Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who? Honest question




Myself, I suppose? Recursive resolvers are low-maintenance, and you get less exposure to ISP censorship (which "developed" countries also do).

Realistically, either you ignore the privacy concerns and set up routing to multiple providers preferring the fastest, or you go all-in on privacy and route DNS over Tor over bridge.

Although, perhaps, having an external VPS with a dns proxy could be a good middle ground?


If you're the technical type you can run Unbound locally (even on Windows) and let it forward queries with DoT. No need for neither Tor nor running your own external resolver.

Middle ground is ISP DNS, right?

If privacy is your primary concern I would 100% trust Cloudflare or Google over an ISP in the US

I’m in the Netherlands.

Quad9, dns0.

Google is serving you ads, CF isn’t.

And it’s not conspiracy theory - it was very suspicious when we did some testing on small, aware group. The traffic didn’t look like being handled anonymously at Google side


Unless the privacy policy changed recently, Google shouldn't be doing anything nefarious with 8.8.8.8 DNS queries.

Yeah it's not like they have a long track record of being caught red-handed stepping all over privacy regulations and snarfing up user activity data across their entire range of free products...

They weren't supposed to do anything with our gmail data as well. That didn't stop them.

[citation needed]

Read their TOS.

If it’s in the ToS, then it’s not true that “[they] weren't supposed to do anything with our gmail data”.

CF breaks half the web with their awful challenges that fail in many non-mainstream browsers (even ones based on chromium).



Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: