VPN vs DNS - Which Keeps You The Safest?

  Рет қаралды 27,722

Techlore

Techlore

Күн бұрын

Ultimate guide covering the pros/cons of DNS and VPN providers (and sometimes both!) and different possible configurations you can explore to maximize your privacy and security online. Also showcasing custom DNS configurations in relationship with a VPN!
Techlore Resources: techlore.tech/resources
Techlore Forum: discuss.techlore.tech
More on DNS (Technical): aws.amazon.com/route53/what-i...
🔐 Our Website: techlore.tech
🕵 Go Incognito Course - to learn about privacy: techlore.tech/goincognito
🏫 Techlore Coaching - to get direct support: techlore.tech/coaching
💻 Techlore Forum - to connect with other advocates: discuss.techlore.tech
🦣 Mastodon - to stay updated: social.lol/@techlore
We cannot provide our content without our Patrons, huge thanks to:
BRIGHTSIDE, Clark, Ente, Larry, Afonso, Boori, Brad, Casper, Cookie, Floyd, JohnnyO, kevin, love your content, NotSure, Poaclu, x
🧡 Join them on Patreon: / techlore
💚 To see our production gear, privacy tools we use, and other affiliates: techlore.tech/affiliates
💖 All Techlore Support Methods: techlore.tech/support
00:00 VPN or DNS?!
00:10 What Are DNS Providers?
02:14 What are VPN Providers?
03:38 VPN vs DNS
04:30 Your VPN's DNS and What You Should Use
08:26 So what should you do?
#VPN #DNS #privacy

Пікірлер: 86
@techlore
@techlore 2 ай бұрын
I'd love to see the different configurations you all have chosen to use! Leave them below
@RAM_845
@RAM_845 2 ай бұрын
I use Next DNS I pay AUD$3/month it's awesome I've set it at router level and on my mobile phone the Samsung Galaxy Note10+...also we need a VPN that's outside of the 14 eyes surveillance network..search engine I use is qwant. I use torrent sites too
@ignoram9us
@ignoram9us 2 ай бұрын
The last I checked, NextDNS routes the DNS logs you see of your account, on their website, through Google servers in plain text...
@danmar007
@danmar007 2 ай бұрын
I used Nord's DNS servers the longest. They're slow. Then I tried Quad9. Faster than Nord. Then I tried Cloudflare. Very fast. I just moved to NextDNS. We shall see how it performs.
@TheChadXperience909
@TheChadXperience909 2 ай бұрын
I use dnscryptproxy on my OPNsense router. It allows to filter via downloadable black lists, and I also use a filtering DNS provider. So, I should be fairly protected. The included Unbound DNS service can also filter, and it's even possible to add a custom list to that. I have mine handoff the lookups to dnscryptproxy after it resolves any intranet DNS queries. Also, don't forget to setup the cron job to automatically update the DNS black lists and restart the service. Oh yeah... And, it's all no cost, and no subscription. Mine also intercepts all outgoing DNS port 53 traffic.
@darrellm9915
@darrellm9915 Ай бұрын
On an unrelated note, I wanted to ask a question about Monero. If Monero is ever cracked with quantum computers (or anything) could this de-anonymize past transactions? since the blockchain itself is public?... So maybe your transaction is anonymous today, but if in 10 years it gets cracked, could it ever be traced back to us?
@mr.normalguy69
@mr.normalguy69 2 ай бұрын
Me: **Turns off phone and goes outside for a walk** 🍷🗿
@SWUploads971
@SWUploads971 2 ай бұрын
I have a second phone I take for walks
@pewgarpolls
@pewgarpolls 2 ай бұрын
​@@SWUploads971a smartwatch would make sense and theres privacy friendly smartwatch'es. mental outlaw made a video on it a while ago
@kevindetolli
@kevindetolli 2 ай бұрын
and yet, you are here commenting on KZbin hahahahahaha
@youchwb6005
@youchwb6005 2 ай бұрын
@@kevindetolli And apparently, you are not.
@kevindetolli
@kevindetolli 2 ай бұрын
@@youchwb6005 I am!
@MrDowntemp0
@MrDowntemp0 2 ай бұрын
NextVDNS looks kinda neat. But honestly, the last thing I need right now is ANOTHER party to PAY for private internet. Between VPN, private e-mail, and your ISP, and maybe even things like Password Managers, Icogni, etc. internet cost really starts to add up for the privacy focused consumer. So I'm still going to stick with the free DNS options for now. Would love to see a more thorough comparison of modern free DNS providers. Most of the comparisons I find are pretty out of date.
@ultravioletiris6241
@ultravioletiris6241 2 ай бұрын
AdGuard is great for self hosting, it’s also very simple and has features that similar options dont. It’s simpler than pihole in my humble opinion. For everything else your best bet is to secure DNS by making sure it’s set to a proper upstream one such as Mullvad or Quad9. Unfortunately you may have to set this on a per device and per app basis. Each device tends to have different support for encrypted DNS. Apps themselves can also vary. This is what adguard or pihole are great at. You point all DNS to the adguard/pihole, and then from there you have it do the upstream requests in encrypted DNS. The main thing that encrypting DNS does in terms of privacy is make sure that your ISP doesn’t hijack the DNS query on the way out (which apparently happens). A VPN also prevents this because the DNS request is sent through an encrypted tunnel as it goes through the ISP connection. So realistically the minimum setup of good VPN + something like Quad9 DNS is going to do most of your network privacy without getting too into the weeds. Then you have to look at your browser, device, operating system, apps, and other sources of telemetry and metadata fingerprinting. Many of these issues are fixed by using Linux + open source. Anyway this got long, but personally with all that considered I don’t see much need to pay for DNS services. The way i would personally pay for DNS services is by spinning up a cloud VPS with it’s own domain to use as a VPN and reverse proxy. This is pretty common and can be pretty cheap.
@RoyaltyInTraining.
@RoyaltyInTraining. 2 ай бұрын
Enabling Quad9 DNS over HTTPS is the first thing I do when setting up any new PC / browser
@kongstrong88
@kongstrong88 2 ай бұрын
Sadly no word about encrypted DNS. I thought your IPS can't see what you're doing if you're using DNS-over-HTTTPS (except raw IPs).
@bionicbison05
@bionicbison05 2 ай бұрын
Great video! Would love to see a comparison/review of Control D vs. NextDNS, especially since Control D without its proxy features is the same price.
@RealJonzuk
@RealJonzuk 2 ай бұрын
appreciate you uploading these videos so i can easily point to it for my friends that arent informed on this stuff yet
@brockm4047
@brockm4047 2 ай бұрын
Using pihole and masquerading outgoing port 53 back to pihole. Actual outgoing dns requests use DoH to quad9. This works well.
@l0gic23
@l0gic23 2 ай бұрын
Any pointers on where we can learn more?... I'm using pihole and Quad9 but lost on the portion related to port 53 and getting DOH working. Ty
@whiskeylinux
@whiskeylinux 2 ай бұрын
I use PIA's MACE on my local machine + Adguard DNS on the router. Good stuff.
@RAM_845
@RAM_845 2 ай бұрын
I use NextDNS on the router and Adguard extension on my Brave Browser.
@youchwb6005
@youchwb6005 2 ай бұрын
@@RAM_845 Isn't Brave is a Google browser?
@RAM_845
@RAM_845 2 ай бұрын
@@youchwb6005 a modified one
@marcfabricatore1506
@marcfabricatore1506 2 ай бұрын
@@youchwb6005It is based on Chromium. But everything Google related has been ripped out. It is 100% safe to use.
@kueacybtguicyregfibubkueacybax
@kueacybtguicyregfibubkueacybax 2 ай бұрын
Great video going into the details of networking privacy! My current setup (IVPN + NextDNS + Ublock Origin) as well as using generally more privacy friendly services has led to seeing basically no ads ever, less spam, and has generally improved the experience with every new service I use/switch to. Hope you guys keep up the good work.
@pewgarpolls
@pewgarpolls 2 ай бұрын
i expect you to also use revanced or any other private KZbin app edit: but you might not use your phone as an entertainment device
@enigma220
@enigma220 2 ай бұрын
I've always heard that using a DNS provider with a VPN is not a good idea. Instead you should only use the VPNs DNS.... I don't know
@etziowingeler3173
@etziowingeler3173 2 ай бұрын
Most vpn service providers have trackers on board (third party trackers). Even if no personally identifieable information is included, you can be identified easily using a few features). Mostly, people use a VPN and think they're good in terms of privacy. Yeah, well... turns out, no
@kueacybtguicyregfibubkueacybax
@kueacybtguicyregfibubkueacybax 2 ай бұрын
@@enigma220 He covers the topic in the video, VPN dns vs custom DNS. While custom DNS is more idenfiable, the benefits outweigh the cons, and to be honest its such a minor "anti-fingerprinting" measure.
@SagaciousUser
@SagaciousUser 2 ай бұрын
why don't you just use your own VPN?
@persistenthomology
@persistenthomology 2 ай бұрын
the cutest privacy and security host out there!
@peterwassmuth4014
@peterwassmuth4014 2 ай бұрын
Awesome! Thank you for Sharing!
@addy7445
@addy7445 2 ай бұрын
Adguard dns is dope😂 it's an adblock killah
@animeclipz1561
@animeclipz1561 2 ай бұрын
Recently just bought a new iPad and new gaming laptop and one of the first things I did on both devices was change the dns settings to ControlD.
@cakeboss16
@cakeboss16 2 ай бұрын
Have you tried controld? I think it is now better then nextdns by a little
@jdfnorton8570
@jdfnorton8570 2 ай бұрын
Great video, thanks. Do you have any thoughts on ShadowSocks DNS? 👍
@johnhiggins2696
@johnhiggins2696 2 ай бұрын
I have pihole and unbound (local dns) on my nas and use that for local traffic. I'm gonna try to get those accessible from the internet at some point but I haven't looked into it yet.
@Anyoneonyoutubeoffical
@Anyoneonyoutubeoffical 2 ай бұрын
Wonderful video
@YordkarYordkar
@YordkarYordkar 2 ай бұрын
Can you please make a video about securing your pc for online banking?
@youchwb6005
@youchwb6005 2 ай бұрын
Trend Micro has " Pay Guard". It opens in a new isolated window like Sandboxie. Then after your session, delete all the history and cache in that window. Been using for other transaction sites like E bay, etc and never had problems. Other AVs have the same feature.
@-someone-.
@-someone-. 2 ай бұрын
Could pihole be setup to mimic nextDNS?
@Anyoneonyoutubeoffical
@Anyoneonyoutubeoffical 2 ай бұрын
@Techlore Can you do a video on how domain vs website work and a separate video on how to remove domains from Whois websites ?
@jellybean7253
@jellybean7253 2 ай бұрын
So I have both Mullvad and Proton VPN's. I use the default DNS servers in Safari, but, Firefox and Vavaldi I have set to Cloudflare. Brave too. BUT, with all that said, my Router is set to Cloudflare. How does that play in?
@cheesium238
@cheesium238 2 ай бұрын
On the fingerprint side: Michael Bazell pointed out in one of his podcasts, that he uses NextDNS, but a different account for every instance, so one for the base Linux system, another one for the browser, then the phone, etc, etc. Not sure if it makes sense though
@techlore
@techlore 2 ай бұрын
That's definitely a valid option too, you can opt for different configs on different devices w/ different priorities :)
@yeseniasplace
@yeseniasplace 2 ай бұрын
love your jacket and content
@rogerthomas3802
@rogerthomas3802 2 ай бұрын
What about Lokinet?
@user-uh1uo4bo9d
@user-uh1uo4bo9d 2 ай бұрын
which is bette for twiiter opposition in Egypt tor vs mullvad ?mac android?
@OcteractSG
@OcteractSG 2 ай бұрын
How would a website be able to tell what DNS provider you used to reach them? Maybe response time to be transferred to a subdomain could be a clue, but I don’t think there is a definitive way.
@AidenDarling
@AidenDarling Ай бұрын
My first and only thought: *why not just use both!?*
@Placesandspaces35
@Placesandspaces35 9 күн бұрын
Can’t you just use unbound dns and run dns over von then run your devices through a vpn? That way your query is encrypted and then the actual data is encrypted? That is how I run it on my external firewall and no issues thus far.
@l0gic23
@l0gic23 2 ай бұрын
Quad9 all day
@TruePrivacyFactsYT
@TruePrivacyFactsYT Ай бұрын
I actually use proton vpn that is good to know.
@rubysamachisuru5584
@rubysamachisuru5584 2 ай бұрын
Adguard DNS Server review next!
@enigma220
@enigma220 2 ай бұрын
ControlD has the most powerful and revolutionary features than any other DNS provider in the history of DNS. It can do WAY more than NextDNS.
@FEAR_Blu
@FEAR_Blu Ай бұрын
Such as?
@jimmybruneel4540
@jimmybruneel4540 2 ай бұрын
I use portmaster with spn
@Sparky_Chipmunk
@Sparky_Chipmunk 2 ай бұрын
Because pfSense, the VPNs are always on 24/7 and with 1 hour IP rotation. :p
@pmauriciomm
@pmauriciomm 2 ай бұрын
and how having a Pihole in the network goes in all this ?
@claycassin8437
@claycassin8437 2 ай бұрын
I say use both.
@the-lettere
@the-lettere 2 ай бұрын
VPNs vs DNS Chalk vs Cheese
@The_work_grind
@The_work_grind 2 ай бұрын
I still don’t understand how a dns keep you safe
@yurydmorales
@yurydmorales 17 күн бұрын
🎯 Key Takeaways for quick navigation: 00:00 *🌐 DNS providers act like a phone book for the internet, translating domain names into IP addresses.* 00:57 *🛡️ DNS providers can offer security features like anti-phishing protection, but by default, they primarily focus on delivering internet services without harvesting user data.* 02:22 *🔒 VPNs encrypt traffic locally, enhancing security, especially on public Wi-Fi networks, and mask IP addresses to improve privacy.* 05:37 *🔄 VPNs often come with their own DNS, but users can opt for custom DNS providers like Next DNS for enhanced privacy and security features.* 08:52 *🚀 Consider switching to more privacy-respecting DNS providers and evaluate the need for a VPN based on your security and privacy requirements.*
@zippitydoohdangtwang
@zippitydoohdangtwang 2 ай бұрын
The irony is that guys who know how to set up IT security are the guys that don't need it, and vice versa
@goosty17
@goosty17 2 ай бұрын
Can you do a full hair tutorial on a separate video? I really like your hair style
@abdelkaioumbouaicha
@abdelkaioumbouaicha 2 ай бұрын
📝 Summary of Key Points: 📌 DNS providers act as a phone book for the internet, translating domain names into IP addresses. They offer some security features like anti-phishing protection but are primarily focused on providing internet access without compromising privacy. 🧐 VPNs encrypt traffic locally on your device, enhancing security and privacy by masking your IP address. They are used as privacy and security tools, especially on public Wi-Fi networks, to prevent data harvesting by ISPs. 💡 Additional Insights and Observations: 💬 Quotable Moments: DNS providers are like a search engine for the internet, while VPNs are used as privacy and security tools in the digital rights community. 📊 Data and Statistics: VPNs encrypt traffic locally, preventing Wi-Fi networks from accessing data, which is crucial for security. 🌐 References and Sources: The video mentions specific VPN providers like Mulvad, IVPN, ProtonVPN, and Windscribe, highlighting their role in securing web traffic. 📣 Concluding Remarks: The video delves into the differences between DNS providers and VPNs, emphasizing their roles in privacy and security. While DNS providers focus on providing internet access and some security features, VPNs encrypt traffic to enhance privacy and security. Choosing the right DNS provider and VPN can significantly impact your online safety. Generated using TalkBud
@EnglishRain
@EnglishRain 2 ай бұрын
Noice
@INEXTERMINABLE
@INEXTERMINABLE 2 ай бұрын
Bro forgor proxies from this category
@itsjustpersonalizedviews
@itsjustpersonalizedviews 2 ай бұрын
i have dns
@Cruxuh
@Cruxuh 2 ай бұрын
f i r s t
@user-xl5kd6il6c
@user-xl5kd6il6c 2 ай бұрын
7:16 You are wrong on this. There's no advantages to a custom DNS over a VPN regarding privacy. What your custom DNS is doing is blocking stuff, you should be doing that via adblock When you change to a custom DNS over a VPN you are becoming *uniquely identifiable,* which defeats the point of using a VPN
@techlore
@techlore 2 ай бұрын
How do you suppose you block ads and trackers outside a web browser environment? An app with trackers? An OS submitting invasive telemetry? I would take a look at what can be blocked by a DNS provider and how the scope is a bit different. Adblock + DNS together are a very ideal workflow for people who want the best of both worlds. I directly address the ‘identifiable’ argument you make in the video and how it *is* a con to the workflow.
@kueacybtguicyregfibubkueacybax
@kueacybtguicyregfibubkueacybax 2 ай бұрын
​@@techloreAdding to this, the blocklists are very different, with network wide ones having a much more broad scope. An example of this would be blocking youtube and google ads, but not google telemetry/google play services tracking.
@user-xl5kd6il6c
@user-xl5kd6il6c Ай бұрын
@@techlore On your first argument, ad blockers don't do the DNS requests, when a DNS request is made for a domain on their list, the ad blocker intercepts the request and returns a null response As for the latter, it's irrelevant if you "addressed it in the video", you are advising people to do something they absolutely shouldn't. You are giving bad advise that doesn't give neither safety or privacy
@user-xl5kd6il6c
@user-xl5kd6il6c Ай бұрын
@@kueacybtguicyregfibubkueacybax 6:16 As it's in the video, use a VPN provider that provides adblocking via their DNS. But never, NEVER use a VPN with an external custom DNS, specially not NextDNS or similar where your DNS requests go with UNIQUE IDENTIFIERS of your account and your identity
@Stewart-zk1fg
@Stewart-zk1fg Ай бұрын
Your videos lost all meaning for me, after you insulted me, and apparently you're directly hacked into my phone and you're emailing me about it to rub it in. I understand why they call you tech bore now.
Why VPNs are a WASTE of Your Money (usually…)
14:40
Cyberspatial
Рет қаралды 1,4 МЛН
The 2024 VPN Tier List: Privacy & Security Smackdown!
19:29
Techlore
Рет қаралды 34 М.
I MADE A CARDBOARD SWING!#asmr
00:40
HAYATAKU はやたく
Рет қаралды 24 МЛН
Monster dropped gummy bear 👻🤣 #shorts
00:45
Yoeslan
Рет қаралды 11 МЛН
Host Your Own Encrypted DNS Server
24:21
Mental Outlaw
Рет қаралды 110 М.
I'm leaving DuckDuckGo, and here's what I picked...
8:02
Techlore
Рет қаралды 319 М.
Portmaster Intro #4: Allow Connections
2:27
Safing
Рет қаралды 2,3 М.
The VPN You Use Probably Sucks - Here's Why...
9:08
Techlore
Рет қаралды 40 М.
The NAS That Permanently Changed My Privacy Life
15:26
Techlore
Рет қаралды 26 М.
Why I no longer use a VPN (most of the time) and nor should you
11:25
Sun Knudsen
Рет қаралды 1,1 МЛН
Why I Stopped Hardening Firefox.
8:10
Techlore
Рет қаралды 63 М.
phone charge game #viral #tranding #new #reels
0:18
YODHA GAMING RAAS
Рет қаралды 11 МЛН
САМЫЙ дешевый ПК с OZON на RTX 4070
16:16
Мой Компьютер
Рет қаралды 97 М.
🤏 САМЫЙ ТОНКИЙ гаджет #Apple! 🍏
0:29
Яблочный Маньяк
Рет қаралды 602 М.
Главная проблема iPad Pro M4 OLED!
13:04
THE ROCO
Рет қаралды 38 М.