Hacker News new | ask | show | jobs
by acidtrucks 3552 days ago
This is great, but google doesn't need to eavesdrop on us when they compel us to use their avenues for our every action.
2 comments

It is optional to use. Just like it's optional to use Googles Dns servers at 8.8.8.8 and 8.8.4.4. The advantage with this is the extra security you get with HTTPS.

Google DNS tends to be one of the fastest DNS servers you can use (just benchmark them against other options). The IPs are anycast, so you will likely be served by the Google data center closest to you.

As for what they log, check it yourself: https://developers.google.com/speed/public-dns/privacy

So, what DNS server do you use? I trust Google's DNS (I use the normal DNS ones, 8.8.8.8 and 8.8.4.4) a lot more than I trust Comcast's DNS servers. I'm sure there are others out there, of course, but 8.8.8.8 is good, reliable, and easily memorized.
I run my own, but then again, I also run my own web and email services. But in my gut, I have the feeling that at some point, Google will become the Internet (or even worse---we have the GoogleNet and FacebookNet and never the twain shall share).

Until then, I'll run my own stuff.

> So, what DNS server do you use?

The chaos computer club runs their own, which happens to answer usually just as fast as Google’s DNS. (And which isn’t subject to censorship, Google’s DNS, like Comcast and most US ISPs, censor several domains of piracy websites, although the domains are still existing in the ICANN database, and are reachable through most other DNS servers)

I use OpenDNS. My home network is setup so that all DNS requests are sent via dnscrypt to OpenDNS. This ensures that Comcast (or whoever) doesn't ever see my DNS traffic and can't muck with it.
Comcast is the one sending you the (unsigned, unencrypted) response packets from 8.8.8.8.

You might as well use the Comcast ones.

Politically it's a lot easier to stop Comcast from altering through-traffic DNS than it is to stop them from lying in DNS responses and calling it pro-user.
And if you use DNS-over-HTTPS to get your answers from Google, Comcast can't modify them.
I use OpenDNS