Author Topic: Any Thoughts on OpenDNS  (Read 1486 times)

0 Members and 1 Guest are viewing this topic.

Offline NHAS

  • Serf
  • *
  • Posts: 40
  • Cookies: 1
    • View Profile
Any Thoughts on OpenDNS
« on: April 05, 2014, 08:20:33 am »
Hey EZ, Just wanted to ask you guys what your thoughts on OpenDNS are.
At the moment I'm contemplating switching from my ISP's DNS to their one and was just wondering if anyone had any reason I shouldn't or information that I should be aware of before I switch.

Thanks for any info or just general opinions on OpenDNS.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #1 on: April 05, 2014, 10:36:31 am »
Well in a lot of cases there is not much reason to switch nor is there much against doing so.
If you really want to do something useful with your DNS queries I suggest you setup your own caching DNS server on the network.
On slow lines and even on fast lines this can have quite the speed advantage.

Quote
At OpenDNS headquarters in beautiful San Francisco, CA, our world-class engineering team is obsessed with inventing new methodologies to eradicate malware, botnets and phishing through DNS, and use the system to intelligently route our users around it.

This is from their website, thats cute, nothing more imo.
The only problem with DNS as it is used for most systems is the lack of encryption on the queries.
There might be something to gain in that field as there are 'secure' alternatives.
« Last Edit: April 05, 2014, 10:37:57 am by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline NHAS

  • Serf
  • *
  • Posts: 40
  • Cookies: 1
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #2 on: April 05, 2014, 09:08:06 pm »
Yeah guess I could setup a DNS server on our network I have a computer lying around not doing anything...

Oh and I'm pretty sure OpenDNS does support encrypted DNS queries.
See here: http://www.opendns.com/about/innovations/dnscrypt/

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #3 on: April 06, 2014, 03:58:58 am »
Yeah guess I could setup a DNS server on our network I have a computer lying around not doing anything...

Oh and I'm pretty sure OpenDNS does support encrypted DNS queries.
See here: http://www.opendns.com/about/innovations/dnscrypt/
I myself use pdnsd , I have a thread somewhere about basic setup combined with squid.
The only trade-off for encrypted queries would be the speed, not that irl this is noticable.
For one you would prevent snooping from your ISP which is something at least.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline NHAS

  • Serf
  • *
  • Posts: 40
  • Cookies: 1
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #4 on: April 06, 2014, 05:38:31 am »
Okay thanks

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: Any Thoughts on OpenDNS
« Reply #5 on: April 06, 2014, 06:30:31 am »
I use googles DNS, no reason though. Just always have.
>>>import this
-----------------------------

Offline NHAS

  • Serf
  • *
  • Posts: 40
  • Cookies: 1
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #6 on: April 06, 2014, 06:58:12 am »
I use googles DNS, no reason though. Just always have.

Yeah, I was thinking about that. But i'd prefer if I had control of the DNS somewhat.
« Last Edit: April 06, 2014, 06:58:28 am by NHAS »

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #7 on: April 06, 2014, 07:39:07 am »
Yeah, I was thinking about that. But i'd prefer if I had control of the DNS somewhat.
Then cache it, a plus is that you can also use block lists/null routing of ad's, trackers and other internet whores.
Can run just fine on the same machine.
You could also increase the TTL's a bit , most devices don't hop that often anyway, it can eliminate quite some traffic.
One of the funny little things is that I never have ad's on youtube.
« Last Edit: April 06, 2014, 07:42:24 am by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline NHAS

  • Serf
  • *
  • Posts: 40
  • Cookies: 1
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #8 on: April 06, 2014, 09:03:52 am »
Hmm cant run it on the same machine 'cause I often turn it off so I think ill stick with chucking the DNS onto another one but thanks for all the knowledge proxx have a cookie.

Offline Neolux

  • /dev/null
  • *
  • Posts: 5
  • Cookies: 0
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #9 on: April 26, 2014, 05:13:50 am »
Parents used it on the router to block pr0n as a kid... was terrible.

3 years before I learned how to change my DNS server on the computer.

Sad story.  :'(

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Any Thoughts on OpenDNS
« Reply #10 on: April 26, 2014, 08:05:08 am »
One of the funny little things is that I never have ad's on youtube.

Neither have I. And Adblock Edge is shit; I switched from ADB, and it was just pure fail.
As for OpenDNS, I've heard good and bad.

Bad:
"OpenDNS may cooperate with legal authorities and/or third parties in the investigation of any suspected or alleged crime or civil wrong." Obviously one of the worst parts is the logging aspect. They also log your queries for a time (I think for 72 hours). During which the gov't is free to send requests for such data without your knowledge. And the quote below confirms that suspicion:

"The Software together with the Service may collect certain data and information about your use and, if you are an entity, your individual users’ use of the Service (“User Data”).  Any personally identifiable information contained in User Data provided to OpenDNS will be treated as set forth in the OpenDNS Privacy Policy available at http://www.opendns.com/privacy-policy/. With the exception of any personally identifiable information you or your individual users submit, any information you transmit to OpenDNS via the Services related to the functionality of the Services and Software, whether by direct entry, submission, e-mail or otherwise, including data, questions, comments, or suggestions, will be treated as non-confidential and non-proprietary and will become the property of OpenDNS."

As far as the encryption, I would rather use DNS Crypt (but I don't trust anything with access to my unlimited data even if they promise encryption).

Good:
At least DNSCrypt explains it's not end-to-end but rather uses Elliptic Curve.

"The DNSCrypt protocol uses high-speed high-security elliptic-curve cryptography and is very similar to DNSCurve, but focuses on securing communications between a client and its first-level resolver. While not providing end-to-end security, it protects the local network, which is often the weakest point of the chain, against man-in-the-middle attacks. It also provides some confidentiality to DNS queries."

I guess pick your poison lol.

Offline Stannis_the_Mannis

  • /dev/null
  • *
  • Posts: 6
  • Cookies: 0
  • For the net is dark and full of NSA
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #11 on: April 26, 2014, 08:35:57 am »
I use openDNS just for shits and giggles. And because I'm not a fan of google. I don't really notice any difference between that and my default DNS, but then again I don't know that much.
"Free software means software that respects the users freedom" -Stallman
"Arguing on the internet is like winning the special olympics, even if you win you are still retarded." -internet proverb
"We live in a society of victimization, where people are much more comfortable being victimized than actually standing up for themselves" -Marilyn Manson
"What is dead may never die" -Theon Greyjoy
"A man who must say "I am the king" is no true king. -Tywin Lannister

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Any Thoughts on OpenDNS
« Reply #12 on: April 26, 2014, 03:11:47 pm »
It is not such a bad idea to tunnel DNS traffic away through something like tor.
Using a caching daemon as a method to compensate with the speed trade-off.
DNS is a great way to profile people over the years, the question is who has insight in such data which is probably stored infinite.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage