frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Improve Privacy by Running a DNS Server Without Forwarder

https://louwrentius.com/improve-privacy-by-running-a-dns-server-without-forwarder.html
1•louwrentius•1h ago

Comments

st3fan•1h ago
The privacy angle here is wrong, or at least incomplete.

The reason for that is that your ISP is most likely capturing all your unencrypted DNS traffic (port 53) to build that exact profile of you.

And unlike CloudFLare or Google, your ISP, which often is also the company from which you get your mobile phone subscriptions, now knows where you live, who you are, what your family looks like and which specific websites you visit.

Cable/Fiber modem manufacturers are also known to do exactly this kind of data collection. There was a recent example of this where it happened with firmware directly on the cable modem for a Dutch provider.

Running your own DNS server does not change this at all. From a network perspective this is the same: unencrypted DNS that anyone in the middle can see and record.

The only way to work around companies upstream from you is actually to use a DNS forwarder combined with some form of DNS privacy (encryption). A very good way is to have a local DNS Server that forwards to a outside trusted DNS server over DoT or DoH. Both of which are encrypted. Your ISP can see the traffic, but they can't see inside it and find out what DNS queries you do.

That means your devices on your local network can just talk "plain" DNS port 53 like they always do, to your self hosted DNS server. But your self hosted DNS server will then forward those queries to a trusted server _outside of your and the ISP network_ over an encrypted channel.

I do this with Unbound and the following config https://gist.github.com/st3fan/22ac09b7219b29f446a45d6cc599c...

Note that I do not trust my ISP (Bell Canada) but I do feel ok with using Google and CloudFlare. That is my personal choice and not a recommendation. You can probably find better options - they do need to support DoT or DoH though.

Building pentest devices with Rust and an ESP32-C6

https://kerkour.com/rust-esp32-pentest
1•randomint64•30s ago•0 comments

People don't like wearing things on their faces and don't trust those who do

https://nealstephenson.substack.com/p/my-prodigal-brainchild
1•ilamont•1m ago•0 comments

New In-App Purchase and subscription data now available in Analytics

https://developer.apple.com/news/?id=hh6v4b55
1•surprisetalk•2m ago•0 comments

Kali Linux 2026.1 introduces 8 new tools

https://www.techzine.eu/news/security/139952/kali-linux-2026-1-introduces-8-new-tools/
1•losgehts•2m ago•0 comments

The 667MHz Machine

https://www.0xsid.com/blog/667mhz-machine
2•ssiddharth•2m ago•0 comments

The Lock Nobody Held: Deadlocking a Tokio Mutex Without Holding a Lock

https://www.e6data.com/blog/deadlocking-tokio-mutex-without-holding-lock
1•g0xA52A2A•3m ago•0 comments

OpenAI's latest repo has Claude as the third top contributor

https://twitter.com/CodeByNZ/status/2036723050197012771
2•mirzap•3m ago•1 comments

A movement to ban data centers gains steam across the U.S.

https://www.washingtonpost.com/technology/2026/03/25/sanders-data-centers-bipartisan-moratorium/
1•1vuio0pswjnm7•3m ago•0 comments

To Counter China, America's Military AI Needs an Open-Source Reboot

https://www.nationalreview.com/2026/03/to-counter-china-americas-military-ai-needs-an-open-source...
1•everybodyknows•4m ago•0 comments

Mind over Math

https://samheuck.com/blog/mind-over-math/
1•mayhemducks•5m ago•1 comments

I downloaded and hashed 4.6M ArXiv PDFs. Then the hashes changed

https://dorsalhub.com/blog/i-downloaded-and-hashed-4-6-million-arxiv-pdfs-then-the-hashes-changed
1•rioachuzia•6m ago•0 comments

Meta must pay $375M for violating New Mexico law, jury rules

https://www.cnbc.com/2026/03/24/jury-reaches-verdict-in-meta-child-safety-trial-in-new-mexico.html
1•1vuio0pswjnm7•8m ago•0 comments

If Japan Can, Why Can't We? – NBC Documentary (1980) [video]

https://www.youtube.com/watch?v=vcG_Pmt_Ny4
1•alexandrehtrb•8m ago•0 comments

Storing Claude Code API keys in KeePassXC instead of plaintext config

https://mareksuppa.com/til/keepassxc-claude-code-api-keys/
1•mrshu•9m ago•1 comments

Show HN: Paper Console – Handmade thermal printer for news, weather, games etc.

https://travismiller.design/paper-console/
1•travmiller•9m ago•0 comments

Gradient Descent into Confusion: How the AI Field Renamed Everything

https://dreossi.github.io/blog/gradient-descent-into-confusion/
1•maunic•10m ago•0 comments

DownToTalk – When Claude goes down, talk to a human instead

https://downtotalk.vercel.app
2•yakovvasiliev•11m ago•0 comments

Russia Launched First Cluster of Satellites for Its Analog of Starlink

https://militarnyi.com/en/news/russia-cluster-satellites-starlink-rassvet/
2•giuliomagnifico•11m ago•0 comments

Palestinians warn of expanding West Bank settler violence

https://www.bbc.com/news/articles/c747x00m83vo
2•tartoran•12m ago•0 comments

Age requirements for managing an Apple Account in the UK

https://support.apple.com/en-gb/126788
1•ChrisArchitect•12m ago•0 comments

Theory X and Theory Y

http://www.netmba.com/mgmt/ob/motivation/mcgregor/
1•rzk•12m ago•0 comments

New Mexico seeking changes to Meta's platform after jury finds company liable

https://www.cnbc.com/2026/03/25/new-mexico-meta-lawsuit-jury-verdict.html
1•1vuio0pswjnm7•12m ago•0 comments

Show HN: QWERTY mini – a 16-key, 2-row keyboard, now available as a Pro version

https://play.google.com/store/apps/details?id=com.qwerty_mini_pro.app&hl=en_US
1•QWERTYmini•12m ago•1 comments

Ubuntu wants to strip some of GRUB features in 26.10 for security purposes

https://discourse.ubuntu.com/t/streamlining-secure-boot-for-26-10/79069
2•dryarzeg•13m ago•0 comments

Why insane Gout Gout run has gone viral 15 months later

https://www.nine.com.au/sport/athletics/news-2026-gout-gout-viral-clip-race-run-australian-sprint...
1•wslh•14m ago•0 comments

Hush: An on-device AI cry detector and soother built for spare phones

https://hush-baby.app/
1•efkanworks•14m ago•0 comments

Show HN: Voice-to-Text in a Browser Tab

https://donetyping.com/
1•Patt_•15m ago•0 comments

Fire risks and ugly designs are stalling EV charger adoption

https://restofworld.org/2026/ev-charger-backlash-fire-safety-aesthetics/
1•Brajeshwar•15m ago•0 comments

The Tyranny of What If It Changes

https://chriskiehl.com/article/the-tyranny-of-what-if-it-changes
1•hasanhaja•15m ago•0 comments

How an Early 20th Century Steam Ship Works [video]

https://www.youtube.com/watch?v=tBN2o4rAt5A
1•dataviz1000•15m ago•0 comments