Encrypt Your DNS (STOP Your ISP SNOOPING!)

  Рет қаралды 443,043

Naomi Brockwell TV

Naomi Brockwell TV

Күн бұрын

Пікірлер: 823
@glennw3154
@glennw3154 Жыл бұрын
I stumbled upon this video as a pfSense and Unbound noob. What a masterful, concise and logical presentation that truly helped to eliminate the confusion created by many others. This is literally the best short video on the topic, earning you another subscriber. Excellent work!
@stryfespoint304
@stryfespoint304 Жыл бұрын
Another gem delivered as always, keep up the quality work and thanks for all that you and your team constantly do.
@timmcreynolds2734
@timmcreynolds2734 Жыл бұрын
This is fantastic. You have a new subscriber now. I'm sending this to everybody I know. I am an IT nerd, I know DNS queries are not encrypted, but just felt like that would be out of my control. Great information. Thanks!
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Thanks for subscribing!
@OcteractSG
@OcteractSG Жыл бұрын
Securing DNS is good, but ISPs can still do reverse DNS lookups on the IP addresses you connect to. There is also SNI exposures in the TLS handshakes between your browser and websites, which will usually reveal the domain name of the server (if the server is named after its domain, which many are). The real value of using Quad9 is in mitigating the actions of lazy ISPs and the DNS security feature that Quad9 provides (which is blocking known malicious domains).
@bgroesser
@bgroesser Жыл бұрын
I was thinking the same. Traffic still needs routing.
@ralphm6901
@ralphm6901 Жыл бұрын
@@bgroesser right. The IP address has to be unencrypted to use it, because numerous routers and switches have to be able to route it correctly. The first stop out the door is your own ISP, who can do a reverse lookup on the IP and get the domain name, then log the fact that YOUR IP address went to THAT server.
@Glutzie
@Glutzie Жыл бұрын
Exactly
@cre8tivebreed
@cre8tivebreed Жыл бұрын
What's the alternative or solution?
@damiendye6623
@damiendye6623 Жыл бұрын
​@@cre8tivebreednothing because it's an envelope. You don't encrypt the address when posting a letter.
@collectorguy3919
@collectorguy3919 Жыл бұрын
Thank-you Naomi. Every time I watch one of your videos, I improve my privacy/security by one significant step. This time, I tweaked my Pi-hole to use DNSSEC, because for no good reason I had it configured incorrectly. Perhaps pfSense or OPNsense is a better choice (?), but using the Pi-hole is effective and eye opening. (you don't need a Raspberry Pi, mine is running in a Proxmox VM)
@tigreonice2339
@tigreonice2339 Жыл бұрын
Ward. What and how to install, to block all youtube adds in the network, even in smart tv
@MrDimn
@MrDimn Жыл бұрын
@collectorguy3919 - I am building a similar setup as you have. Using Pi-hole or Adguard to block ads, and using OPNsense as my firewall. But now, I've got a few new features to add - and all because of @Naomi. Great video!
@handsomehobo6434
@handsomehobo6434 Жыл бұрын
Alright, i’ve watched a handful of your videos now. Holy hell, these are fantastic. I have seen a ton of educational privacy content, but your channel is hands down the best, and criminally under subscribed. Somehow you perfectly thread the needle, being able to conceptualize ideas for the privacy and security hobbyist like myself in an easy to understand package. Please keep up the good work Naomi and team. You have yourself a viewer for life. Cheers!
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Thanks for watching!
@SoundMediaVibes
@SoundMediaVibes Жыл бұрын
@@NaomiBrockwellTV Hi Naomi, If I use TOR would that be the same or better than DNS encryption?
@Adam01Time
@Adam01Time Жыл бұрын
Well you believe this sht then I got free property in Hawaii . A DNS is a portal. And you all have no clue wtf a DNS means. I got cotton candy children.
@TheDeanCStone
@TheDeanCStone Жыл бұрын
Hi Naomi, I love all your videos! I was really excited to learn that the Texas Legislature just passed the Texas Data Privacy and Security Act. (Aka HB4 by Capriglione.) Sadly it doesn't go into effect for a year. I hear other States have similar efforts. Maybe it's a little early, but I'd love to see you do a video on this. I was getting sick of reading all the privacy policies and CA had the only Opt out exception. Keep up the great work! We are winning!
@therealb888
@therealb888 Жыл бұрын
That's great to hear. Honestly texas is one of my favorite states
@ericv738
@ericv738 Жыл бұрын
I suspect the only reason we're allowed to feel like we're winning and actually gaining ground in terms of privacy... Is because they have new methods of surveillance we aren't even aware of yet.
@jirehla-ab1671
@jirehla-ab1671 Жыл бұрын
​​@@therealb888a it possible to route my internet from a Huawei router to pfsense?
@0secdox
@0secdox Жыл бұрын
​@@therealb888great idea for a video! I hope you decide to never stop 👏 🎉
@fotisgezepis7016
@fotisgezepis7016 Жыл бұрын
Sharp, independent, practical, precisely detailed content for the security conscious user. More please! And thank you!
@area_5049
@area_5049 Жыл бұрын
Independent??
@genkiferal7178
@genkiferal7178 Жыл бұрын
very *dependent* on companies or orgs @@area_5049
@y_strikes2770
@y_strikes2770 Жыл бұрын
Yeah, independent?
@weapoolx182
@weapoolx182 Жыл бұрын
@@y_strikes2770 Yeah, she's a secret G-woman. 😏
@MakeitZUPER
@MakeitZUPER Жыл бұрын
I am so incredibly happy that I have just found your platform/channel. This is the information that I have been trying to find for the past few months. I had always known that internet data was collected but I've only recently found out how intrusive it really is. Thank you so very much for your clear presentations. They are full of facts and the answers to my questions. As the narration is going on, a question forms in my mind and is almost immediately answered as if almost telepathically, lol. It's very obvious how much effort goes into a high-quality production like this given it's forward thinking. The person/people/team responsible for this extremely well executed presentation is one of the finest I have ever seen. I say that because I have never tried to find a true favorite yet but I see no reason why this wouldn't be a contender for the best. I say this as completely unbiased even though I have had an attraction to red since I was 2 years old, lol. Thanks again, I will be absorbing all the knowledge that I can from your productions. I wish you good luck during the turbulent economy that is looming over us and will likely last a decade or so.
@StrummerDave
@StrummerDave 6 ай бұрын
Not everything on this channel is correct. Don’t believe things just because they are on KZbin.
@MrRoda8143
@MrRoda8143 5 ай бұрын
​@@StrummerDaveso what's not correct? Care to enlighten the rest of us what this channel is giving misinformation
@JustARandomSomething
@JustARandomSomething Жыл бұрын
Stumbled across your channel recently after watching some videos on privacy. I'm now on a binge sesh of your vids. Even watched 2 of your conferences. Really good content. Subed after the 1st video.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Thanks for your support!
@Steven_nevetS
@Steven_nevetS Жыл бұрын
Excellent information again Naomi! Thank you
@jimboelterdotcomm9153
@jimboelterdotcomm9153 Жыл бұрын
This is a great mix of technical knowledge and "street level" accessibility> Very impressive!
@aphanic
@aphanic Жыл бұрын
I don't know if anyone has mentioned it already, but even with DoH (DNS over HTTPS), DoT (DNS over TLS) the TLS ClientHello packet is *not* encrypted, and yet they contain the domain you want to access. Not a whole lot of DPI (Deep Packet Inspection) needs to be done to guess where that particular user is going to, regardless of the upstream DNS server used... _(let's forget about DPI though, keep the talk on DNS)_ TLS 1.3 has an extension, ESNI (Encrypted Server Name Indication), so if employed as long as queries to the resolvers are done through encrypted DNS protocols (by the way, how come DNSCrypt wasn't mentioned? I think all of Quad9's servers support it too and there's at least a plugin for those using unbound :). ESNI alone wouldn't do much when used with the traditional DNS protocols, ECH (Encrypted ClientHello) would though! The ClientHello packet would be encrypted, but I haven't seen many (servers and clients, meaning not only OSes but also apps) support it, but I think it hasn't passed the draft stage yet, it is to be another TLS extension (so DoH, DoT would benefit). When do we get support for it across the board, even as experimental?
@marhensa
@marhensa Жыл бұрын
even with DoH, while domain destination is encrypted BUT the provider still could identity IP of server we are connecting, and from them they could simply associating it with some service or some website.
@deHakkelaar1
@deHakkelaar1 Жыл бұрын
Was looking for this comment without having seen the vid yet.
@sourcebased
@sourcebased Жыл бұрын
@@marhensaThat! You need a provider or proxy you can trust, not only with DNS.
@marhensa
@marhensa Жыл бұрын
@@sourcebased yes that, also it's possible to host your own VPN server on VPS provider you can trust. even that VPS provider still could identify what IP you are connecting via VPN. using VPN and then browsing with ToR is for me the safest for now, but it will slows down the internet connection by a lot. but we don't need that extra privacy and security everyday, so it's just an occassional thing.
@sourcebased
@sourcebased Жыл бұрын
@@marhensa Yes, I was talking only about that practical everyday usage. If you need a higher level of anonymity, using Tor is the least indeed. Best used with Tails and changing hardware and location. I am glad that I don’t really need this in practical terms but I am aware that my internet usage is an open book to my provider and some players on the state services level, as well as my OS and hardware vendors to some degree. I just try to be conscious and selective with who could spy on me and what for.
@Breeegz
@Breeegz Жыл бұрын
DNS is key, and I think you covered this topic with the perfect amount of details. Just enough to get the point across, without bogging it down with the details. I would add PiHole or some other ad-blocker to your series of videos on this topic, where every webpage you load, there's no telling how many different servers that you make DNS requests for. Each frame, each advertisment, each Third-Party cookie you download is a website that can see your traffic and that you visited that particular website. By pointing those rogue DNS requests to a sinkhole, you protect yourself from some of the other types of tracking that happens as you visit websites.
@Bond2025
@Bond2025 Жыл бұрын
I would suggest AdGuardHome on a raspberrypi. It has everything built in and ready to go with just two commands to set it up, it also updates from the web interface, so no messing about with SSH. You set it up and it works. It already has DoH DNS over HTTPS built in unlike PiHole and does not need various modules or bits added on - plus it is far more stable and you can set and forget. AGH is far more stable than pihole and programming is far better, plus they fix any faults - you don't get arrogant people on a forum who don't know how to do things. The other handy thing is AGH does not have the many faults of PiHole. One fault PiHole has is chewing up SD cards by continuous writing to them. This makes systems fail regularly because of poor programming. There are various fixes and commands to use on PiHole and bits to add on, then procedures to update, but do people really want an unfinished product being trusted with their data? AdGuardHome is what PiHole wanted to be!
@keylanoslokj1806
@keylanoslokj1806 Жыл бұрын
Can you elaborate a bit on how that works?
@jeremymoon9088
@jeremymoon9088 Жыл бұрын
What's the "perfect amount" of details? Information isn't a spice, u know? What I hear u saying is she doesn't provide enough info; but since every comment only kisses Naomi's ass, ur fine with her leaving it out.
@funbucket09
@funbucket09 Жыл бұрын
@@jeremymoon9088 they are all simps. If a bloke did the exact same video all these people would rage about how wrong and vague the info was. I have seen this exact thing on videos that had the same approximate scope. The only difference was a male presenter. Everyone raged
@jeremymoon9088
@jeremymoon9088 Жыл бұрын
@funbucket09 u read my mind! I actually used the word "simp" when I typed that comment; but I edited it before I posted it, because I didn't want to trigger anyone. Have u ever seen Jay at Learn Linux TV interview her? He gets all nervous and wimpy, it's some top level simpin. It's amazing how the internet will give an average woman attention as if she were a super model
@MaxPower-11
@MaxPower-11 Жыл бұрын
If the goal of this action is to limit your ISP from capturing your DNS queries then it is of very limited utility. Your ISP can simply do a reverse DNS lookup on the target IP address in the packets you send out once you received your name resolution from your encrypted DNS.
@breakfastattwilight
@breakfastattwilight 11 ай бұрын
Indeed, it feels like an ad.
@stonent
@stonent 11 ай бұрын
Yeah, you'd still want a VPN to hide that traffic.
@Vainglory100
@Vainglory100 Ай бұрын
What if you use TLS?
@MaxPower-11
@MaxPower-11 Ай бұрын
@@Vainglory100 Won’t make a difference. You have to provide your ISP with the destination address, which they can simply run a reverse lookup on. If you really want your ISP not to know where you’re going then you need to use a VPN or some other network tunneling scheme to some remote endpoint that will serve as your gateway to the internet.
@martinwalker3088
@martinwalker3088 Жыл бұрын
Thank you once again Naomi. That was really informative and I'll need to watch this several times to get my head around this!!
@gregsayshi
@gregsayshi Жыл бұрын
Yes, I’d have to agree with the others @Naomi you stand out as one of the best educational KZbinrs for me! Your depth of coverage on these topics is amazing considering how entertaining and digestible you manage to make them. Thank you for putting out content that raises the bar on all fronts. :)
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
I really appreciate your kind words!
@0secdox
@0secdox Жыл бұрын
You deserve the kind words. I've learned so much from you extremely detailed videos. ❤ another fantastic video
@milo-qh7cv
@milo-qh7cv Жыл бұрын
just ask her out already jeez
@parasportz
@parasportz Жыл бұрын
​@@NaomiBrockwellTVHey Naiomi. Don't mean to hijack the thread...have you heard of 4freedom mobile? Supposedly a privacy focussed mobile service provider which works in Australia, apparently. Do you know much about it?
@sulemanalrajhy330
@sulemanalrajhy330 Жыл бұрын
All my data is saved and logged in physical memory inside the server that inside the room of isp when they need it just memory and some tools the to see everything I did from the day I subscribed until now In the other side vpn and some step can help you to stay away from hackers and company, website ets... anything away from isp because the isp is the hub where my traffic gose and come from 🤭
@jajwarehouse1
@jajwarehouse1 Жыл бұрын
Thank you for this, Naomi!
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
You are welcome!
@tsundokujim
@tsundokujim Жыл бұрын
PFSense is increasingly focusing on its proprietary commercial PFSense+ product, at the expense of the open source Community Edition. CE is updated far less frequently than PFS+ and doesn't receive a lot of the features of the commercial product. I moved to OPNSense last year for this reason. It's open source and actively developed, so it's likely to be a much better product over the longer term.
@thebugg333
@thebugg333 Жыл бұрын
Well for home use PF+ is free and the license is not expensive considering the cost of hardware or VM. Not sure what you mean by proprietary either. I had ongoing DNS issues a couple of years back on CE but my device has been stable and with + for home it's an advantage. Either solutions are better than an off the shelf solution at walmart or best buy.
@IDF4HELL
@IDF4HELL 11 ай бұрын
I find tip videos like these get more people in the line of fire. Have you ever heard of Reverse DNS look up? Or perhaps fingerprinting? They can easily see past this. ISP have also reported that they slow down users found doing this.
@chrisyoung8062
@chrisyoung8062 Жыл бұрын
I really appreciate this video and the Quad9 tip. I set up DoH (DNS over HTTPS) in just a few minutes on my MikroTik router running routerOS. Also installed the Quad9 android app on my phone.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
nice!
@tacticalcenter8658
@tacticalcenter8658 11 ай бұрын
Avoid quad 9.
@chrisyoung8062
@chrisyoung8062 11 ай бұрын
@@tacticalcenter8658 Why?
@RealEstate3D
@RealEstate3D 11 ай бұрын
@@tacticalcenter8658Why? Any information would be appreciated.
@Aquabyte
@Aquabyte 5 ай бұрын
​@@tacticalcenter8658Why to avoid Quad9?
@Shrapnel_Music
@Shrapnel_Music 11 ай бұрын
EDIT: To Clear up something: I am "NOT" basing the video at all. I liked the video, it was produced great as always, below is just my thoughts. Not bad at the video. I hope I'm making sense, opening peoples minds to conversation on things? Is that the way to say it? Here is why all this stuff is pointless. Start at problem. (Us). Our computer -> Our Router -> Our Modem -> Their sub station -> everywhere else your cloudflare all that. This is a 'false' since of security; like a front door made of glass with a deadbolt on it and you think it has you covered. It don't. Proof in pudding, check your IP's config and all before and after and not just literally your IP. Look at the packets, we change nothing and it goes to the "ISP" Before any other DNS can grab it. Other wise you would have "hacked" free internet somehow, just think about it. If you don't have to go through the ISP and get online why would you? See pipe dream..
@DJ-Daz
@DJ-Daz 11 ай бұрын
PFSense gives the user more control, but Pi-Hole lets you add Quad9 (IPv4 and v6) and enable DNSSEC all very easily (within settings, DNS tab).
@Prime_Animal
@Prime_Animal Жыл бұрын
fantastic! just subscribed without thinking. love the content
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Thanks and welcome!
@rajughorai7483
@rajughorai7483 Жыл бұрын
Like your way to explain it make it very simple, well for me I have been using pihole and unbound for more than year and it simple to setup up
@towkukus
@towkukus Жыл бұрын
OK, we can encrypt our DNS queries. But all DNS servers belong to either ISPs, private entities (Google for example) etc. So at the end our DNS queries will still end up with one or the other DNS service provider.
@reaperinsaltbrine5211
@reaperinsaltbrine5211 10 ай бұрын
what basic DNS encryption (from both the client and service side) does is that one at least can be somewhat confident that the data is actually correct and not spoofed. The DNS client code of all widespread OSes (even Windows!) have supported it for quite a long time. That many applications don't make use of it is a different matter. All current widely used nameservers (BIND, NSD, PowerDNS, KNOT,...) comes supporting it by default. Setting it up can be challenging if it's your first time, but it is worth it.
@IntangirVoluntaryist
@IntangirVoluntaryist Ай бұрын
I love you❤❤, and not just because you're impossibly cute, but you are so brilliant and great at explaining everything. I looked this up and saw other jokers with useless nonsense and sales pitches for vpns, but I saw you on the list and already enjoyed your videos on many other topics so I watched yours and it's perfect! you focus on actually HELPING people ❤❤❤❤
@NaomiBrockwellTV
@NaomiBrockwellTV Ай бұрын
Thanks so much for watching!
@Elemino
@Elemino Жыл бұрын
I tried to do this on my pfSense install and then I couldn’t get web pages to load. Eventually, I discovered you also have to uncheck “Enable DNSSEC Support” for this to work. After that, I had no problems. I hope this helps!
@omega.Networx
@omega.Networx Жыл бұрын
Can u do me a favor sir 🙏? Can you let me know if you can see my comments on here? I don't understand other than being shadow banned, (which they say isn't real) as to why whenever I comment something, that is probably important to this dns subject, not one person says anything , I would really appreciate it. I have made 3 comments , 2 comments 12 days ago, and one a few mins ago.
@Elemino
@Elemino Жыл бұрын
@@omega.Networx yes
@beefjerky5708
@beefjerky5708 4 ай бұрын
KZbin mixes up the comments. It's very difficult to find anything you have commented on as it gets burried quickly. Even when they send you an email you can't get back to the original comment. It's a crappy system.
@SayAhh
@SayAhh Жыл бұрын
Unsure if you've ever covered it before, but should we be concerned about AdBlock Plus and uBlock Origin when it comes to privacy and security?
@Shrapnel_Music
@Shrapnel_Music 11 ай бұрын
I know this is old. I'm thinking you found your answer but if you didn't. I'd like to try to help, I'd use uBlock Origin. It's the one I use it's 100% open source, and I looked through I haven't found anything wrong. uBlock is 100% safe though for sure (example what it does, blocks javascripts from a server (googles) and returns null; instead of a value. The other thing is it just blocks HTML elements). This is why they hate the F12 button, lol. P.S. If any other extention has a blocker in it, like I use watchmaker it has one. Make sure to turn that off, it's not a security thing; it will just make videos not load. Much Love and Respect
@bryndal36
@bryndal36 Жыл бұрын
Even though Quad9 says they don't do anything with your data, how do they make money? I don't trust any of them no matter how secure they say they are.
@grabantot1648
@grabantot1648 Жыл бұрын
According to their webpage they live on donations. Someone has to make money here. Where is their infrastructure located, who provides the servers/data centers?
@mrmotofy
@mrmotofy Жыл бұрын
Many have another income source
@emilymarriott5927
@emilymarriott5927 Жыл бұрын
At the moment I'm using Technitium DNS in a docker container, but yeah. The fact that it's just communicating unencrypted with upstream authoritative servers is a concern to me. I don't have a pfsense router at the moment, so I'll likely have to deal with configuring unbound directly. I don't want to give up having a DNS resolve my local home lab addresses, so I'll figure out unbound.
@boink800
@boink800 Жыл бұрын
Likewise, OpenWrt can be used as well as pfsense and OpenSense.
@not12listen
@not12listen Жыл бұрын
I've been on a security/privacy kick for a while now. This is something that I knew only 1 tiny bit about, but certainly not enough to make effective changes. I'll be going through the process of seeing how to implement this on my IPFire / Pi-Hole setup. Worst case scenario, I have no issues with replacing IPFire with PFSense.
@StrummerDave
@StrummerDave 6 ай бұрын
DNS queries do not contain the complete URL of a request. They only contain the FQDN. Even if you run your own resolver, the ISP can still see where you are browsing by doing a reverse lookup on the destination IP of the request. If the request is not encrypted, the ISP will be able to see the entire URL. Luckily, most requests are encrypted. That said, Server Name Indication is always in clear and can leak information.
@InnerHacking
@InnerHacking 19 күн бұрын
2:45 Even if it is on their terms of service that the ISP is not using your data... do you believe them just because they say so?
@trparky
@trparky Жыл бұрын
I wonder why Cloudflare wasn't mentioned, they seem to get good reviews especially on the privacy front. Even Mozilla trusts them to use them as the default DNS server in Firefox.
@richardharker2775
@richardharker2775 Жыл бұрын
Most of this is over my head but still interests me. I have Quad9 set on my router and I'm hoping this helps within my home network.
@aphanic
@aphanic Жыл бұрын
In simple terms what the video is about is the confidentiality of the DNS protocol itself (there is none, because it goes in the clear) and what to do about it, hence the suggestion to use an encrypted DNS protocol (DoH, DoT, DNSCrypt) instead of the traditional one. Switching to using Quad9 in your router instead of the ISP set servers (I suppose) doesn't really help in that regard I'm afraid, unless your router is using any of those protocols. It does, however, help if your ISP were doing some sort of filtering through their DNS servers, plus, the default DNS servers for Quad9 offer some threat protection at that level by denying connections to known malicious domains.
@jfiosi
@jfiosi 11 ай бұрын
Clear, detailed, informative and user-friendly. Only home-made french toast with fruit toppings is tastier.
@vulcan6940
@vulcan6940 Жыл бұрын
Good info as usual but what is the relationship of this privacy method to that of using a VPN. Can this be used instead of a VPN, in conjunction with a VPN or does using either/or still provide a similar level of privacy? Your videos are awesome!
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Usually when you use a VPN the VPN provider is handling your DNS. But if you have any other devices on your network like IoT devices, phones that don't have a vpn, etc, then changing your DNS settings is still a big help!
@vulcan6940
@vulcan6940 Жыл бұрын
@@NaomiBrockwellTV Thank you!
@alfepalfe
@alfepalfe Жыл бұрын
Also, remember that most VPN providers are not as secure as they claim and most will happily give away data if asked by a government agency or police. From what little research I have made Mullvad VPN seems to be one of the better ones but please do your own research.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
@@alfepalfe Mullvad seems very good
@simonbackwash
@simonbackwash Жыл бұрын
@@alfepalfe Sorry to pilled up but still in doubts regarding OP question: If you do not trust your VPN provider is it technically possible to use both this amazing and simple method as shown in the video + A VPN ? (Let's say i'm stuck for 2 years with a Nord membership multi devices plan ? Would it make any sense or simply work to Change my DNS before Data's connect to a one of Nord's Node ? Or it works the other way around in this case i get it and have to choose one or the other....👍 Awesome videos👍, fantastic channel🙏 Since i've discovered it i'm bingeing it like a maniac but the 🐇 hole 🕳️ is Deep... The more i'm learning, the more questions and complex you discover how hard it became to preserve your privacy or just encrypt your clouds data's, photos, email, Google Photo's face recognition and Metadata's usage is freaking me out😱. Govs don't even need anymore datas for their CBDS's Digital ID's we've been face scanned and analysed for years 😤🤦🏻‍♂️They crosscheck with others services from Google Ecosystem and even third party. Feels like an endless work even migrating on Linux, and assuming Google Drive or Dropbox, all cloud storage companies, really delete your datas if you terminate/delete your accounts, or encrypt on Local using an offline open source file encryptor and re-synch the encrypted content. And even by doing that you may trigger attention and have no proof and they wont retain your non end to end encrypted re-synched or deleted data's🤦🏻‍♂️🤬👨‍💻. Who knows what is their real retention time if any ? It's really full-time job! 🤯🛂🧿👩‍💻🏦🕳️
@traian658
@traian658 6 ай бұрын
Ok that sounds fine but a step by step from start to finish it will help and also to touch if we use our own wire guard server and if so how this can help even more ? Also please touch the subject of speed as speed this days is important
@M3PH11
@M3PH11 Жыл бұрын
2:45 i just want to point out that in the UK it is a legal requirement that isp's snoop your DNS traffic in order to enact blocking of p2p sharing sites. If you live in the UK, you need to manually set your DNS server ip's in your router to a service that supports DoH and malicious site blocking 4:45 this is why you don;t use unbound and you run another machine behind the pfsense box that can run an encrypted resolver (and now we are getting into territory where some basic IT qualifications would be nice)
@1Corinthians15v1-4
@1Corinthians15v1-4 Жыл бұрын
I'd love to see some pfSense videos both on this topic and beyond.
@gasparem16
@gasparem16 Жыл бұрын
great video! I haven't been thinking about DNS encryption but now is cristal clear that it is super easy to profile users by doing this. Will change to this setup. Thanks!
@justme-n-gracie
@justme-n-gracie Жыл бұрын
SMH... I am already using Ubuntu latest ver. and did not want to change OS... I did a little investigation and found that unbound is available in the Ubuntu repositories... I have now spent almost 10 hours trying to make it work........ I get it that PFSense has a GUI that makes this a lot easier but I am not going to change OS! I may have to set up another machine just to encrypt and forward traffic with PFSense... but shouldn't have to. I have changed my DNS settings in Ubuntu to use Cloud9 but no encryption until I get unbound to function or my head explodes... iffy which one will happen first.
@nellos4ever
@nellos4ever Жыл бұрын
Thank you to Naomi Brockwell, John Todd and all the NBTV team! One small question: After switching to quad9 is there a way to know that the switch is indeed working? Like a linux terminal command... I could even settle for windows cmd command. Wishing you a nice evening!
@petersmith-iz6im
@petersmith-iz6im 4 ай бұрын
I like the song too ! Will I actually attempt all these security features? I dunno,
@iwannacutube
@iwannacutube Жыл бұрын
Very nice video Naomi and very very well presented, Thank you!
@NickSale-q6y
@NickSale-q6y Жыл бұрын
I'm too lazy to do all this! But I got a GLinet Flint router with OpenWRT pre-installed. There I turn on Tailscale and AdBlock Home, where I think I did some of what you did on this video. I think. I'm not sure. Would be nice if you can make a video using OpenWRT, Tailscale and AdBlock Home.
@vla2uv
@vla2uv 11 ай бұрын
How about those that don't have pfSense routers, how can I enable DNS quad9 in an Asus Router? Update: Asus routers come with those DNS settings and I've already changed to quad9 DNS' settings! Thanks a lot!
@angelh1743
@angelh1743 7 ай бұрын
Thank you. That's 2 great videos so far. I'm now subscribed and I just might see ya at DEFCON conference now that I know what it is.
@chralber2000
@chralber2000 Жыл бұрын
We will never be sure if it saves if DNS is not encrypted. Quad9 is sponsoring this video and says there are not looking in your traffic, what is there benefit to move all traffic to them ask your self? But one Positive site on this is that their headquarters are in Swiss. Anyway nice video
@nazdabner2685
@nazdabner2685 3 ай бұрын
Very good content but.. what do we buy? Do we download software? Hardware? Etc..
@crazysquirrel9425
@crazysquirrel9425 4 ай бұрын
Need more info on quad9 and how to get mx linux to use it. Other linux distros have little problem, except that one.
@terminator2513
@terminator2513 Жыл бұрын
Love you Naomi❤🙏
@MM-he2iq
@MM-he2iq 10 ай бұрын
The poster thanking Snowden is enough to earn a sub
@germanarturo11
@germanarturo11 Жыл бұрын
This is great information as usual, and you always beautiful Naomi, if I could I would hire you with no hesitation.
@BitcoinNewsTodayLive
@BitcoinNewsTodayLive Жыл бұрын
Thanks for the info drop Naomi!
@evodefense
@evodefense Жыл бұрын
Amazing video thank you for the explanations and looking forward to follow up video!
@nevarius9010
@nevarius9010 Жыл бұрын
What a fantastic video, you earned this sub.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Grazie!
@mr.shredder5430
@mr.shredder5430 6 ай бұрын
Naomi just one question, is it safe for online transaction? since it is an open source system.
@NIAtoolkit
@NIAtoolkit Жыл бұрын
Wouldn’t the ISP know the sites you visit by reversing the DNS process given they can see the IP addresses?
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
The ISP can't see the IP address you're visiting if you use a VPN
@1983Bantam
@1983Bantam Жыл бұрын
Most websites are hosted on IP addresses that host lots of other websites, so no, but SNI would still reveal where you're going. VPN solves this but then the VPN can see that.
@specialk9999
@specialk9999 Жыл бұрын
I didn’t understand any of this. What is PF sense and unbound? So you have to use 3 different things (PFsense, Unbound and Quad 9) to make it private?
@Jannickjay
@Jannickjay Жыл бұрын
Pfsense are one of the firewall OS you can install as your router( u need hardware ). Unbound is like an add-on integrate in this OS. Quad offer a service you can point ip from your router.
@specialk9999
@specialk9999 Жыл бұрын
@@Jannickjay okay, thanks for explaining that. This all sounds out of my skill set to setup.
@1983Bantam
@1983Bantam Жыл бұрын
All of this is pointless if you connect to a secure site and negotiate the certificate using SNI (which is pretty much every website), anybody can see the exact information you'd request via DNS in clear text. This kind of snooping is less common than using DNS data, though.
@PSL1969
@PSL1969 Жыл бұрын
Any way to prevent this?
@aphanic
@aphanic Жыл бұрын
@@PSL1969 ESNI, extension in TLS 1.3, or even better ECH (Encrypted ClientHello) where that packet of TLS is fully encrypted, but there isn't much support for either that I know of. ECH is to be an extension to TLS (has it made it already?) so _as long as_ the connection to the server is done over TLS 1.x (being x the one supporting it) you'd be golden, but it'd require the browser, for example, to also know about it. I believe AdGuard (client app, not the browser extension) recently launched a version enabling ECH throughout, but I have yet to see how it behaves.
@Bond2025
@Bond2025 Жыл бұрын
@@PSL1969 The rest of us used ESNI for years! Encrypted, it was a setting in Firefox for ages. There is a modified version of this in modern browsers now called something else. ECH. A sort of "encrypted hello"!
@tonykeltsflorida
@tonykeltsflorida Жыл бұрын
My phone dns is set for the quad9 service. I have had it set for about a year and it seems to work just fine.
@tigreonice2339
@tigreonice2339 Жыл бұрын
Pihole, Pfsense, OPNsense... What and how to install, to block all youtube adds in the network, even in smart tv
@23432
@23432 Жыл бұрын
I don't for a minute presume that internet activity is private. Why would that be true, it must be paid for somehow? Still, I would jump right in and follow these instructions, except I have NO WAY to verify what happens beyond my router. Doing this might just open the door even wider for those who are looking in. Or is there? That would be a good episode!
@quickmythril2398
@quickmythril2398 Жыл бұрын
can you please show us how we could set this up using pihole/unbound instead of pfsense/unbound ?
@thebugg333
@thebugg333 Жыл бұрын
There about 1,000 existing well made videos already. What should be a concern is blocking time requests on your devices if you have a smart device. There are Chinese hard coded time request that go to china, even if it's "open source" and an "American" company....like the Phillips hue bridge No reason for the device to "sync" time in that region when it's most likely collecting data using those ports under the radar.
@quickmythril2398
@quickmythril2398 Жыл бұрын
​@@thebugg333 i don't own those things. no plans to buy them, so that's not a concern for me. not sure why this reply goes with my message. yes i can find guides for myself, but this is the channel i'm watching and interacting with, and i wanted to voice my support for pihole. how can she know what her community is doing if we don't communicate?
@1mouseman
@1mouseman Жыл бұрын
Well done, and so easy to understand. I know nothing about computers, but this was easy to follow. Thanks!
@nwogamesalert
@nwogamesalert Жыл бұрын
@Naomi - As I understand it, PfSense has to be installed on a router? 1) Can it be installed it on a PC instead, so it will work when I connect to the internet from varying locations? 2) What if I use a USB modem with sim card & subscription for my internet connection? Can PfSense be used in this setup? 3) If it can be installed on a PC, does it use many resources, in other words, will it slowdown my PC?
@mrmotofy
@mrmotofy Жыл бұрын
pfSense/OpnSense is a router software or operating system and yes it can be run on any regular pc like an older Dell Optiplex. Add a dual or quad NIC and you have enterprise level router capabilities
@nwogamesalert
@nwogamesalert Жыл бұрын
@@mrmotofy Thanks for the information!
@AldarisFenrir
@AldarisFenrir Жыл бұрын
If you are insterested in secure your navigation, you are kinda screw, couse your fist problem is that you using google, whatsap, facebook, instagram... and a lot of others social media. These entities are already taking your information and profiling you. And you give them all your data for free. If you want to skip the dns of your provider, it is as simple as changing the dns of your pc or your router to a different one from your ISP But if your isp capture all dns requests you cant bypass isp dns. The next point is that most ISPs should be able to capture your dns request because if the authorities in your country ask for a report on a particular user, the ISP should respond. This is for legal issues like pedophilia, drugs and other illegal things. No matter how hard you try to hide or resolve your requests with another dns provider, at some point you will reach a dns server can be interfered in some way. There is no single dns server and no dns server knows all the possibilities for the pages you are looking for, dns servers ask each other when they can't find a site. In general professionally speaking nobody messes with anyone's dns requests unless you are involved in something illegal and the government asks for it. Also keep in mind that changing the dns can cause browsing problems, longer resolution times or not being able to enter a particular site. Sorry if there is a spelling mistake, English is not my natural language =)
@jozsefizsak
@jozsefizsak Жыл бұрын
Thank you once again for all your wonderful work!
@timetriad6199
@timetriad6199 Жыл бұрын
What about those NOT using pfSense?
@josephjefferson6368
@josephjefferson6368 11 ай бұрын
Can I ask a question, Naomi? How did you form your I.T. connections with folks like John, Brent, etc.?
@s.j.5850
@s.j.5850 Жыл бұрын
Great information, especially for someone just getting into networking.
@charld
@charld 7 ай бұрын
around the @9:46 mark i think you need to call out the option - Allow DNS server list to be overridden by DHCP/PPP on WAN or remote OpenVPN server - needs to be unchecked right?
@nommindymple6241
@nommindymple6241 Жыл бұрын
I've got all of that set up in pfSense. But, what about browser settings? For instance, in Chrome Settings > Privacy and Security > Use Secure DNS: do I leave that off and assume all that will be handled by pfSense before the browser gets involved? Or, do I turn it on and set a service provider? Won't doing that override pfSense's settings?
@TheDevnul
@TheDevnul 10 ай бұрын
So I used to work for an ISP. The thing is every time you access a web page you can be resolving anything from 1 to dozens of various sites. The main site, sub, advertising, provider (Amazon, Microsoft, Apple…) Multiply that with thousands of users, the flow of data is significant. You’re not that interesting.
@deeyadeli1435
@deeyadeli1435 6 ай бұрын
Until you are.
@tomofedek7613
@tomofedek7613 9 ай бұрын
Hi Naomi, is it possible to share link to that podcast you mentioned here ?
@123smartcontent
@123smartcontent Жыл бұрын
Great video! How can you do that for phones or laptops after you leave the security of your home/office network?
@metamask0x
@metamask0x 6 ай бұрын
I got a question , Do you think ISP's can monitor what videos we/you are watching ? What's ur take on this ? The day they can monitor what we see on the website through DNS ,we are toast :)
@DeDraconis
@DeDraconis Жыл бұрын
Doesn't Tor already obfuscate everything like this?
@hmssirius9343
@hmssirius9343 10 ай бұрын
If you had more than one computer, or a laptop, how would you even set all this up? Would you need to do it multiple times? Or have multiple routers for each device?
@robmorin
@robmorin Жыл бұрын
SO I did what is in this video, but how do i verify that my DNS requests are indeed encrypted?
@P4V3LS
@P4V3LS Жыл бұрын
DNS-over-TLS ( DOT) are great but what about reverse ssh tunnels are kind of scary.
@woodygilson3465
@woodygilson3465 Жыл бұрын
All well and good for a home office set-up. What if you're using a cell phone as a hot spot? How would this work out in the wild, as it were?
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
you can change your DNS on any device, but unsure how to set up encrypted DNS on mobile. I'll have a look
@woodygilson3465
@woodygilson3465 Жыл бұрын
@@NaomiBrockwellTV Thanks.
@mrmotofy
@mrmotofy Жыл бұрын
Full tunnel VPN to your home then it should all run through there
@spud76
@spud76 Жыл бұрын
As longe an email is needed to creat a login, your email is being sold. Just think about the smartphone in your hand, and all those privecy settings you have turned off, right. None of them don't matter anyway.
@ParGellen
@ParGellen Жыл бұрын
Sounds great. Unfortunately we have very different definitions of the term "simple"...
@matthijsleenhouts4827
@matthijsleenhouts4827 Жыл бұрын
DNS over TLS in combination with openvpn end your data is standard for encrypting DNS queries to keep them secure and private.
@Jabber_Wock
@Jabber_Wock Жыл бұрын
Naomi thank you for your excellent videos as always. Would you please post the pfsense link? Also, do you have any recommendations for privacy friendly vpn providers? I seem to recall you had a video on this but could not find it on your channel. My vpn subscription is coming up for renewal shortly so this is a good time for me to look at options.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
www.pfsense.org/ Mullvad and protonvpn are good!
@artstation707
@artstation707 Жыл бұрын
@@NaomiBrockwellTV I'm a bit slow when it comes to all of this, and security is a welcomed thing. Could you explain this to me in a more for dummies style? My system in Windows 10 on an intel dual-core chip.
@thanosvad
@thanosvad 11 ай бұрын
Does pfsense need to be running all the time ? If yes , is a rasbbery pi a good idea to run it from?
@ThinkGenius
@ThinkGenius Жыл бұрын
Great! How about NextDNS?
@Bond2025
@Bond2025 Жыл бұрын
They probably sell your info too, but that is not confirmed. They did however change "blacklist" to "blocklist" and "whitelist" to "allowlist" after a user happened to mention it! They seem OK, but police can still request records and they MUST comply as data flows in /thought/out of the UK - exactly the same as others like Quad9, if they have ANY equipment in the UK, the hosting company by Law must log all data even if the company says it has no part in that. Q9 does NOT block trackers and advertising sites which is a huge privacy risk to users.
@boink800
@boink800 Жыл бұрын
NextDNS is great if you want to block ads.
@HexPortal
@HexPortal Жыл бұрын
​@@Bond2025 Have you even read the first line of NextDNS' privacy policy? "1. We do not (and will never) sell, license, sublicense or share any of the data submitted directly or indirectly by our users with any person or entity." And you can manually choose which country you want your logs to be stored in: US, EU, UK and Switzerland. Or disable logging completely.
@JasonWestaway
@JasonWestaway Жыл бұрын
Hi @Naomi, thanks for your content. Have a question, My router is ISP-Locked. If I use quad9 settings in Brave Browser will it still have the same effect? Thanks
@randomraidor
@randomraidor Жыл бұрын
Amazing informative video, the only disturbing thing was *sshh, sssshh* which was coming from your mic, please reduce that
@smilelifeisbeautifulwithou7945
@smilelifeisbeautifulwithou7945 Жыл бұрын
if you setup Simple DNSCrypt on windows can do the same ? can you make a related video (as alternative also secure solution) ?
@SamOween
@SamOween Жыл бұрын
Naomi you are a boss!
@rishibellam738
@rishibellam738 Жыл бұрын
does tor protect you from this?
@speed_rider362
@speed_rider362 Жыл бұрын
You an even encrypt the requests themselves - you can use DNS over HTTPS (DoH) or DNS over TLS (DoT). This way nobody is able to see what pages you browse - not even your ISPs.
@youronlinepresencepro9348
@youronlinepresencepro9348 Жыл бұрын
Great Video as always thank you!
@deus5185
@deus5185 Жыл бұрын
ty very helpfully
DNS Blocklists Explained! Stop Internet Snooping!
16:07
Naomi Brockwell TV
Рет қаралды 56 М.
Should You Remove The SIM In Your Car?
19:56
Naomi Brockwell TV
Рет қаралды 462 М.
Chain Game Strong ⛓️
00:21
Anwar Jibawi
Рет қаралды 41 МЛН
Sigma Kid Mistake #funny #sigma
00:17
CRAZY GREAPA
Рет қаралды 30 МЛН
Une nouvelle voiture pour Noël 🥹
00:28
Nicocapone
Рет қаралды 9 МЛН
No SIM? No Problem!
22:00
Naomi Brockwell TV
Рет қаралды 1,9 МЛН
NEVER install these programs on your PC... EVER!!!
19:26
JayzTwoCents
Рет қаралды 4,5 МЛН
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 1,1 МЛН
What is DNS? (and how it makes the Internet work)
24:22
NetworkChuck
Рет қаралды 290 М.
Incredible Dangers in Browsers (Affects all of them)
21:02
Rob Braxman Tech
Рет қаралды 336 М.
You're running Pi-Hole wrong! Setting up your own Recursive DNS Server!
18:02
“I Have Nothing to Hide” - The Dangerous Myth About Privacy
17:35
Naomi Brockwell TV
Рет қаралды 80 М.
You won't believe how UNSAFE your home router is!
20:56
Naomi Brockwell TV
Рет қаралды 359 М.
Chain Game Strong ⛓️
00:21
Anwar Jibawi
Рет қаралды 41 МЛН