Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Tuesday November 21 2017, @12:59PM   Printer-friendly
from the promise-we-won't-peek dept.

The Global Cyber Alliance has given the world a new free Domain Name Service resolver, and advanced it as offering unusually strong security and privacy features.

The Quad9 DNS service, at 9.9.9.9, not only turns URIs into IP addresses, but also checks them against IBM X-Force's threat intelligence database. Those checks protect agains landing on any of the 40 billion evil sites and images X-Force has found to be dangerous.

The Alliance (GCA) was co-founded by the City of London Police, the District Attorney of New York County and the Center for Internet Security and styled itself "an international, cross-sector effort designed to confront, address, and prevent malicious cyber activity."

[...] The organisation promised that records of user lookups would not be put out to pasture in data farms: "Information about the websites consumers visit, where they live and what device they use are often captured by some DNS services and used for marketing or other purposes", it said. Quad9 won't "store, correlate, or otherwise leverage" personal information.

[...] If you're one of the lucky few whose ISP offers IPv6, there's a Quad9 resolver for you at 2620:fe::fe (the PCH public resolver).

https://www.theregister.co.uk/2017/11/20/quad9_secure_private_dns_resolver/

takyon: Do you want to give the City of London Police control of your DNS?


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Interesting) by edIII on Tuesday November 21 2017, @07:59PM (1 child)

    by edIII (791) on Tuesday November 21 2017, @07:59PM (#599832)

    Windows sucks ass to begin with, but you are far better off running your own recursive DNS server with something like pfsense. I had about 5 or 6 Windows boxes I needed to manage at a relatives home, and instead of trying to manage their hosts files, I just went with stopping the shit at the router. How do you put a hosts file on an embedded device? That's primarily why I decided to do it. Then after hooking it all up, enabling the recursive DNS server, and setting up some adblocking stuff, it was reported that I was even stopping ads on their Kindles, phones, etc.

    That way Windows wasn't responsible and you don't need a super slow box. It's not just a big hosts file either. I had an office machine for graphics and documentation that I loaded up at least 30,000 fonts :) Windows boot time went to something like 10 minutes and the whole box was hilariously slow.

    --
    Technically, lunchtime is at any moment. It's just a wave function.
    Starting Score:    1  point
    Moderation   +1  
       Interesting=1, Total=1
    Extra 'Interesting' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3  
  • (Score: 2) by requerdanos on Thursday November 23 2017, @01:50PM

    by requerdanos (5997) Subscriber Badge on Thursday November 23 2017, @01:50PM (#600652) Journal

    even stopping ads on their Kindles, phones, etc.

    Well, for what it's worth, pi-hole is doing this very well, running on a tricked-out olinuxino lime2.

    Day 3 problem: User complaint I received: "Honey, [my pirate video site] isn't working anymore. Can you take me off that thing?"