAO

  • @ocsanik502
    @ocsanik502 3 роки тому +1

    10:12 CloudFair? More like CloudUnfair!

  • @NathanielWyatt
    @NathanielWyatt 2 роки тому

    It is called cloud flare not cloud fair

  • @eldoprano
    @eldoprano 2 роки тому

    Yooo, is that an All The Fallen cap in the thumbnail? 😭

  • @middle_pickup
    @middle_pickup 2 роки тому

    Naughty SPLC "pressuring" Cloudflare. lol

  • @barbyboi
    @barbyboi 3 роки тому +3

    Hello merkel mom

  • @Loucousscousslou
    @Loucousscousslou 4 роки тому +1

    I added NATO public DNS server lulz

  • @devy2
    @devy2 2 роки тому

    3:29 haHa!!! aFunny "sjw" (social justise warior) from 2016 meme!! epic!!!

  • @s9209122222
    @s9209122222 4 роки тому +4

    Too complicated.