Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is amusing that in Europe, there is this big DGPR drama playing out about websites embedding resources from US companies. Like Google Fonts, Tweets and Facebook like buttons.

Yet the browser sends each and every website the user visits to a US company.

All in all, I tend to think that it is a net positive.

Downside: Now one US companies gets all my DNS queries. But can they stitch them together? I tend to think they can't easily. And will hopefully not keep enough logs to do so later.

Upside: My ISP and the cafes and hotels I visit do not get the info which websites I visit.

The protection could be made even stronger if the browser would send 5 DNS requests for every IP it needs. So if you visit news.ycombinator.com it additionally sends 4 random hostnames to cloudflare.



Use a non-US DoT or DoH like for example the one provided by the Digitale Gesellschaft [1] in Switzerland.

[1] https://github.com/DigitaleGesellschaft/DNS-Resolver

[2] https://www.digitale-gesellschaft.ch/dns/


> It is amusing that in Europe, there is this big DGPR drama playing out about websites embedding resources from US companies. Like Google Fonts, Tweets and Facebook like buttons.

> Yet the browser sends each and every website the user visits to a US company.

DoH is only enabled by default in a handful of countries, and in each country the default resolver is different. In all cases it's customizable. In no case, is it sending European user's traffic to the US by default.

There are European based resolvers that offer DoH endpoints you can use, one of the better options is Quad9, which is a European company domiciled in Switzerland.

I think your concerns about data jurisdictional issues are overblown considering that Mozilla is being careful to do address them as part of their rollout strategy.


> The protection could be made even stronger if the browser would send 5 DNS requests for every IP it needs. So if you visit news.ycombinator.com it additionally sends 4 random hostnames to cloudflare.

I can’t find it now but forever ago there was a tool/project that more or less did this. It would purposefully flood your history with random entries meant to confuse advertisers.


It was called AdNauseam, I think


AdNauseam still exists AFAICT, actually. It's only in Chrome where Google has classified it as malware and prevents you from installing it


My memory is beyond fuzzy but this sounds and looks correct. Thank you!


> Now one US companies gets all my DNS queries

I mean honestly, Cloudflare probably gets a large chunk of your actual browsing traffic too. Giving them access to my DNS queries seems a pretty low concern to me.


Use uncensoreddns.org or mullvad.net (they offer free DNS, not just VPN).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: