Shutting down our public encrypted DNS

(mullvad.net)

60 points | by mywacaday 51 minutes ago

6 comments

  • pbhjpbhj 37 minutes ago
    >We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead.

    Brilliant.

    • pbhjpbhj 33 minutes ago
      On the Quad9 website:

      >Since Quad9 already performs DNSSEC validation, DNSSEC being enabled in the forwarder will cause a duplication of the DNSSEC process, significantly reducing performance and potentially causing false BOGUS responses.

      This sounds dodgy. Surely that means Quad9 can poison my DNS?

    • oofdere 11 minutes ago
      Quad9 doesn't have an adblocking DNS service though, so it's not really a replacement.
    • seany 22 minutes ago
      I'm all for supporting quad9; but what if we just disable dnssec instead, it really solves nothing and continued support of it just makes it show up in compliance guides unnecessarily.
  • nullmatrix 1 minute ago
    Their founder supports Nazis.
  • 1vuio0pswjnm7 5 minutes ago
    These was one of the fastest DoH services for pipelined queries over single TCP connection

    IME, it was much faster than Quad9 for this purpose

    First Mullvad shuts down its Google search proxy

    Now its DoH service

    What's next

  • ianmurrays 6 minutes ago
    Does anyone know of good alternatives that also block ads? Seems Quad9 doesn't.
  • em-bee 34 minutes ago
    disappointing, because alternatives matter too. quad9 and other well known servers are potentially blocked by some countries, so the more lesser known services there are the better.