>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead.
>Since Quad9 already performs DNSSEC validation, DNSSEC being enabled in the forwarder will cause a duplication of the DNSSEC process, significantly reducing performance and potentially causing false BOGUS responses.
This sounds dodgy. Surely that means Quad9 can poison my DNS?
DNSSEC validation on your forwarder would prevent a maliciously modified record from Quad9 (or others) from being accepted locally - i.e. "Quad9 can poison my DNS".
I've always been of two minds on this. On one hand, that concern is beyond any reasonable level of security/performance/reliability tradeoff for most any user. At the same time, it is a bit of a shame DNS doesn't have a more scalable & performant approach to security which can just always be done without having to consider it a tradeoff, however minor in practice.
You are rely here on the assumption what your resolver already knows what the zone is DNSSEC signed. If your forwarder or resolver strips that information?..
1. The forwarder gets a response claiming the record is supposed to be DNNSEC signed from the parent (recursively traversing from the root). The forwarder checks the signature of this claim. If the signature is valid, the forwarder continues on to validate the signature of the record and checks its validity to know if the info was secure. If the signature is invalid, the forwarder knows any information any information is not able to be validated as secure
- Somewhere during the recursive checks through the root, the forwarder gets an unsigned (no DNSSEC) or invalidly signed (e.g. your stripped response) response. The forwarder knows any information is not able to be validated as secure.
- A claim for lack of configuration or support of DNSSEC records comes back. The forwarder knows any information is not able to be validated as secure.
So you always know whether or not the information was secure, it's just if it was insecure you don't know if it's because it was just never secured or if someone tried to tamper with it. And that should make sense, an insecure message is by definition one which you can't tell if it has been tampered with.
Wait, I must be misunderstanding you, because if you're resolving off Quad9, they can definitely poison your DNSSEC-signed records. Between a stub resolver and a recursor DNSSEC collapses down to a single "yes it was signed" bit in the header.
To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a reason why DoH took off instead.
> To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a reason why DoH took off instead.
What? I don't see how you can call that a flaw in DNSSEC when DoH is no better in this regard; it doesn't even attempt to protect against a malicious recursive resolver. The only way to do that is to validate DNSSEC on the client.
DNSSEC and DoH provide different security services. But to get the benefit of DNSSEC, you need to resolve recursively. DoH works for stub resolvers. That's all I'm saying.
I don't know the details but knot-resolver asks for DS records of the domain being looked up when forwarding to avoid needing to do a full recursive lookup to validate DNSSEC. As I recall from what I've read this works almost everywhere, including Quad9, but not Google DNS due to a bug that they claim to have identified three years ago but haven't fixed. But as I understand it this is not how recursive resolvers validate so it is extra data that the forwarding server needs to request and cache.
Technically yes, in practice the odds your local resolver is validating DNSSEC is slim (and if you're intentionally configured it to do so, switch to a provider that isn't Quad9).
I use Clouldflare DoT and enabled validation in systemd-resolved some time ago. Not because I would be particularly paranoid, but more out of curiosity how it works. I noticed no problems, except for with Atlassian. They use 2 second level domains (at least), one under .com signed and one under .net (unsigned) (IIRC). Most things worked like normal, but some Jira extension stopped working. Turned out that systemd did reject their signed subdomains. Could not figure out whether the rejection was justified or not. When I asked Claude 7 times about it, I also got 7 contradicting answers... Reported to Atlassian support that their signing is incorrect (some delegation missing). To my surprise they replied: Are you using systemd? And gave a bug number that systemd handles validation wrong in their case.
Haven't had time to study the bug and really understand the whole issue myself. Just left it there with the takeaway that local validation is currently not for non-experts.
(Sorry not at my computer. Details rather vague from memory.)
I'm all for supporting quad9; but what if we just disable dnssec instead, it really solves nothing and continued support of it just makes it show up in compliance guides unnecessarily.
This is a very important detail. Adblock in 2026 is necessary and DNS will transparently do a lot of that work for you. It isn't just about lightning fast lookups and five-nines uptime anymore.
I've been loving the Pihole setup I just set up. It uses Quad9 as the upstream provider and then I do all the blocking myself. I used to use NextDNS but this is so much better and free!
Mullvad had adblocking, malware blocking. And they didn’t block websites from governments blacklists in France and Italy. None of these features are available on Quad9.
That's something people should run themselves. I run Adguard Home on my router. Unlike the main Adguard product, Adguard Home is fully FOSS. It's been rock-solid for me, and improves on pi-hole in various ways - like full IPv6 support.
It's probably the software I trust the most on my network to 'just work', and with the local caching I can use slower upstream dns providers and still have sub 1ms average latency (no performance worries by excluding google and cloudflare). I don't use it for dhcp, but it is a good fit that it's available as well. Couldn't be happier.
There's also Orion browser, but I found it to be a bit more glitchy, especially around sites like YouTube (fuck the app, I'm not watching videos there): https://orionbrowser.com/
I've been using NextDNS [0] for a long time. It's worth the price because you can set up all kinds of different blocking profiles and have different ones on different devices, allows you to have overrides for local network items (or internals like on a Tailnet, Pangolin, Wireguard, etc) and a lot more. The ad blocking ends up working so well a lot not only are ads blocked on web pages but it works with some streaming audio ads as well as VoD that has ads injected. Highly recommend.
Yes, I use Firefox on Android with ublock origin, it works great. But using adblocking DNS on your phone will also block most in-app ads which is a big quality of life improvement.
I could also use a VPN to keep my phone always on my home network and thus behind my own ad blocking DNS but Mullvad's adblocking DNS was really nice and convenient.
Really? I never found it effective unless I messed with certs on my phone.
For example, DNS blocking isn't going to block YouTube ads if you're using the app since they don't need to respect your DNS, but it will if you're in browser because they can't control that.
Ads from providers like Google AdMob and AppLovin are blocked. Apps could bundle their own DNS or DoH resolver or use hardcoded static IP addresses but in my experience most do not.
Youtube ads do not get blocked by DNS adblock because Youtube ads are served from the same domains as the content and thus DNS blocking would be counterproductive. I don't think it has anything to do with respecting DNS.
I don't have the Youtube app installed to test but the Internet suggests that at least in 2023 it was very possible to block the Youtube android app (content and all) via DNS, which hints it does not bypass system DNS. [1]
> That's something people should run themselves. I run Adguard Home on my router.
I'll second this. People should really be flashing their routers. OpenWRT is simple enough that if you're on HN I think you'll easily be able to do it. And like most routers, you set it up and forget it.
But you'll also get a bunch more benefits from OpenWRT, to make it worth your while.
- I was able to buy a router for <$100 that was WiFi 7 capable (W1700K[0]) and had better hardware than most consumer routers. You can find plenty of cheaper routers that are flashable and more capable.
- Adguard Home
- Split tunneling/VLANs: Since we're talking Mullvad, you can put devices behind Mullvad on a VLAN. So activate Mullvad by changing SSIDs.
- Trivial to put IOT devices on a VLAN (can make one directional too so you can access from your main network but they can't reach back. I throttle everything IOT)
- Tailscale
- QoS (Control the speed and prioritization of different connections)
- It's a fucking computer, you can even run shell scripts
[0] You don't need something like this unless you're getting >1Gbps from your ISP. Big thing I wanted is the 2 10G ports.
I stopped recommending anything I host myself for those people. When it breaks I'm the support team, and I'd rather not be. NextDNS free tier is what I give them now, takes two minutes, and I never hear about it again.
I'd argue you don't need to run DoT/DoH yourself if it is just for your local network.
Setting up a local resolver, such as a Pi-Hole or Unbound on a firewall can serve unencrypted responses to your devices. Those resolvers in turn can use DoT/DoH with their upstream resolvers to encrypt the requests that go through untrusted networks on the Internet.
This is the best of both worlds, the simplicity of unencrypted DNS while encrypting traffic where it matters.
Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS.
> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders
Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.
The entire point is that it can't be reasonably enforced with any granularity. Rights-holders want it to be like that so a copyright win in a single country means something has to be taken down globally.
Indeed it needs to happen, and even here on HN, it can be difficult for some to admit and acknowledge.
It'd be great for this to be the first major relinquishment of nation-state power to happen without violence, without backroom deals, without wedge politics and flag waving.
Just... let it go.
It's beyond obvious that copyright is not going to exist in 1000 years. Every creature on earth - especially the internet - survives by copying information. It's the most basic life force in the universe.
Copyright is serving exactly nobody today. It's time. Are there elder stateswo/men in the room who can see the writing on the wall and act with grace?
Except for nearly everyone who writes anything (including software) or other artistic pursuits to make a living. This includes a majority of people here on HN.
I’ve written software all my life, copyright has never been relevant to my earnings at all, trade secrets have been to some extent.
Frankly copyright was meant to enable more sharing and benefiting the public domain, instead it’s become a cancer…
yeah I wouldn't be able to put food on the table if my employer didn't have exclusive license to the glue we use to stick together all that open source code we rely on. Which we now generate exclusively using AI, products of which are of unclear copyright status.
Modern IP law inhibits productivity more than it helps, imo. LLMs have fundamentally changed our line of work, and they have done so by completely ignoring the existing legal framework for IP. We should not defend the current implementation just because some people might suffer reduced earning potential.
Copyright was not designed to maximize productivity. It was designed to maximize creativity and inventiveness (or, as stated in the US Constitution, the progress of science and the useful arts).
Linux is a marvel of the world and a large amount of its contributions have been made by people being paid to do so for commercial purposes - and I am not sure that would be true without the GPL. Is there a convincing argument there?
And outside open source there has been a staggering amount of creative work at all quality levels done for commercial purposes under the protection of copyright. Is there a convincing argument that the last century of software and music and books and etc would have been just as staggering without copyright?
I would love to hear such an argument. In my youth I thought copyright was blatantly stupid and should be abolished. I still sorta think that but I don't have a convincing argument in the face of the absolutely massive amount of good work that has been produced under it.
> Is there a convincing argument that the last century of software and music and books and etc would have been just as staggering without copyright?
> I would love to hear such an argument.
Fortunately, one of the many tentacles of the octopus most obviously at the forefront of the zeitgeist of the freedom that arises from a culture of free information - The Grateful Dead - had the outcome of producing - in the form of gripping autobiography - an extremely compelling, and seemingly utterly true and beautiful and good, instrument to fulfill your request:
Unfortunately that will happen irrespective of the law.
If you want permissive rules then corporations will just resell your IP (like we see with SaaS). And if you want tighter rules then you just create a higher barrier for entry that benefits corporations rather than independent entities.
Either way, it’s easier to operate when you already have a leading position.
Most hackers here are not relying on copyright to make their living. Either you work on open source but make your living off services on top of the code, or your code is a trade secret protected via contracts.
Not to mention that everyone using coding agents probably aren't even protected by copyright in the first place, at least in the US, since the courts are taking a pretty hard line on human authorship being required...
"your code is a trade secret protected via contracts" isn't enough to replace copyright because the contracts are only enforceable to the signing parties.
Let's say you write some software for your employer and they sell the product to several customers with a contract not to distribute it. However, the product appears on some pirate website anyway, and you can't identify who allowed the product to be leaked. Once it's there, your contracts are worthless as nobody who downloads it from the pirate site will be bound by your contract. You need copyright laws to prevent subsequent distribution.
Without copyright laws, you'd then end up in the situation where people who paid for the software then are bound by the contract and would have to keep paying, and those who just downloaded it from a pirate site would be completely fine legally and could use the software with impunity. That would create a disincentive for anybody agreeing to buy the software and entering into a contract in the first place, essentially killing the industry.
You might not see a problem with that if you believe in Open Source, but most licences require copyright laws to exist to protect the software freedoms so that people don't just take the software and close source it.
Yeah, I'm assuming most people here aren't selling proprietary code to customers directly. I assume most professionals here work somewhere that sells SaaS or uses the software they develop internally only.
You're advocating for the end of software licensing? Ie the removal of GPL or Open Source licenses? A landscape where any source code (or binary) can be snapped up by say Amazon or Microsoft and run via a paid subscription?
You're advocating for a business model which removes your access to local code and only allows access via a terminal or browser?
Because removal of copyright doesn't mean corporations go away. Rather it incentivizes business models that protect their products in other ways.
In the 80's and 90's, pre-internet, binary programs were distributed on media. An arms race of copiers and copy protection ensued. The copiers won, and since copyright enforcement has always been weak, business changed to favoring remote access (with subscription) over running locally via purchase.
At the same time Open Source and Free Software have thrived. Copyright protects that software being used outside the terms of the license. Indeed there's even outrage when it's used within the terms of the license (by AWS etc.)
Of course OSS still thrives under a copyrightless environment. (Free Software less so). But equally it means AI can simply be trained on it (probably no great loss since it's likely most of OSS will be AI generated anyway.)
Business however will adapt. And the easiest way to prevent coping now is simply remote execution. With a suitable Terms Of Use declaration.
Outside of software it would destroy music, movies, books etc. Basically it becomes a race to the bottom in terms of production costs (think user-generated You-Tube as the high-water mark.) But I assume you meant in the context of software.
Yes, I agree, that in much less than 1000 years copyright is dead. Because by then so much is in the public domain it doesn't matter anyway. Also because by then the last human programmer is long dead. AI will write anything you want, only you won't even ask because computer interfaces and abilities will be long past where we are now. You would have no need to create software any more than you need to build a plane or car today.
And those industries have taken less than 150 years to invent, explode, consolidate and commoditize. Indeed most of the complexity disappears when we go EV.
In 1000 years copyright is gone. But today it serves a lot of people.
> It'd be great for this to be the first major relinquishment of nation-state power
Intellectual property serves corporate interests and the idea of "nations" you are forced to have in your head are the exclusive servants the interests of capital. Ironically, tragically, that's what's holding us back from dismantling it in the first place, even a critic of it can't articulate it properly.
Sorry that will be undecipherable for HN. Let me try again: The defense you get in this pigstall is the individual that copyright is protecting. You just hate the small businesses and individual artists. Instead of the trillion dollar industry holding the copyrights and the practice of exploiting copyright on works by authors who died decades ago. The commodification of copyright of something produced by the lowest bidder, crappiest AI and cheapest third world labor you can get your literal bloody hands on. Or even a vaccine against the literal plague or cure for cancer protected by intellectual property.
To make something immaterial with no cost to reproduce, a commodity, to trade and invest and speculate in is the part to argue if you want to dismantle it, identify the rotten bits of the system even peasants can smell. If you are a billionaire or even trillionaire then just argue like everybody on HN always does, because it's identical.
German courts think the internet revolves around German laws. There are some really insane cases, sometimes they will consider a website to fall under German jurisdiction simply for having a German-language version (somehow ignoring that Austria and Switzerland exist, ignoring German-speaking minorities in other countries, ignoring that a fully automated translation in 100+ languages is now possible at the click of a button).
There's some irony in Germany using censorship for the purpose of ensuring people don't get into reading materials that might convince them to become... fascists who censor people
There is no irony. The German government is proto-fascist, and has been for a while, as are several other European governments. Apparently the UK now arrests more people per capita for online speech than China does.
For Hitler? He won the most seats of all the parties in the Reichstag in 1932 with 37 or so percent of the vote. That majority would normally have gotten him appointed as Chancellor (by tradition).
He used violence and backroom dealing to get from that majority to become Führer, but without a doubt Hitler did get his foot into the door democratically.
> Germany has its problems, but it's consistently in the top 15 most democratic nations in the world.
According to what? Some think tank’s “democracy index”, carefully constructed to preserve the illusion that Western countries are free and democratic? That’s begging the question.
German federal LE agencies have been doing it for years. Threatening to put you on lists of wanted and sanctioned individuals as a basically islamic suicide bomber for not taking down tiny things globally.
That kind of thing isn't unheard of for police agencies with moral and oversight issues, though. Orgs start seeking for bigger reasons. A simple copyright issue creatively expounded into an imaginary global drug bombing cyber trafficking crime ring takedown creates a massive internal win. So they do that.
What's even worse: the court fined us because they claimed this use case was in some way in contempt of their ruling. Then, when we won the overall case, that money was never returned because it wasn't specifically referenced by the final court. The response from the lower court was effectively: "Well, you will need to sue the court to get that money back." <table flip>
For awhile I self-hosted adguard dns server. It supports iphone profiles thus forcing iOS DNS. I eventually disabled it due to timeout issues specific to iOS. Issue was something DNSSEC related.
While reproing the issue I noted the average recursor round trip time from my OVH server hosted in Oregon to the default upstream DNS - Quad9 - was around 70ms. When I changed it to Hurricane Electric the roundtrip dropped to a steady 20ms. Later I changed it again to Cloudflare and the roundtrip was a consistent 2 to 3ms.
I'm always wondering whether those centralized privacy services are not the easiest first target for three-letter-agencies to infiltrate to gain access to the most relevant users to track - and what currently would prevent them from doing so if they haven't already ? Maybe, as with the case of many TOR nodes , they might be running them.
Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.
CIA is not stupid enough to break into a guarded data center in Switzerland or one of the less America friendly EU countries. They tell the NSA to look for security holes and spread narratives that only criminals use VPN hoping that a politician will notice and try to ban them, like what's happening in the UK.
Big tech services are less private than you think but almost every provider who cares about privacy is safer than you expect. Most of the people who work there are committed to their mission, and if they ever get a gag order someone will leak it in no time because they know exactly how to do it without exposing their identity.
Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?
The data would/should be encrypted; while the NSA did successfully tap Google's inter-datacenter traffic before the Snowden leaks, since then it is encrypted, too. Hopefully other providers won't fall for that trick anymore, either.
IIRC, Google addressed the incident you're referring to by adding E2E encryption to sensitive inter-DC RPC sessions, rather than by fully encrypting inter-DC traffic at the link level. It would be nice to be able to reasonably expect carrier/ISP backbones to be secure against this threat, but in our actual reality this seems like fantastical thinking.
They’ve already done both. When they can get a cooperative party (AT&T, for example), they colocate their splitter equipment. When they can’t, they tap undersea and overland cables.
When it’s a hostile environment entirely, they hack and do secret operations and bribe.
Are you sure? Someone broke into a Hetzner data center and a Linode one, physically intercepted the Ethernet cables for jabber.ru, and got certificates signed on their behalf.
I don't think there's any company with useful information on the American public that isn't being forced to regularly hand over that data. That's probably been true to some extent for a long time (see Room 641A) but it's certainly gotten worse. At this point you can't check out a book from the library without the feds demanding that your librarian turn over a list of everything you've ever read, or rent a hotel room for a night without the hotel being forced to provide your information to the government.
Use an online service that's new enough and small enough and it might not be compromised, but the moment it gets popular men with guns and national security letters with gag orders will show up to install hardware on their prem, take over entire offices, or just demand reports.
VPNs and secure DNS services aren't there to keep your data from the NSA, ICE, or even the police. They are useful for keeping your ISP from selling your browsing history to anyone willing to pay them (https://www.mitnicksecurity.com/in-the-news/republicans-just...). It'll help keep a little of what you do online away from data brokers, keep your ISP from sending you DMCA notices, and not much else.
For clarification, this is completely true of the US, without needing to speculate, thanks to a combination of FISA 702, the ECPA, CALEA, EO 12333, and the CLOUD act. It all has legal footing in the States.
However, it's not at all the reality of a vast swath of other countries (or, at least, not yet; see Chat Control v2). The US is particularly foul (and effective) when it comes to this practice, but anything outside of US jurisdiction that doesn't have an office in the US can't be touched by laws like these, and the laws of most other countries tend to be significantly less invasive than American ones when it comes to data interception and the practices surrounding it.
Quad9 is a reasonable choice given the stance on privacy and the similar jurisdiction (Mullvad would probably face the same takedown orders as Quad9), but really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver. Unbound is a great choice.
Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Your resolver’s DNS queries could be piped through Mullvad or Tor if you want additional privacy.
Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics.
First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and with the users of the service - this is exactly how an ideal transfer should go, at least from our perspective.
I'll try to make some short summaries of some of the points here, and a reply on each.
"You should just run your own DNS server - it's easy." - Yes, we agree that for a small company or home running your own recursive resolver is a reasonable solution. You probably won't get the threat mitigation depth of service that Quad9 offers, but you may not want that. Privacy also suffers a bit, since it's still the same IP address (your home "public" address) sending queries to authoritative servers, probably unencrypted. A good middle compromise is to run PiHole or AdGuard software, and forward your queries to Quad9 via an encrypted connection. (see below) This mixes your queries in with a large number of other users, and gets the potential improvements of having a much larger active cache nearby which will have "hot" answers.
Running a home resolver for yourself or even a few dozen (or even a few hundred) people is not difficult. But with all services, things change with scale. As the query volume and number of locations grow, you soon find yourself hitting all possible exception cases, instantly. Many millions of requests a second requires a lot of time, expertise, and money to ensure nearly 100% uptime. We are admittedly quite a small group - less than 10 full time - but even that is under-staffed for supporting more than 100 million daily users. We do quite a bit with a very small resource set, and I doubt it could be done less expensively with the same robustness for the same scale. Again, we appreciate Mullvad's sponsorship to help keep this expanding at our normal weekly growth rate of around 2%.
"I want ad blocking, and Quad9 doesn't do that" - Correct, Quad9 does not do ad blocking at this time. There are good solutions like PiHole or AdGuard extensions that provide this functionality, and getting local control and logging of your DNS queries is probably useful for power users. There are also commercial platforms that provide this capability, and they may provide significantly more "knobs" for what you want to block. Quad9 is a non-profit - we're not out to corner the market, and as long as privacy and security is increased for the end user, we're all for commercial solutions!
"Quad9 blocks domains in Germany" - Currently there are no mandatory blocks that Quad9 is integrating or enforcing on our DNS platform, from any external party. We did briefly block some domains as a result of legal actions against us in Germany. The good news is that we won that case in Germany, after two years and three appeals and an enormous amount of time and money (which despite Germany's "loser pays" rule, is not even close to expenditures.) https://quad9.net/news/blog/quad9-turns-the-sony-case-around... The bad news is that the identical thing is happening now in France where we have a number of legal cases open against Quad9, and we do not see an end to this any time soon as long as there is an open question in the EU about what a content-neutral intermediary is and is not required to do.
"Mullvad exiting creates more centralization, and that is bad." On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction. It's not just large public resolvers - consolidation in the ISP industry is causing more and more of the world's internet-using population to utilize a smaller number of recursive servers. Those servers are operated (mostly) by law-abiding companies, and so there is a strong interest by various parties interested in control of content to "put a hand on the available throat" even though it's the wrong throat to choke. We're busy with some ideas of how to solve this, both from a legal defense position as well as a technology position - stay tuned in the coming months. In the meantime, you can contribute a few euros/francs/dollars to us and we'll have more funds to pay for legal defense in France and hopefully up to the EU courts. https://quad9.net/donate/
"Government agencies can tap data" - Quad9 is based in Switzerland. Despite what may be common knowledge from movies, there is a very formal and rigorous process for governments (Swiss or non-Swiss) to demand data. It is (ultimately) transparent, and managed in a way that is quite well structured - this is, after all, what the Swiss have been doing with financial data for many years. More importantly: Quad9 stores no user data about queries. There isn't anything to demand - the box of data is quite empty. Because of this technological decision and our wide announcement of it (https://quad9.net/about/transparency-report/) we have never received a request for data.
As for technological methods: Quad9 operates in 200+ widely-separated locations, with no backbone or central data transport network - it is intentionally 'islanded'. It would be a significant challenge to intercept data at all those locations, though we're certain that there are many queries that are observed due to their presence on various ISP or cable networks which are under surveillance.
We support all major DNS encryption methods today (even the two that run on QUIC - HTTP/3 and DOQ) and we encourage users to use one of those for their communications to us. We are also one of the few major resolvers experimenting with ADOx, which encrypts messages between the recursive resolver and authoritative server. (https://dnsprivacy.org/adox_status_and_deployment/)
Been using them for years. The price is reasonable too. It’s the only way I found to block ads everywhere on iOS (except the YT app, Mullvad’s Albania wireguard did that)
I'm not the person you are responding to, but Proton VPN? That's what I switched to after it turned out one of the two Mullvad founders took my money and gave it to a local lunatic politician.
I did too, but I really miss Mullvad's static port forwarding system. It's a pain having to continually run a NAT-PMP client, and it doesn't work when you're connecting to ProtonVPN on your router.
I stopped using Mullvad when they discontinued OpenVPN support (another one to add to the parent list). OpenVPN, if nothing else, provides a wider array of connection options that have a better chance of fulfilling your specific network needs. It supports both UDP and TCP, unlike WireGuard.
I say this respectfully, but Mullvad is perhaps “dumbing down” their VPN service in an effort to simplify their operations and cater to a wider and more general audience.
I've found DoH was pretty unusable for me on Windows because the TCP connection doesn't seem to stay open between queries. No idea if it's a software or network issue, but big unpredictable delays on DNS queries broke all kinds of weird unexpected stuff.
NB. I don't use Windows and I don't use "Private DNS". I'm referring to using HTTP/1.1 pipelining^1 with a TCP client plus TLS forward proxy or HTTP/2 with an ldns-based client to fetch DNS data in bulk, outside the browser, from the command line. I got some incredible speeds from Mullvad
1. Not every service still supports 1.1, RFC recommends H2
> Running a privacy-focused public DNS service is a highly specialized undertaking
This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].
It's a legal problem (granted, you could still call that both a scaling problem and a cost problem), not a technical nor infrastructural one. That's where Quad9 has specific experience with public hosting that Mullvad doesn't.
I'm sure that the time, effort, money, and exposure that goes into responding and adhering to legal requests for a publicly offered service is something Mullvad wasn't expecting and would rather not be doing considering it's not their core focus.
What is intrinsic difficulty? A product at scale has many intrinsic dimensions, not just technical. Saying scaling is not an intrinsic difficulty is pretty weird given a highly scalable product usually looks nothing like their 1-user counterpart even when they have the same functionality.
This dude has been doing it for 25 years, and actually this is a dns provider for domain names which I'm decently sure makes it more complicated than public dns.
They're allowed to say they don't want to pay for it anymore, I just think their logic is bad. Or maybe their lawyer said they're running risks just ignoring takedown and they didn't want to deal with it anymore.
They mean it's authoritative DNS, not a resolver. The two are completely different services. Authoritative DNS is the side that serves the records for your website, resolver is the part that follows the tree of authoritative servers on behalf of the client.
Their DoH going down for hours multiple times is what forced me back to cloudflare, i don't trust cloudflare more but at least it works consistently.
Additionally the default of blocking 'malware' doesn't jive with uncensored internet - that should be an opt in and not a default on their flagship address if they want to be taken seriously as unfiltered provider.
If the encrypted endpoint can go down for extended periods and they curate list of 'malware' they are not something that should be considered a gateway to uncensored and open internet.
What does everybody here think about Daniel Berntsson, founder and co-owner of Mullvad, personally donating 5 million Swedish krona to the populist Örebro party, criticized for its stances on race & immigration?
I'm not trying to start an unhealthy discussion about this topic, genuinely curious about your opinion on the matter.
The old heads out there might remember a time when, rather than everyone using one service provider (ex. for Linux binaries/source), we all mutually agreed to use independently run mirrors closer to us. We sort of had to because of bandwidth and latency limits. But it meant that there were a thousand different people providing the same service. Impossible to censor everyone, everyone shares the load, too many places to hack if you wanted to massively compromise, and the users won.
DNS is harder to do that way because it's hard to have limits on DNS. Perhaps DNS could be adapted with QUIC, to allow fast, encrypted DNS that's easier to rate-limit, and then it'd be easier for average people to run public mirrors with limits.
disappointing, because alternatives matter too. quad9 and other well known servers are potentially blocked by some countries, so the more lesser known services there are the better.
Mullvad talks a lot about decentralization, then hands its resolver users to one of the biggest resolvers going. Quad9 is a good operator, and they actually fought Sony in German court instead of quietly complying. They still got ordered to block. That's the problem. A blocking order only hurts as much as the resolver it lands on is used, so every operator that shuts down and sends its users to Quad9 makes the next order a better deal for whoever files it.
They are not far right, AFAICT they are “right” Marxists, probably most similar to Albanian Hoxhaism.
If you aren’t familiar with splits inside Marxism-Leninism, the “left” is most often represented by Trotskyism with the “right” tendency being more like Stalinism and North Korean Juche. (Note that these left/right terms aren’t universally used or applied because every faction claims to be correct.)
Whoever openly spouts the concept of "remigration" [1] has no business being called anything else but far-right.
> In its political program for the 2026 Swedish general election the Örebro Party writes that they want to "stop the ongoing population replacement" and make Sweden a monocultural society, rather than a multicultural one. The party also writes that this "will be a Sweden where ethnic Swedes are once again the clear majority."
In particular, the "population replacement" is the most clear sign. That's as antisemitic and far-right as it gets [2].
Is Kim Jong Un far right? Seems like a stretch. (North Korea’s immigration policies are even more restrictive than what they want.)
Btw, Malcom Kyeyune, who has a podcast with the party’s founder, is a black child of an immigrant, adopts an avatar on Twitter of Kim Jong Un’s sister, and semi-ironically stans for North Korea on a regular basis.
yes, obviously he is. There is also no law of the universe that prevents a black person from interviewing a far right person or supporting a far right party.
I think it is more accurate to think of them as syncretic. (that is what Wikipedia has them listed as) Their main focus seems to be on nationalism/anti-immigration rather than socialism. Many fascist parties historically flirt with socialist policies as a way to make inroads with working class voters so it is not always straightforward.
Translation: one of Mullvad’s two cofounders has donated money to Örebropartiet, a left-leaning Swedish political party that promotes strict and restrictive immigration laws.
There's no such thing as a left-leaning party that harsh on immigration. Only parties that call themselves left-leaning. You may as well speak of a capitalist party that wants to seize and redistribute the means of production.
Or that the Nazis are socialist because they have socialist in their name instead of it being a front name to hide their fascist and racist intentions.
which shows how thoroughly they've been subverted by their purported enemy. siding with the capital on its quest to drive the wages down and the rents up will rightfully be their doom. no amount of progressive signaling can make up for that betrayal. the age of unprecedented prosperity is almost over in the west, and the modern left will perish with it.
is there a single party in Europe campaigning on the promise of more immigration, I wonder? if so, how do they fare? :)
>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead.
Brilliant.
On the Quad9 website:
>Since Quad9 already performs DNSSEC validation, DNSSEC being enabled in the forwarder will cause a duplication of the DNSSEC process, significantly reducing performance and potentially causing false BOGUS responses.
This sounds dodgy. Surely that means Quad9 can poison my DNS?
Not if Quad9 is using DNSSEC, no.
What's the specific threat you're envisioning? If it involves Quad9 themselves being malicious, what would DNSSEC on the forwarding prevent?
This page explains how all of this works in detail: https://quad9.net/news/blog/quad9-enables-dnssec-on-all-serv...
DNSSEC validation on your forwarder would prevent a maliciously modified record from Quad9 (or others) from being accepted locally - i.e. "Quad9 can poison my DNS".
I've always been of two minds on this. On one hand, that concern is beyond any reasonable level of security/performance/reliability tradeoff for most any user. At the same time, it is a bit of a shame DNS doesn't have a more scalable & performant approach to security which can just always be done without having to consider it a tradeoff, however minor in practice.
You are rely here on the assumption what your resolver already knows what the zone is DNSSEC signed. If your forwarder or resolver strips that information?..
At a high level, one of 3 things happens:
1. The forwarder gets a response claiming the record is supposed to be DNNSEC signed from the parent (recursively traversing from the root). The forwarder checks the signature of this claim. If the signature is valid, the forwarder continues on to validate the signature of the record and checks its validity to know if the info was secure. If the signature is invalid, the forwarder knows any information any information is not able to be validated as secure
- Somewhere during the recursive checks through the root, the forwarder gets an unsigned (no DNSSEC) or invalidly signed (e.g. your stripped response) response. The forwarder knows any information is not able to be validated as secure.
- A claim for lack of configuration or support of DNSSEC records comes back. The forwarder knows any information is not able to be validated as secure.
So you always know whether or not the information was secure, it's just if it was insecure you don't know if it's because it was just never secured or if someone tried to tamper with it. And that should make sense, an insecure message is by definition one which you can't tell if it has been tampered with.
Wait, I must be misunderstanding you, because if you're resolving off Quad9, they can definitely poison your DNSSEC-signed records. Between a stub resolver and a recursor DNSSEC collapses down to a single "yes it was signed" bit in the header.
To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a reason why DoH took off instead.
> To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a reason why DoH took off instead.
What? I don't see how you can call that a flaw in DNSSEC when DoH is no better in this regard; it doesn't even attempt to protect against a malicious recursive resolver. The only way to do that is to validate DNSSEC on the client.
DNSSEC and DoH provide different security services. But to get the benefit of DNSSEC, you need to resolve recursively. DoH works for stub resolvers. That's all I'm saying.
I don't know the details but knot-resolver asks for DS records of the domain being looked up when forwarding to avoid needing to do a full recursive lookup to validate DNSSEC. As I recall from what I've read this works almost everywhere, including Quad9, but not Google DNS due to a bug that they claim to have identified three years ago but haven't fixed. But as I understand it this is not how recursive resolvers validate so it is extra data that the forwarding server needs to request and cache.
Technically yes, in practice the odds your local resolver is validating DNSSEC is slim (and if you're intentionally configured it to do so, switch to a provider that isn't Quad9).
I use Clouldflare DoT and enabled validation in systemd-resolved some time ago. Not because I would be particularly paranoid, but more out of curiosity how it works. I noticed no problems, except for with Atlassian. They use 2 second level domains (at least), one under .com signed and one under .net (unsigned) (IIRC). Most things worked like normal, but some Jira extension stopped working. Turned out that systemd did reject their signed subdomains. Could not figure out whether the rejection was justified or not. When I asked Claude 7 times about it, I also got 7 contradicting answers... Reported to Atlassian support that their signing is incorrect (some delegation missing). To my surprise they replied: Are you using systemd? And gave a bug number that systemd handles validation wrong in their case.
Haven't had time to study the bug and really understand the whole issue myself. Just left it there with the takeaway that local validation is currently not for non-experts.
(Sorry not at my computer. Details rather vague from memory.)
I'm all for supporting quad9; but what if we just disable dnssec instead, it really solves nothing and continued support of it just makes it show up in compliance guides unnecessarily.
Quad9 doesn't have an adblocking DNS service though, so it's not really a replacement.
This is a very important detail. Adblock in 2026 is necessary and DNS will transparently do a lot of that work for you. It isn't just about lightning fast lookups and five-nines uptime anymore.
For blocking, I would much rather run my own service.
I've been loving the Pihole setup I just set up. It uses Quad9 as the upstream provider and then I do all the blocking myself. I used to use NextDNS but this is so much better and free!
Technitium is also really good as a performant local blocker and recursive dns server. I have been running mine for years now and it is fast as well.
How do you block ads when you're outside of your home network? Do you expose your pihole outside?
Mullvad had adblocking, malware blocking. And they didn’t block websites from governments blacklists in France and Italy. None of these features are available on Quad9.
Maybe it’s time to try nym.com?
That's something people should run themselves. I run Adguard Home on my router. Unlike the main Adguard product, Adguard Home is fully FOSS. It's been rock-solid for me, and improves on pi-hole in various ways - like full IPv6 support.
It's probably the software I trust the most on my network to 'just work', and with the local caching I can use slower upstream dns providers and still have sub 1ms average latency (no performance worries by excluding google and cloudflare). I don't use it for dhcp, but it is a good fit that it's available as well. Couldn't be happier.
I use Mullvad's adblocking DNS server on my phone which is not always behind my home router.
If you're on Android, FF supports add-ons.
If you're on an iPhone, uBlock is now supported: https://apps.apple.com/us/app/ublock-origin-lite/id674534269...
There's also Orion browser, but I found it to be a bit more glitchy, especially around sites like YouTube (fuck the app, I'm not watching videos there): https://orionbrowser.com/
It's not the same thing at all. Mullvad DNS blocks all ads across the system.
I've been using NextDNS [0] for a long time. It's worth the price because you can set up all kinds of different blocking profiles and have different ones on different devices, allows you to have overrides for local network items (or internals like on a Tailnet, Pangolin, Wireguard, etc) and a lot more. The ad blocking ends up working so well a lot not only are ads blocked on web pages but it works with some streaming audio ads as well as VoD that has ads injected. Highly recommend.
[0] https://nextdns.io
Up until the developers roll their host files into their app. That's why a pihole doesn't stop ads when you use the YouTube app.
Look, I still run AdGuard on my router, but it's not the same thing
Yes, I use Firefox on Android with ublock origin, it works great. But using adblocking DNS on your phone will also block most in-app ads which is a big quality of life improvement.
I could also use a VPN to keep my phone always on my home network and thus behind my own ad blocking DNS but Mullvad's adblocking DNS was really nice and convenient.
Really? I never found it effective unless I messed with certs on my phone.
For example, DNS blocking isn't going to block YouTube ads if you're using the app since they don't need to respect your DNS, but it will if you're in browser because they can't control that.
For apps I always use revanced.
Ads from providers like Google AdMob and AppLovin are blocked. Apps could bundle their own DNS or DoH resolver or use hardcoded static IP addresses but in my experience most do not.
Youtube ads do not get blocked by DNS adblock because Youtube ads are served from the same domains as the content and thus DNS blocking would be counterproductive. I don't think it has anything to do with respecting DNS.
I don't have the Youtube app installed to test but the Internet suggests that at least in 2023 it was very possible to block the Youtube android app (content and all) via DNS, which hints it does not bypass system DNS. [1]
[1] https://superuser.com/questions/713289/blocking-youtube-andr...
The uBlock Origin lite that can run on iOS is very limited compared to the uBlock Origin that runs on Firefox Android.
Sure, but you're on iPhone. It's better than nothing.
I'm on your side but telling people to buy a new phone doesn't solve their problem. Short of that uBlock and/or Orion are their best options
I'll second this. People should really be flashing their routers. OpenWRT is simple enough that if you're on HN I think you'll easily be able to do it. And like most routers, you set it up and forget it.
But you'll also get a bunch more benefits from OpenWRT, to make it worth your while.
[0] You don't need something like this unless you're getting >1Gbps from your ISP. Big thing I wanted is the 2 10G ports.
I could, but DoH/DoT seems very involved to run yourself, and sometimes I need to give a recommendation to someone less tech-savvy.
I stopped recommending anything I host myself for those people. When it breaks I'm the support team, and I'd rather not be. NextDNS free tier is what I give them now, takes two minutes, and I never hear about it again.
I'd argue you don't need to run DoT/DoH yourself if it is just for your local network.
Setting up a local resolver, such as a Pi-Hole or Unbound on a firewall can serve unencrypted responses to your devices. Those resolvers in turn can use DoT/DoH with their upstream resolvers to encrypt the requests that go through untrusted networks on the Internet.
This is the best of both worlds, the simplicity of unencrypted DNS while encrypting traffic where it matters.
I've been using Control D and have been happy with it so far
Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS.
[1] https://quad9.net/news/blog/italian-blocking-demands-followi...
> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders
Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.
The entire point is that it can't be reasonably enforced with any granularity. Rights-holders want it to be like that so a copyright win in a single country means something has to be taken down globally.
My fear exactly.
Sounds more like we should end copyright worldwide.
Indeed it needs to happen, and even here on HN, it can be difficult for some to admit and acknowledge.
It'd be great for this to be the first major relinquishment of nation-state power to happen without violence, without backroom deals, without wedge politics and flag waving.
Just... let it go.
It's beyond obvious that copyright is not going to exist in 1000 years. Every creature on earth - especially the internet - survives by copying information. It's the most basic life force in the universe.
Copyright is serving exactly nobody today. It's time. Are there elder stateswo/men in the room who can see the writing on the wall and act with grace?
> Copyright is serving exactly nobody today
Except for nearly everyone who writes anything (including software) or other artistic pursuits to make a living. This includes a majority of people here on HN.
I’ve written software all my life, copyright has never been relevant to my earnings at all, trade secrets have been to some extent. Frankly copyright was meant to enable more sharing and benefiting the public domain, instead it’s become a cancer…
For every rule there is an exception.
yeah I wouldn't be able to put food on the table if my employer didn't have exclusive license to the glue we use to stick together all that open source code we rely on. Which we now generate exclusively using AI, products of which are of unclear copyright status.
Modern IP law inhibits productivity more than it helps, imo. LLMs have fundamentally changed our line of work, and they have done so by completely ignoring the existing legal framework for IP. We should not defend the current implementation just because some people might suffer reduced earning potential.
Copyright was not designed to maximize productivity. It was designed to maximize creativity and inventiveness (or, as stated in the US Constitution, the progress of science and the useful arts).
> t was designed to maximize creativity and inventiveness
If you look at outcomes it has completely failed while making big corps very rich in the process
Linux is a marvel of the world and a large amount of its contributions have been made by people being paid to do so for commercial purposes - and I am not sure that would be true without the GPL. Is there a convincing argument there?
And outside open source there has been a staggering amount of creative work at all quality levels done for commercial purposes under the protection of copyright. Is there a convincing argument that the last century of software and music and books and etc would have been just as staggering without copyright?
I would love to hear such an argument. In my youth I thought copyright was blatantly stupid and should be abolished. I still sorta think that but I don't have a convincing argument in the face of the absolutely massive amount of good work that has been produced under it.
> Is there a convincing argument that the last century of software and music and books and etc would have been just as staggering without copyright?
> I would love to hear such an argument.
Fortunately, one of the many tentacles of the octopus most obviously at the forefront of the zeitgeist of the freedom that arises from a culture of free information - The Grateful Dead - had the outcome of producing - in the form of gripping autobiography - an extremely compelling, and seemingly utterly true and beautiful and good, instrument to fulfill your request:
https://www.goodreads.com/book/show/36750087-mother-american...
If you don't want to read a whole book and just want a stump speech which kicks ass in the department of argument you're requesting, it's here:
https://www.youtube.com/watch?v=rLbqgG6o1n8
Unfortunately that will happen irrespective of the law.
If you want permissive rules then corporations will just resell your IP (like we see with SaaS). And if you want tighter rules then you just create a higher barrier for entry that benefits corporations rather than independent entities.
Either way, it’s easier to operate when you already have a leading position.
People made a living juste fine before copyright stop spreading myths
Most hackers here are not relying on copyright to make their living. Either you work on open source but make your living off services on top of the code, or your code is a trade secret protected via contracts.
Not to mention that everyone using coding agents probably aren't even protected by copyright in the first place, at least in the US, since the courts are taking a pretty hard line on human authorship being required...
"your code is a trade secret protected via contracts" isn't enough to replace copyright because the contracts are only enforceable to the signing parties.
Let's say you write some software for your employer and they sell the product to several customers with a contract not to distribute it. However, the product appears on some pirate website anyway, and you can't identify who allowed the product to be leaked. Once it's there, your contracts are worthless as nobody who downloads it from the pirate site will be bound by your contract. You need copyright laws to prevent subsequent distribution.
Without copyright laws, you'd then end up in the situation where people who paid for the software then are bound by the contract and would have to keep paying, and those who just downloaded it from a pirate site would be completely fine legally and could use the software with impunity. That would create a disincentive for anybody agreeing to buy the software and entering into a contract in the first place, essentially killing the industry.
You might not see a problem with that if you believe in Open Source, but most licences require copyright laws to exist to protect the software freedoms so that people don't just take the software and close source it.
Yeah, I'm assuming most people here aren't selling proprietary code to customers directly. I assume most professionals here work somewhere that sells SaaS or uses the software they develop internally only.
>> Copyright is serving exactly nobody today.
Are you sure about that?
So just to be clear;
You're advocating for the end of software licensing? Ie the removal of GPL or Open Source licenses? A landscape where any source code (or binary) can be snapped up by say Amazon or Microsoft and run via a paid subscription?
You're advocating for a business model which removes your access to local code and only allows access via a terminal or browser?
Because removal of copyright doesn't mean corporations go away. Rather it incentivizes business models that protect their products in other ways.
In the 80's and 90's, pre-internet, binary programs were distributed on media. An arms race of copiers and copy protection ensued. The copiers won, and since copyright enforcement has always been weak, business changed to favoring remote access (with subscription) over running locally via purchase.
At the same time Open Source and Free Software have thrived. Copyright protects that software being used outside the terms of the license. Indeed there's even outrage when it's used within the terms of the license (by AWS etc.)
Of course OSS still thrives under a copyrightless environment. (Free Software less so). But equally it means AI can simply be trained on it (probably no great loss since it's likely most of OSS will be AI generated anyway.)
Business however will adapt. And the easiest way to prevent coping now is simply remote execution. With a suitable Terms Of Use declaration.
Outside of software it would destroy music, movies, books etc. Basically it becomes a race to the bottom in terms of production costs (think user-generated You-Tube as the high-water mark.) But I assume you meant in the context of software.
Yes, I agree, that in much less than 1000 years copyright is dead. Because by then so much is in the public domain it doesn't matter anyway. Also because by then the last human programmer is long dead. AI will write anything you want, only you won't even ask because computer interfaces and abilities will be long past where we are now. You would have no need to create software any more than you need to build a plane or car today.
And those industries have taken less than 150 years to invent, explode, consolidate and commoditize. Indeed most of the complexity disappears when we go EV.
In 1000 years copyright is gone. But today it serves a lot of people.
> It'd be great for this to be the first major relinquishment of nation-state power
Intellectual property serves corporate interests and the idea of "nations" you are forced to have in your head are the exclusive servants the interests of capital. Ironically, tragically, that's what's holding us back from dismantling it in the first place, even a critic of it can't articulate it properly.
Sorry that will be undecipherable for HN. Let me try again: The defense you get in this pigstall is the individual that copyright is protecting. You just hate the small businesses and individual artists. Instead of the trillion dollar industry holding the copyrights and the practice of exploiting copyright on works by authors who died decades ago. The commodification of copyright of something produced by the lowest bidder, crappiest AI and cheapest third world labor you can get your literal bloody hands on. Or even a vaccine against the literal plague or cure for cancer protected by intellectual property.
To make something immaterial with no cost to reproduce, a commodity, to trade and invest and speculate in is the part to argue if you want to dismantle it, identify the rotten bits of the system even peasants can smell. If you are a billionaire or even trillionaire then just argue like everybody on HN always does, because it's identical.
>So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up?
Trivial to do nowadays: https://focsec.com/
>I really don't like where this is going.
German courts think the internet revolves around German laws. There are some really insane cases, sometimes they will consider a website to fall under German jurisdiction simply for having a German-language version (somehow ignoring that Austria and Switzerland exist, ignoring German-speaking minorities in other countries, ignoring that a fully automated translation in 100+ languages is now possible at the click of a button).
There's some irony in Germany using censorship for the purpose of ensuring people don't get into reading materials that might convince them to become... fascists who censor people
There is no irony. The German government is proto-fascist, and has been for a while, as are several other European governments. Apparently the UK now arrests more people per capita for online speech than China does.
I would like to see your definition of fascism under which the German government is proto-fascist.
An authoritarian state that exercises oppressive power through legalistic institutions in league with a corporate oligarchy.
Germany has its problems, but it's consistently in the top 15 most democratic nations in the world.
Calling a solidly democratic nation "fascist" is a rhetorical reversal straight out of the authoritarian playbook.
Germany’s last officially fascist government was democratically elected
Citation needed.
For Hitler? He won the most seats of all the parties in the Reichstag in 1932 with 37 or so percent of the vote. That majority would normally have gotten him appointed as Chancellor (by tradition).
He used violence and backroom dealing to get from that majority to become Führer, but without a doubt Hitler did get his foot into the door democratically.
> Germany has its problems, but it's consistently in the top 15 most democratic nations in the world.
According to what? Some think tank’s “democracy index”, carefully constructed to preserve the illusion that Western countries are free and democratic? That’s begging the question.
German courts and technology are not always the best friends
German federal LE agencies have been doing it for years. Threatening to put you on lists of wanted and sanctioned individuals as a basically islamic suicide bomber for not taking down tiny things globally.
That kind of thing isn't unheard of for police agencies with moral and oversight issues, though. Orgs start seeking for bigger reasons. A simple copyright issue creatively expounded into an imaginary global drug bombing cyber trafficking crime ring takedown creates a massive internal win. So they do that.
What's even worse: the court fined us because they claimed this use case was in some way in contempt of their ruling. Then, when we won the overall case, that money was never returned because it wasn't specifically referenced by the final court. The response from the lower court was effectively: "Well, you will need to sue the court to get that money back." <table flip>
Edit: I'm with Quad9 (CTO)
The hubris of the courts can be stunning. Sorry from Germany.
And thanks for the great DNS service, I'm using it everywhere!
For awhile I self-hosted adguard dns server. It supports iphone profiles thus forcing iOS DNS. I eventually disabled it due to timeout issues specific to iOS. Issue was something DNSSEC related.
While reproing the issue I noted the average recursor round trip time from my OVH server hosted in Oregon to the default upstream DNS - Quad9 - was around 70ms. When I changed it to Hurricane Electric the roundtrip dropped to a steady 20ms. Later I changed it again to Cloudflare and the roundtrip was a consistent 2 to 3ms.
I'm always wondering whether those centralized privacy services are not the easiest first target for three-letter-agencies to infiltrate to gain access to the most relevant users to track - and what currently would prevent them from doing so if they haven't already ? Maybe, as with the case of many TOR nodes , they might be running them.
> and what currently would prevent them from doing so if they haven't already
they arent gods. some people actually have moral standards and dont just do whatever a foreign agency wants them to do
Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.
CIA is not stupid enough to break into a guarded data center in Switzerland or one of the less America friendly EU countries. They tell the NSA to look for security holes and spread narratives that only criminals use VPN hoping that a politician will notice and try to ban them, like what's happening in the UK.
Big tech services are less private than you think but almost every provider who cares about privacy is safer than you expect. Most of the people who work there are committed to their mission, and if they ever get a gag order someone will leak it in no time because they know exactly how to do it without exposing their identity.
Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?
The data would/should be encrypted; while the NSA did successfully tap Google's inter-datacenter traffic before the Snowden leaks, since then it is encrypted, too. Hopefully other providers won't fall for that trick anymore, either.
IIRC, Google addressed the incident you're referring to by adding E2E encryption to sensitive inter-DC RPC sessions, rather than by fully encrypting inter-DC traffic at the link level. It would be nice to be able to reasonably expect carrier/ISP backbones to be secure against this threat, but in our actual reality this seems like fantastical thinking.
They’ve already done both. When they can get a cooperative party (AT&T, for example), they colocate their splitter equipment. When they can’t, they tap undersea and overland cables.
When it’s a hostile environment entirely, they hack and do secret operations and bribe.
Are you sure? Someone broke into a Hetzner data center and a Linode one, physically intercepted the Ethernet cables for jabber.ru, and got certificates signed on their behalf.
https://notes.valdikss.org.ru/jabber.ru-mitm/
https://news.ycombinator.com/item?id=37961166
I don't think there's any company with useful information on the American public that isn't being forced to regularly hand over that data. That's probably been true to some extent for a long time (see Room 641A) but it's certainly gotten worse. At this point you can't check out a book from the library without the feds demanding that your librarian turn over a list of everything you've ever read, or rent a hotel room for a night without the hotel being forced to provide your information to the government.
Use an online service that's new enough and small enough and it might not be compromised, but the moment it gets popular men with guns and national security letters with gag orders will show up to install hardware on their prem, take over entire offices, or just demand reports.
VPNs and secure DNS services aren't there to keep your data from the NSA, ICE, or even the police. They are useful for keeping your ISP from selling your browsing history to anyone willing to pay them (https://www.mitnicksecurity.com/in-the-news/republicans-just...). It'll help keep a little of what you do online away from data brokers, keep your ISP from sending you DMCA notices, and not much else.
For clarification, this is completely true of the US, without needing to speculate, thanks to a combination of FISA 702, the ECPA, CALEA, EO 12333, and the CLOUD act. It all has legal footing in the States.
However, it's not at all the reality of a vast swath of other countries (or, at least, not yet; see Chat Control v2). The US is particularly foul (and effective) when it comes to this practice, but anything outside of US jurisdiction that doesn't have an office in the US can't be touched by laws like these, and the laws of most other countries tend to be significantly less invasive than American ones when it comes to data interception and the practices surrounding it.
Quad9 is a reasonable choice given the stance on privacy and the similar jurisdiction (Mullvad would probably face the same takedown orders as Quad9), but really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver. Unbound is a great choice.
Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Your resolver’s DNS queries could be piped through Mullvad or Tor if you want additional privacy.
Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics.
First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and with the users of the service - this is exactly how an ideal transfer should go, at least from our perspective.
I'll try to make some short summaries of some of the points here, and a reply on each.
"You should just run your own DNS server - it's easy." - Yes, we agree that for a small company or home running your own recursive resolver is a reasonable solution. You probably won't get the threat mitigation depth of service that Quad9 offers, but you may not want that. Privacy also suffers a bit, since it's still the same IP address (your home "public" address) sending queries to authoritative servers, probably unencrypted. A good middle compromise is to run PiHole or AdGuard software, and forward your queries to Quad9 via an encrypted connection. (see below) This mixes your queries in with a large number of other users, and gets the potential improvements of having a much larger active cache nearby which will have "hot" answers. Running a home resolver for yourself or even a few dozen (or even a few hundred) people is not difficult. But with all services, things change with scale. As the query volume and number of locations grow, you soon find yourself hitting all possible exception cases, instantly. Many millions of requests a second requires a lot of time, expertise, and money to ensure nearly 100% uptime. We are admittedly quite a small group - less than 10 full time - but even that is under-staffed for supporting more than 100 million daily users. We do quite a bit with a very small resource set, and I doubt it could be done less expensively with the same robustness for the same scale. Again, we appreciate Mullvad's sponsorship to help keep this expanding at our normal weekly growth rate of around 2%.
"I want ad blocking, and Quad9 doesn't do that" - Correct, Quad9 does not do ad blocking at this time. There are good solutions like PiHole or AdGuard extensions that provide this functionality, and getting local control and logging of your DNS queries is probably useful for power users. There are also commercial platforms that provide this capability, and they may provide significantly more "knobs" for what you want to block. Quad9 is a non-profit - we're not out to corner the market, and as long as privacy and security is increased for the end user, we're all for commercial solutions!
"Quad9 blocks domains in Germany" - Currently there are no mandatory blocks that Quad9 is integrating or enforcing on our DNS platform, from any external party. We did briefly block some domains as a result of legal actions against us in Germany. The good news is that we won that case in Germany, after two years and three appeals and an enormous amount of time and money (which despite Germany's "loser pays" rule, is not even close to expenditures.) https://quad9.net/news/blog/quad9-turns-the-sony-case-around... The bad news is that the identical thing is happening now in France where we have a number of legal cases open against Quad9, and we do not see an end to this any time soon as long as there is an open question in the EU about what a content-neutral intermediary is and is not required to do.
"Mullvad exiting creates more centralization, and that is bad." On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction. It's not just large public resolvers - consolidation in the ISP industry is causing more and more of the world's internet-using population to utilize a smaller number of recursive servers. Those servers are operated (mostly) by law-abiding companies, and so there is a strong interest by various parties interested in control of content to "put a hand on the available throat" even though it's the wrong throat to choke. We're busy with some ideas of how to solve this, both from a legal defense position as well as a technology position - stay tuned in the coming months. In the meantime, you can contribute a few euros/francs/dollars to us and we'll have more funds to pay for legal defense in France and hopefully up to the EU courts. https://quad9.net/donate/
"Government agencies can tap data" - Quad9 is based in Switzerland. Despite what may be common knowledge from movies, there is a very formal and rigorous process for governments (Swiss or non-Swiss) to demand data. It is (ultimately) transparent, and managed in a way that is quite well structured - this is, after all, what the Swiss have been doing with financial data for many years. More importantly: Quad9 stores no user data about queries. There isn't anything to demand - the box of data is quite empty. Because of this technological decision and our wide announcement of it (https://quad9.net/about/transparency-report/) we have never received a request for data. As for technological methods: Quad9 operates in 200+ widely-separated locations, with no backbone or central data transport network - it is intentionally 'islanded'. It would be a significant challenge to intercept data at all those locations, though we're certain that there are many queries that are observed due to their presence on various ISP or cable networks which are under surveillance. We support all major DNS encryption methods today (even the two that run on QUIC - HTTP/3 and DOQ) and we encourage users to use one of those for their communications to us. We are also one of the few major resolvers experimenting with ADOx, which encrypts messages between the recursive resolver and authoritative server. (https://dnsprivacy.org/adox_status_and_deployment/)
It's not that I don't trust Quad9 or dns.sb or any of the others, it's just that I trust Mullvad more.
Sad to see this going away, but I assume this is so Mullvad can focus on their primary services.
Does anyone know of good alternatives that also block ads? Seems Quad9 doesn't.
https://controld.com/free-dns
nextdns.io might be an option
https://adguard-dns.io/kb/general/dns-providers/ have a list of options that some of them have ad blocker
NextDNS https://nextdns.io/
Been using them for years. The price is reasonable too. It’s the only way I found to block ads everywhere on iOS (except the YT app, Mullvad’s Albania wireguard did that)
The price is so reasonable, I think the risk is that you’re paying mainly with your data?
https://joindns4.eu/for-public#resolver-options
they block duolingo
What about Cloudflare’s public DNS? https://developers.cloudflare.com/1.1.1.1/setup/#1111-for-fa...
Cloudflare DNS does not block ads, it only blocks malware
I'm using numa(https://github.com/razvandimescu/numa) for ad filtering and odoh mode for privacy (shameless plug)
So this is something to use instead of pihole?
dns.adguard-dns.com
Several (European) alternatives are available: https://eualternative.eu/categories/public-dns/
https://github.com/AdguardTeam/AdGuardHome/releases
Trivial to self-host, and gives you full control of blocking.
dot.sb
I have a router with adguard on it so I can locally filter everything.
Sometimes you need to unblock things to ensure something works properly, so having it be local is better in my opinion.
These was one of the fastest DoH services for pipelined queries over single TCP connection
IME, it was much faster than Quad9 for this purpose
First Mullvad shuts down its Google search proxy
Now its DoH service
What's next
They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas
Curious what alternative you found as a replacement. Could you share?
I'm not the person you are responding to, but Proton VPN? That's what I switched to after it turned out one of the two Mullvad founders took my money and gave it to a local lunatic politician.
I've heard AirVPN being mentioned around, if it interests you.
I switched to ProtonVPN which has a heavy emphasis on port forwarding.
I did too, but I really miss Mullvad's static port forwarding system. It's a pain having to continually run a NAT-PMP client, and it doesn't work when you're connecting to ProtonVPN on your router.
Switched to Windscribe at the time, quite cheap.
I stopped using Mullvad when they discontinued OpenVPN support (another one to add to the parent list). OpenVPN, if nothing else, provides a wider array of connection options that have a better chance of fulfilling your specific network needs. It supports both UDP and TCP, unlike WireGuard.
I say this respectfully, but Mullvad is perhaps “dumbing down” their VPN service in an effort to simplify their operations and cater to a wider and more general audience.
Also had a ChatGPT alternative with less surveillance
Discontinued
I've found DoH was pretty unusable for me on Windows because the TCP connection doesn't seem to stay open between queries. No idea if it's a software or network issue, but big unpredictable delays on DNS queries broke all kinds of weird unexpected stuff.
NB. I don't use Windows and I don't use "Private DNS". I'm referring to using HTTP/1.1 pipelining^1 with a TCP client plus TLS forward proxy or HTTP/2 with an ldns-based client to fetch DNS data in bulk, outside the browser, from the command line. I got some incredible speeds from Mullvad
1. Not every service still supports 1.1, RFC recommends H2
> Running a privacy-focused public DNS service is a highly specialized undertaking
This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never thought it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].
[0] https://github.com/hagezi/dns-blocklists
You can't compare running a single service in your home network with the operations it takes to serve a public DNS
This is a scaling problem, not an intrinsic difficulty. Mullvad already had the infrastructure in place. I suspect the real reason is cost-cutting.
It's a legal problem (granted, you could still call that both a scaling problem and a cost problem), not a technical nor infrastructural one. That's where Quad9 has specific experience with public hosting that Mullvad doesn't.
I'm sure that the time, effort, money, and exposure that goes into responding and adhering to legal requests for a publicly offered service is something Mullvad wasn't expecting and would rather not be doing considering it's not their core focus.
What is intrinsic difficulty? A product at scale has many intrinsic dimensions, not just technical. Saying scaling is not an intrinsic difficulty is pretty weird given a highly scalable product usually looks nothing like their 1-user counterpart even when they have the same functionality.
>https://freedns.afraid.org/
This dude has been doing it for 25 years, and actually this is a dns provider for domain names which I'm decently sure makes it more complicated than public dns.
They're allowed to say they don't want to pay for it anymore, I just think their logic is bad. Or maybe their lawyer said they're running risks just ignoring takedown and they didn't want to deal with it anymore.
> this is a dns provider for domain names which I'm decently sure makes it more complicated than public dns
Can you expand on this? Isn't all DNS for domain names?
They mean it's authoritative DNS, not a resolver. The two are completely different services. Authoritative DNS is the side that serves the records for your website, resolver is the part that follows the tree of authoritative servers on behalf of the client.
Hey dang can I get my rate limit removed yet?
How much traffic is your public DNS serving?
I used to use Mullvad's DoH Service because of ad blocking, it worked quite well with SoundCloud etc.
Are there any alternatives?
This obviously isn't for everyone, but the solution I use is: my own DNS server at home + wg to access it when I'm away.
How's the latency when you're away?
nextdns. I wonder why people use anything else at all
Quad9 has horrible latency and frequent query failures, I hope Mullvad encourages them to improve their routes
Their DoH going down for hours multiple times is what forced me back to cloudflare, i don't trust cloudflare more but at least it works consistently.
Additionally the default of blocking 'malware' doesn't jive with uncensored internet - that should be an opt in and not a default on their flagship address if they want to be taken seriously as unfiltered provider.
If the encrypted endpoint can go down for extended periods and they curate list of 'malware' they are not something that should be considered a gateway to uncensored and open internet.
I compared pings recently and was getting like 200-300ms to the closest mullvad DoH server. Quad9 has an adblocking DoH DNS with decent latency.
What does everybody here think about Daniel Berntsson, founder and co-owner of Mullvad, personally donating 5 million Swedish krona to the populist Örebro party, criticized for its stances on race & immigration?
I'm not trying to start an unhealthy discussion about this topic, genuinely curious about your opinion on the matter.
I have no insights in Swedish politics. His actions could be really bad, or mean nothing at all. Without proper context, it’s hard to say.
That's a shame, even if I remember their DNS service being a bit unstable (it would at various points not be able to resolve or flat out it was down).
The old heads out there might remember a time when, rather than everyone using one service provider (ex. for Linux binaries/source), we all mutually agreed to use independently run mirrors closer to us. We sort of had to because of bandwidth and latency limits. But it meant that there were a thousand different people providing the same service. Impossible to censor everyone, everyone shares the load, too many places to hack if you wanted to massively compromise, and the users won.
DNS is harder to do that way because it's hard to have limits on DNS. Perhaps DNS could be adapted with QUIC, to allow fast, encrypted DNS that's easier to rate-limit, and then it'd be easier for average people to run public mirrors with limits.
disappointing, because alternatives matter too. quad9 and other well known servers are potentially blocked by some countries, so the more lesser known services there are the better.
Mullvad talks a lot about decentralization, then hands its resolver users to one of the biggest resolvers going. Quad9 is a good operator, and they actually fought Sony in German court instead of quietly complying. They still got ordered to block. That's the problem. A blocking order only hurts as much as the resolver it lands on is used, so every operator that shuts down and sends its users to Quad9 makes the next order a better deal for whoever files it.
There is always the option of running your own locally.
This is probably service you can host locally with the lowest maintenance and hardware requirements so it isn't even a hassle to do it yourself.
Their founder supports Nazis.
Pretty unapologetically, too. He's still doing it and will keep doing it the more you give him money.
First I thought it must be the usual Israel-related dogwhistle, but nope, it's legitimate and related to Swedish far-right Örebropartiet [1].
(Next time, might be worth to add a source yourself to prevent downvotes)
[1] https://www.reddit.com/r/ProtonMail/comments/1uivm45/mullvad...
They are not far right, AFAICT they are “right” Marxists, probably most similar to Albanian Hoxhaism.
If you aren’t familiar with splits inside Marxism-Leninism, the “left” is most often represented by Trotskyism with the “right” tendency being more like Stalinism and North Korean Juche. (Note that these left/right terms aren’t universally used or applied because every faction claims to be correct.)
Whoever openly spouts the concept of "remigration" [1] has no business being called anything else but far-right.
> In its political program for the 2026 Swedish general election the Örebro Party writes that they want to "stop the ongoing population replacement" and make Sweden a monocultural society, rather than a multicultural one. The party also writes that this "will be a Sweden where ethnic Swedes are once again the clear majority."
In particular, the "population replacement" is the most clear sign. That's as antisemitic and far-right as it gets [2].
[1] https://en.wikipedia.org/wiki/%C3%96rebro_Party#Immigration_...
[2] https://en.wikipedia.org/wiki/Great_Replacement_conspiracy_t...
Is Kim Jong Un far right? Seems like a stretch. (North Korea’s immigration policies are even more restrictive than what they want.)
Btw, Malcom Kyeyune, who has a podcast with the party’s founder, is a black child of an immigrant, adopts an avatar on Twitter of Kim Jong Un’s sister, and semi-ironically stans for North Korea on a regular basis.
yes, obviously he is. There is also no law of the universe that prevents a black person from interviewing a far right person or supporting a far right party.
Calling Kim Jong Un “far right” is a special level of ultra-left idiocy. I’m guessing you consider Marx a “moderate” then.
I think it is more accurate to think of them as syncretic. (that is what Wikipedia has them listed as) Their main focus seems to be on nationalism/anti-immigration rather than socialism. Many fascist parties historically flirt with socialist policies as a way to make inroads with working class voters so it is not always straightforward.
Source?
Translation: one of Mullvad’s two cofounders has donated money to Örebropartiet, a left-leaning Swedish political party that promotes strict and restrictive immigration laws.
And “donated money” here means “his donations amounted to 72% of the party's entire 2025 revenue”[0].
[0]: https://www.flamman.se/techprofil-ger-miljoner-till-orebropa...
There's no such thing as a left-leaning party that harsh on immigration. Only parties that call themselves left-leaning. You may as well speak of a capitalist party that wants to seize and redistribute the means of production.
Or that the Nazis are socialist because they have socialist in their name instead of it being a front name to hide their fascist and racist intentions.
which shows how thoroughly they've been subverted by their purported enemy. siding with the capital on its quest to drive the wages down and the rents up will rightfully be their doom. no amount of progressive signaling can make up for that betrayal. the age of unprecedented prosperity is almost over in the west, and the modern left will perish with it.
is there a single party in Europe campaigning on the promise of more immigration, I wonder? if so, how do they fare? :)
"There's no such thing as a left-leaning party that harsh on immigration."
This was probably the most ignorant thing I've read today. You're knowledge of political history must not extend very far.
They support mass deportations based on race, including of citizens.
If that is what they say before they get power, you need only the basic lessons of history to understand what they might do after they get power.