Brilliant.
Shutting down our public encrypted DNS (mullvad.net)
pbhjpbhj 10 hours ago
pbhjpbhj 10 hours ago
>Since Quad9 already performs DNSSEC validation, DNSSEC being enabled in the forwarder will cause a duplication of the DNSSEC process, significantly reducing performance and potentially causing false BOGUS responses.
This sounds dodgy. Surely that means Quad9 can poison my DNS?
Arainach 10 hours ago
What's the specific threat you're envisioning? If it involves Quad9 themselves being malicious, what would DNSSEC on the forwarding prevent?
This page explains how all of this works in detail: https://quad9.net/news/blog/quad9-enables-dnssec-on-all-serv...
zamadatix 9 hours ago
I've always been of two minds on this. On one hand, that concern is beyond any reasonable level of security/performance/reliability tradeoff for most any user. At the same time, it is a bit of a shame DNS doesn't have a more scalable & performant approach to security which can just always be done without having to consider it a tradeoff, however minor in practice.
justsomehnguy 6 hours ago
zamadatix 2 hours ago
1. The forwarder gets a response claiming the record is supposed to be DNNSEC signed from the parent (recursively traversing from the root). The forwarder checks the signature of this claim. If the signature is valid, the forwarder continues on to validate the signature of the record and checks its validity to know if the info was secure. If the signature is invalid, the forwarder knows any information any information is not able to be validated as secure
- Somewhere during the recursive checks through the root, the forwarder gets an unsigned (no DNSSEC) or invalidly signed (e.g. your stripped response) response. The forwarder knows any information is not able to be validated as secure.
- A claim for lack of configuration or support of DNSSEC records comes back. The forwarder knows any information is not able to be validated as secure.
So you always know whether or not the information was secure, it's just if it was insecure you don't know if it's because it was just never secured or if someone tried to tamper with it. And that should make sense, an insecure message is by definition one which you can't tell if it has been tampered with.
tptacek 4 hours ago
To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a reason why DoH took off instead.
QDwQ1 3 hours ago
What? I don't see how you can call that a flaw in DNSSEC when DoH is no better in this regard; it doesn't even attempt to protect against a malicious recursive resolver. The only way to do that is to validate DNSSEC on the client.
tptacek 3 hours ago
joveian an hour ago
thenewnewguy 8 hours ago
usr1106 3 hours ago
Haven't had time to study the bug and really understand the whole issue myself. Just left it there with the takeaway that local validation is currently not for non-experts.
(Sorry not at my computer. Details rather vague from memory.)
seany 10 hours ago
oofdere 9 hours ago
1970-01-01 9 hours ago
cortesoft 8 hours ago
LetsGetTechnicl 8 hours ago
vardalab 5 hours ago
ornornor 8 hours ago
Maybe it’s time to try nym.com?
ripdog 8 hours ago
sgc 8 hours ago
Brybry 8 hours ago
godelski 5 hours ago
If you're on an iPhone, uBlock is now supported: https://apps.apple.com/us/app/ublock-origin-lite/id674534269...
There's also Orion browser, but I found it to be a bit more glitchy, especially around sites like YouTube (fuck the app, I'm not watching videos there): https://orionbrowser.com/
oofdere 5 hours ago
windexh8er 2 hours ago
godelski 2 hours ago
Look, I still run AdGuard on my router, but it's not the same thing
Brybry 5 hours ago
I could also use a VPN to keep my phone always on my home network and thus behind my own ad blocking DNS but Mullvad's adblocking DNS was really nice and convenient.
godelski 2 hours ago
For example, DNS blocking isn't going to block YouTube ads if you're using the app since they don't need to respect your DNS, but it will if you're in browser because they can't control that.
For apps I always use revanced.
Denatonium 4 hours ago
godelski 2 hours ago
I'm on your side but telling people to buy a new phone doesn't solve their problem. Short of that uBlock and/or Orion are their best options
godelski 5 hours ago
> That's something people should run themselves. I run Adguard Home on my router.
I'll second this. People should really be flashing their routers. OpenWRT is simple enough that if you're on HN I think you'll easily be able to do it. And like most routers, you set it up and forget it.But you'll also get a bunch more benefits from OpenWRT, to make it worth your while.
- I was able to buy a router for <$100 that was WiFi 7 capable (W1700K[0]) and had better hardware than most consumer routers. You can find plenty of cheaper routers that are flashable and more capable.
- Adguard Home
- Split tunneling/VLANs: Since we're talking Mullvad, you can put devices behind Mullvad on a VLAN. So activate Mullvad by changing SSIDs.
- Trivial to put IOT devices on a VLAN (can make one directional too so you can access from your main network but they can't reach back. I throttle everything IOT)
- Tailscale
- QoS (Control the speed and prioritization of different connections)
- It's a fucking computer, you can even run shell scripts
[0] You don't need something like this unless you're getting >1Gbps from your ISP. Big thing I wanted is the 2 10G ports.oofdere 5 hours ago
XenoCyber0 3 hours ago
PhageGenerator 2 hours ago
Setting up a local resolver, such as a Pi-Hole or Unbound on a firewall can serve unencrypted responses to your devices. Those resolvers in turn can use DoT/DoH with their upstream resolvers to encrypt the requests that go through untrusted networks on the Internet.
This is the best of both worlds, the simplicity of unencrypted DNS while encrypting traffic where it matters.
zormino 6 hours ago
assumed_throwaw 9 hours ago
[1] https://quad9.net/news/blog/italian-blocking-demands-followi...
loup-vaillant 8 hours ago
Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.
jwitthuhn 8 hours ago
loup-vaillant 7 hours ago
Henchman21 4 hours ago
jMyles 4 hours ago
It'd be great for this to be the first major relinquishment of nation-state power to happen without violence, without backroom deals, without wedge politics and flag waving.
Just... let it go.
It's beyond obvious that copyright is not going to exist in 1000 years. Every creature on earth - especially the internet - survives by copying information. It's the most basic life force in the universe.
Copyright is serving exactly nobody today. It's time. Are there elder stateswo/men in the room who can see the writing on the wall and act with grace?
otterley 3 hours ago
Except for nearly everyone who writes anything (including software) or other artistic pursuits to make a living. This includes a majority of people here on HN.
cannonpr 3 hours ago
otterley 3 hours ago
denkmoon 2 hours ago
Modern IP law inhibits productivity more than it helps, imo. LLMs have fundamentally changed our line of work, and they have done so by completely ignoring the existing legal framework for IP. We should not defend the current implementation just because some people might suffer reduced earning potential.
otterley 2 hours ago
ekianjo 39 minutes ago
If you look at outcomes it has completely failed while making big corps very rich in the process
furyofantares 8 minutes ago
And outside open source there has been a staggering amount of creative work at all quality levels done for commercial purposes under the protection of copyright. Is there a convincing argument that the last century of software and music and books and etc would have been just as staggering without copyright?
I would love to hear such an argument. In my youth I thought copyright was blatantly stupid and should be abolished. I still sorta think that but I don't have a convincing argument in the face of the absolutely massive amount of good work that has been produced under it.
ekianjo 40 minutes ago
bruce511 41 minutes ago
Are you sure about that?
So just to be clear;
You're advocating for the end of software licensing? Ie the removal of GPL or Open Source licenses? A landscape where any source code (or binary) can be snapped up by say Amazon or Microsoft and run via a paid subscription?
You're advocating for a business model which removes your access to local code and only allows access via a terminal or browser?
Because removal of copyright doesn't mean corporations go away. Rather it incentivizes business models that protect their products in other ways.
In the 80's and 90's, pre-internet, binary programs were distributed on media. An arms race of copiers and copy protection ensued. The copiers won, and since copyright enforcement has always been weak, business changed to favoring remote access (with subscription) over running locally via purchase.
At the same time Open Source and Free Software have thrived. Copyright protects that software being used outside the terms of the license. Indeed there's even outrage when it's used within the terms of the license (by AWS etc.)
Of course OSS still thrives under a copyrightless environment. (Free Software less so). But equally it means AI can simply be trained on it (probably no great loss since it's likely most of OSS will be AI generated anyway.)
Business however will adapt. And the easiest way to prevent coping now is simply remote execution. With a suitable Terms Of Use declaration.
Outside of software it would destroy music, movies, books etc. Basically it becomes a race to the bottom in terms of production costs (think user-generated You-Tube as the high-water mark.) But I assume you meant in the context of software.
Yes, I agree, that in much less than 1000 years copyright is dead. Because by then so much is in the public domain it doesn't matter anyway. Also because by then the last human programmer is long dead. AI will write anything you want, only you won't even ask because computer interfaces and abilities will be long past where we are now. You would have no need to create software any more than you need to build a plane or car today.
And those industries have taken less than 150 years to invent, explode, consolidate and commoditize. Indeed most of the complexity disappears when we go EV.
In 1000 years copyright is gone. But today it serves a lot of people.
sparkling 8 hours ago
Trivial to do nowadays: https://focsec.com/
>I really don't like where this is going.
German courts think the internet revolves around German laws. There are some really insane cases, sometimes they will consider a website to fall under German jurisdiction simply for having a German-language version (somehow ignoring that Austria and Switzerland exist, ignoring German-speaking minorities in other countries, ignoring that a fully automated translation in 100+ languages is now possible at the click of a button).
mikestorrent 5 hours ago
p-e-w 5 hours ago
zmgsabst 5 hours ago
That’s why it’s endorsed by notable Nazi families and collaborators, eg, Soros family and Schwab family.
ahartmetz 4 hours ago
I think he seriously pissed off the right people in Russia who are now throwing whatever shit they can think of at the wall, and some of it sticks. They do not try to be consistent at all, anything that will convince someone is fine.
ahartmetz 4 hours ago
p-e-w 2 hours ago
panarky 30 minutes ago
Calling a solidly democratic nation "fascist" is a rhetorical reversal straight out of the authoritarian playbook.
antonkochubey 14 minutes ago
thi2 4 hours ago
numpad0 2 hours ago
That kind of thing isn't unheard of for police agencies with moral and oversight issues, though. Orgs start seeking for bigger reasons. A simple copyright issue creatively expounded into an imaginary global drug bombing cyber trafficking crime ring takedown creates a massive internal win. So they do that.
mentalgear 9 hours ago
ajjahs 9 hours ago
they arent gods. some people actually have moral standards and dont just do whatever a foreign agency wants them to do
greyface- 8 hours ago
tancop 8 hours ago
Big tech services are less private than you think but almost every provider who cares about privacy is safer than you expect. Most of the people who work there are committed to their mission, and if they ever get a gag order someone will leak it in no time because they know exactly how to do it without exposing their identity.
greyface- 7 hours ago
mrtesthah 7 hours ago
greyface- 6 hours ago
radicaldreamer 7 hours ago
When it’s a hostile environment entirely, they hack and do secret operations and bribe.
pocksuppet 2 hours ago
autoexec 9 hours ago
Use an online service that's new enough and small enough and it might not be compromised, but the moment it gets popular men with guns and national security letters with gag orders will show up to install hardware on their prem, take over entire offices, or just demand reports.
VPNs and secure DNS services aren't there to keep your data from the NSA, ICE, or even the police. They are useful for keeping your ISP from selling your browsing history to anyone willing to pay them (https://www.mitnicksecurity.com/in-the-news/republicans-just...). It'll help keep a little of what you do online away from data brokers, keep your ISP from sending you DMCA notices, and not much else.
morserer 7 hours ago
However, it's not at all the reality of a vast swath of other countries (or, at least, not yet; see Chat Control v2). The US is particularly foul (and effective) when it comes to this practice, but anything outside of US jurisdiction that doesn't have an office in the US can't be touched by laws like these, and the laws of most other countries tend to be significantly less invasive than American ones when it comes to data interception and the practices surrounding it.
iknowstuff 18 minutes ago
iamnothere 9 hours ago
Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Your resolver’s DNS queries could be piped through Mullvad or Tor if you want additional privacy.
david_shaw 6 hours ago
Sad to see this going away, but I assume this is so Mullvad can focus on their primary services.
ianmurrays 9 hours ago
mgrunwald_ 9 hours ago
SamDc73 9 hours ago
https://adguard-dns.io/kb/general/dns-providers/ have a list of options that some of them have ad blocker
Dezvous 9 hours ago
ornornor 8 hours ago
gmac 6 hours ago
hexfish 9 hours ago
mikalauskas an hour ago
brettdav 9 hours ago
1.1.1.2
1.0.0.2
2606:4700:4700::1112
2606:4700:4700::1002koeliga 9 hours ago
rdme 9 hours ago
brnt 3 hours ago
leumon 9 hours ago
sparkling 8 hours ago
ripdog 8 hours ago
Trivial to self-host, and gives you full control of blocking.
immortalist 7 hours ago
1vuio0pswjnm7 9 hours ago
IME, it was much faster than Quad9 for this purpose
First Mullvad shuts down its Google search proxy
Now its DoH service
What's next
kennethrc 9 hours ago
ornornor 8 hours ago
RamRodification 8 hours ago
erxam 8 hours ago
UltraSane 7 hours ago
Denatonium 4 hours ago
ZeWaka 39 minutes ago
stutstev 8 hours ago
I say this respectfully, but Mullvad is perhaps “dumbing down” their VPN service in an effort to simplify their operations and cater to a wider and more general audience.
1vuio0pswjnm7 6 hours ago
Discontinued
omcnoe 2 hours ago
drnick1 8 hours ago
This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].
pprotas 7 hours ago
drnick1 7 hours ago
morserer 7 hours ago
I'm sure that the time, effort, money, and exposure that goes into responding and adhering to legal requests for a publicly offered service is something Mullvad wasn't expecting and would rather not be doing considering it's not their core focus.
anvuong 7 hours ago
ApolloFortyNine 6 hours ago
This dude has been doing it for 25 years, and actually this is a dns provider for domain names which I'm decently sure makes it more complicated than public dns.
They're allowed to say they don't want to pay for it anymore, I just think their logic is bad. Or maybe their lawyer said they're running risks just ignoring takedown and they didn't want to deal with it anymore.
blahlabs 4 hours ago
Can you expand on this? Isn't all DNS for domain names?
pocksuppet 2 hours ago
Hey dang can I get my rate limit removed yet?
SirSavary 7 hours ago
0dayz 4 hours ago
0xbadcafebee 7 hours ago
DNS is harder to do that way because it's hard to have limits on DNS. Perhaps DNS could be adapted with QUIC, to allow fast, encrypted DNS that's easier to rate-limit, and then it'd be easier for average people to run public mirrors with limits.
em-bee 10 hours ago
DemiGuru 10 hours ago
prmoustache 7 hours ago
This is probably service you can host locally with the lowest maintenance and hardware requirements so it isn't even a hassle to do it yourself.
nullmatrix 9 hours ago
erxam 8 hours ago
mschuster91 8 hours ago
(Next time, might be worth to add a source yourself to prevent downvotes)
[1] https://www.reddit.com/r/ProtonMail/comments/1uivm45/mullvad...
iamnothere 7 hours ago
If you aren’t familiar with splits inside Marxism-Leninism, the “left” is most often represented by Trotskyism with the “right” tendency being more like Stalinism and North Korean Juche. (Note that these left/right terms aren’t universally used or applied because every faction claims to be correct.)
mschuster91 7 hours ago
> In its political program for the 2026 Swedish general election the Örebro Party writes that they want to "stop the ongoing population replacement" and make Sweden a monocultural society, rather than a multicultural one. The party also writes that this "will be a Sweden where ethnic Swedes are once again the clear majority."
In particular, the "population replacement" is the most clear sign. That's as antisemitic and far-right as it gets [2].
[1] https://en.wikipedia.org/wiki/%C3%96rebro_Party#Immigration_...
[2] https://en.wikipedia.org/wiki/Great_Replacement_conspiracy_t...
iamnothere 7 hours ago
Btw, Malcom Kyeyune, who has a podcast with the party’s founder, is a black child of an immigrant, adopts an avatar on Twitter of Kim Jong Un’s sister, and semi-ironically stans for North Korea on a regular basis.
pocksuppet 2 hours ago
iamnothere an hour ago
csb6 7 hours ago
PufPufPuf 8 hours ago
snatekay 7 hours ago
MrDOS 7 hours ago
[0]: https://www.flamman.se/techprofil-ger-miljoner-till-orebropa...
pocksuppet 2 hours ago
Eufrat an hour ago
vlyan an hour ago
is there a single party in Europe campaigning on the promise of more immigration, I wonder? if so, how do they fare? :)
betterbeehome 6 minutes ago
This was probably the most ignorant thing I've read today. You're knowledge of political history must not extend very far.