6 ms·
re: "One way less for Google to track me." Google says that they don't use Google DNS for tracking. From the Google DNS privacy page: "We built Google Public
by alec 12y ago
re: "One way less for Google to track me."
Google says that they don't use Google DNS for tracking.
From the Google DNS privacy page: "We built Google Public DNS to make the web faster and to retain as little information about usage as we could, while still being able to detect and fix problems. Google Public DNS does not permanently store personally identifiable information."
They go on in some detail to say how and what they log.
https://developers.google.com/speed/public-dns/privacy https://developers.google.com/speed/public-dns/privacy
- mschuster91 12y agoBut you can bet that at least the NSA and 3-letter-agencies around the world do monitor anything going to or coming from these two IPs. It's just a too convenient target. More distributed resolvers (like with Cloudflare/Amazon datacenters directly linked to ISPs) would make this type of spying orders of magnitude harder (they must actively infiltrate the ISPs network instead of just tapping the DECIX/exchange switches, which e.g. German BND is ALLOWED to do!). Shit, I'd pay for Cloudflare or any other service to build robust, interception-secured DNS servers. Or my provider, but providers have a shameful track record of building fast and reliable DNS servers.
- maxerickson 12y agoWhy would they track Google and then ignore other large DNS servers?
- mschuster91 12y agoGoogle is by far the largest public one, next to OpenDNS. The rest are provider DNS servers, which can't be tracked that easily (NSLs and other "pseudolegal" stuff aside). It is a shame that the Internet has descended from a place where everyone could implicitly trust everyone into a hellhole of spammers, hackers, spooks and other retards. One cannot even trust that private two-way communication STAYS private because our own fucking governments have done everything to erode that trust. It is bad times that one can trust Google to keep your data half-way safe, but your government not. It should be just the other way around!
- maxerickson 12y agoI think I got confused and thought you were thinking of switching to OpenDNS for the NSA and not Google.
- stuki 12y agoIt's not "our own" government, for any "our own" that purports to include me. It is a junta with enough guns to have their way with people across a continent. Pretending otherwise may sound "non extremist" and "responsible", but it's still ridiculously naive and bound to lead to nothing but disappointment. In ever increasing doses. Practically, a good start is to recognize that not all valuable communication mechanisms benefit all that much from minimizing latency of packet delivery. IOW, not all, in fact not even most, means of communication really need the kind of "apparently real time" performance that telephony requires. Moving services that don't, to a protocol where the focus is on making mixing and anonymizing simple, reliable and robust; rather than simply max throughput and min latency, would make end user security and anonymity guarantees much easier to make. And, for many types of channels, this can be done without much at all in the way of negative side effects, given how fast the underlying switching infrastructure has gotten. Current protocols were necessary for any kind of usability when hardware was slow and expensive. And good enough privacy and security vise, when even the NSA didn't really have the means to do much wide net spying at the network level. But neither of those realities of the original internet is true anymore. Instead, sorry for the pompousness, the new environment is so different as to require, or at least recommend, something almost akin to a "new internet." Built with the "new" threats to communication in mind. I'm not working anywhere, at a startup nor anywhere else, that could conceivably "profit" from any of the above ramble. If what I'm saying makes no sense, it's because I'm a moron (or at least misinformed), not because I'm a scumbag.
- mschuster91 12y ago> It's not "our own" government, for any "our own" that purports to include me. It is a junta with enough guns to have their way with people across a continent. Virtually all governments spy on their and other countries' citizens these days, not just the US. We Germans spy, the Brits and the rest of Five Eyes spy, the Russians spy, the Chinese spy, the Iranians spy and I bet that even North Korea has quite some good hackers. And for the rest of your comments: indeed, a "new internet" would be required. But as you can see on the adoption rate of IPv6, we're stuck with this mess unless quantum computing forces us to switch.
- davidu 12y agoWe support DNSCrypt which will encrypt your DNS traffic between you and us. That's the last mile, at least. We support DNSCurve for the other hops, but almost nobody else does.
- bodski 12y agoHow about DNSCurve for traffic between you and us? (client requests). That'd be nice!
- davidu 12y agoDNSCrypt meets this need and is based on the same crypto from DJB. If you're running a full-blown resolver, I'm not sure if DNSCurve works if you forward to us... I'd have to find out.
- blueskin_ 12y agoThat's probably enough for most uses, as the unencrypted queries entering the cache are mixed with millions of other people's. Myself, I'm still wary of providing data to any third party. Maybe it isn't the case any more, but at least recently, OpenDNS stored identifiable logs forever and potentially resold that data.
- jemfinch 12y ago> More distributed resolvers (like with Cloudflare/Amazon datacenters directly linked to ISPs) Cloudflare has 24 datacenters[0]. Google Public DNS is deployed in 45 peering points over at least 16 metros[1]. I would be very surprised if Cloudflare/Amazon were more distributed than Google in this regard. [0] https://www.cloudflare.com/network-map https://www.cloudflare.com/network-map [1] https://developers.google.com/speed/public-dns/faq#locations https://developers.google.com/speed/public-dns/faq#locations
- nilved 12y agoThey go on to contradict themselves. Google Public DNS does not permanently store personally identifiable information except for there 20 things:
- asdfaoeu 12y agoUnless you happen to own an as number I don't see how that info is personally identifiable.
- bigbugbag 12y agoWhy exactly should we believe anything google says ? It's unverifiable and they don't exactly have a clean record. I wouldn't take their word for it, specifically for something privacy related.
- blueskin_ 12y agoGoogle say a lot of things. If you believe them, I have a bridge I can sell you.