nixCraft, (edited )
@nixCraft@mastodon.social avatar

Poll: Are you encrypting DNS traffic using protocols such as DoT (DNS over TLS) or DoH (DNS over HTTPS)?

in_sympathy,
@in_sympathy@mastodon.social avatar

@nixCraft btw does anyone know a good tutorial on setting an encrypted dns on a raspberry pi?

JMillz269,
@JMillz269@mastodon.social avatar

@nixCraft Yup. Using DoQ.

schenklklopfer,
@schenklklopfer@chaos.social avatar

@nixCraft there is still no official Support for this in . So, no. Nothing.

stephengentle,
@stephengentle@ioc.exchange avatar

@nixCraft I want to at home for sure, unfortunately the Ubiquiti EdgeRouter doesn’t support it out of the box without all sorts of hacks and it’s not getting any new feature updates anymore… For work we tend to run our own recursive resolver so it’s not (yet) an option.

nixCraft,
@nixCraft@mastodon.social avatar

@stephengentle Get a Raspberry PI or another low-cost computer. Install the dnscrypt-proxy/stubby and configre the DHCP server to use that as a DNS server. problem solved.

tbroyer,
@tbroyer@piaille.fr avatar

@nixCraft @stephengentle That's exactly what I did (also installed pi-hole, so pi-hole is the DNS server pushed through DHCP, and it uses the dnscrypt-proxy as upstream, that then uses DNS-over-? I don't remember what kind of encrypted protocol is used 🫣)

fijxu, (edited )
@fijxu@noc.social avatar

@nixCraft DNS-over-QUIC using dnsproxy.

DNS over TLS is way too slow and DNS over HTTPS is also slow and it requires a Web Server running, way too many layers for a simple secure DNS server. Thanks TCP.

EDIT: Oh, and if you have slow internet, it will be way worse because the latency is increased like x10 more lol

CodingThunder,
@CodingThunder@mastodon.social avatar

@fijxu @nixCraft I wish systemd-resolved supported DoQ and DoH! Also it's DNSSEC has given me more problems than any gains

nixCraft,
@nixCraft@mastodon.social avatar
fijxu,
@fijxu@noc.social avatar

@nixCraft @CodingThunder

That is what @CodingThunder said, it supports DoT but not DoH nor DoQ lmao.

CodingThunder,
@CodingThunder@mastodon.social avatar

@nixCraft @fijxu Yes I already use it, thanks! But I would definitely like to try DoQ and DoH

fijxu,
@fijxu@noc.social avatar

@CodingThunder @nixCraft

If you want to use DoQ (which is the most appropriate one IMO because it uses UDP and response time is very close to just using Normal DNS without encryption) use https://github.com/AdguardTeam/dnsproxy , it's very simple, there is also RouteDNS but it's way to advanced and more appropriate for servers because of it's extended configuration.

nixCraft,
@nixCraft@mastodon.social avatar

A straightforward method to determine whether you are using DoT/DoH is to visit https://1.1.1.1/help this page. Of course, you can use CLI too.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • modclub
  • DreamBathrooms
  • osvaldo12
  • GTA5RPClips
  • ngwrru68w68
  • magazineikmin
  • everett
  • Youngstown
  • slotface
  • rosin
  • mdbf
  • kavyap
  • tacticalgear
  • InstantRegret
  • JUstTest
  • Durango
  • cubers
  • khanakhh
  • ethstaker
  • thenastyranch
  • normalnudes
  • provamag3
  • tester
  • cisconetworking
  • Leos
  • megavids
  • anitta
  • lostlight
  • All magazines