Host Your Own Encrypted DNS Server

Sdílet
Vložit
  • čas přidán 5. 09. 2024

Komentáře • 349

  • @MentalOutlaw
    @MentalOutlaw  Před 8 měsíci +53

    Use this link to get yourself a Vultr VPS
    www.vultr.com/?ref=8791233
    Use this link to get the little daemon T shirt (also available in long sleeve, pullover hoodie, and ladies shirts)
    based.win/product/little-daemon-premium-short-sleeve-t-shirt/

    • @realcartoongirl
      @realcartoongirl Před 8 měsíci +9

      Why you say private then sellout

    • @Drakonak
      @Drakonak Před 8 měsíci

      Do you recommend a specific VPS from vultr or elsewhere?

    • @brettlaw4346
      @brettlaw4346 Před 8 měsíci

      Got any tips for mitigating BGP attacks?

    • @user-yw1nm4je8o
      @user-yw1nm4je8o Před 8 měsíci +2

      Why are you being racist towards indians?

    • @Anon26335
      @Anon26335 Před 8 měsíci

      You are so freaking racist dude, you should delete the thumbnail goofball🤡🤡

  • @njpme
    @njpme Před 8 měsíci +727

    Blink 2 times if you're ok. 3 times if the NSA is holding you hostage

    • @vlad7269
      @vlad7269 Před 8 měsíci +42

      Don't worry he is hiding near police station

    • @Abhinav_Nayana_Sailen
      @Abhinav_Nayana_Sailen Před 8 měsíci +12

      Bro is off-grid...

    • @ultralaggerREV1
      @ultralaggerREV1 Před 8 měsíci +11

      njp, keep posting this comment on future videos. Also ask in livestreams

    • @MoisesCaster
      @MoisesCaster Před 8 měsíci +6

      It's blinking like a Christmas tree

    • @illiiilli24601
      @illiiilli24601 Před 8 měsíci +2

      ​@@Abhinav_Nayana_Sailenbro is a deep fake

  • @dueeek
    @dueeek Před 8 měsíci +93

    Love the Windows XP style theme! Also, yet another high quality video from you, thanks for being awesome man!

  • @Teddev1337
    @Teddev1337 Před 8 měsíci +152

    Love your channel man! We need people like you who care about privacy and freedom in this crazy digital world!

    • @kuchesezik
      @kuchesezik Před 8 měsíci +7

      naomi brockwell, louis rossmann

  • @noctisumbra4656
    @noctisumbra4656 Před 8 měsíci +58

    Merry christmas Kenny, and hopefully a happy new year :^)

    • @MentalOutlaw
      @MentalOutlaw  Před 8 měsíci +33

      Thanks merry Christmas and happy new year to you too!

  • @somerandomguywastaken
    @somerandomguywastaken Před 8 měsíci +826

    Another great deepfake👏

  • @cyberdusttv
    @cyberdusttv Před 8 měsíci +196

    My limited understanding with DNS is that when one does a recursive DNS query, the queried DNS server needs to check the root server first, which eventually tells the DNS server what IP it is searching for. If this is hosted locally, only the local connection to the queried DNS server would be protected by DoH, and the DNS server making the actual query would be in plaintext still. Wouldn't it be actually worse than using a VPS, if you consider the ISP as a bad actor in the proposed threat model, since they can just read the outgoing traffic of the DNS server?

    • @autohmae
      @autohmae Před 8 měsíci +37

      yes, it's worse than a VPS.

    • @seanmoran6683
      @seanmoran6683 Před 8 měsíci

      I think it's pretty silly as well

    • @spoopyangie
      @spoopyangie Před 8 měsíci

      Not sure if is possible with Bind9. But I am using AdguardHome as my local DNS and I set the upstream DNS server as Cloudflare's DOH.
      I noticed a small hit in response times for uncached requests, but other than that. All good!
      So, in theory, the whole DNS request is encrypted - At least till it reaches Cloudflare.
      And of course, blocking trackers and other nasty stuff through DNS blocklists is a very pleasant added bonus.

    • @authenticallysuperficial9874
      @authenticallysuperficial9874 Před 8 měsíci +6

      Yeah hosting it locally would be stupid.

    • @pyromen321
      @pyromen321 Před 8 měsíci +38

      I’d only host this locally if you have a script to do dns requests for random domains constantly, similar to trackmenot

  • @hanelyp1
    @hanelyp1 Před 8 měsíci +37

    The limit I see to privacy in this setup is it still depends on upstream DNS, and your private server may still be traced to you. To improve this you need your private DNS open for wider use, hence ambiguity of who is requesting a lookup.

    • @DogDooWinner
      @DogDooWinner Před 8 měsíci

      I just break in to my neighbors house and use his computer. A few weeks ago, his wife left him due to his apparent affinity for ladyboys. I didn't know he was in to that as well. Him and I should hang out more.

    • @apache937
      @apache937 Před 8 měsíci +5

      his server is open and publicly available. but do you trust kenny?

  • @specthegod
    @specthegod Před 8 měsíci +9

    I havent even watched the video yet... just logged in to give it an instant LIKE and thank you Kenny for always having our back. In a world where Governments and large Companies want to invade and completely STRIP us of everything when it comes to privacy... I truely hope for the new year 2024, a voice like your will continue be a light for us non-tech-savy to ensure that our privacy is protected and not SOLD or invaded. I wish you a happy New Year in advance🌹🤝 🌹 All the best. PS: I WISH there was a way to DM you regarding something... do hint me in the right direction if possible.

    • @whateveritwasitis
      @whateveritwasitis Před 8 měsíci

      lol, hes given you more then you need. you really want to talk to him cough up the money. everyone of those situations has room for notes and messages. oooo, you just want more free? hes busy.

  • @noanyobiseniss7462
    @noanyobiseniss7462 Před 8 měsíci +31

    Not just privacy but also speed when held locally.
    Add you frequently visited sites to your local hosts file for snappier surfing.

  • @fildisco
    @fildisco Před 8 měsíci +16

    Merry TLS 1.3 Christmas Mental Outlaw and have a happy DNSSEC New Year!! :D

  • @MrTechguy365
    @MrTechguy365 Před 8 měsíci +23

    Important thing to note!
    You should not run a UDP based DNS Server publicly accessible.
    This can be used for DNS amplification attacks. Either move your DNS to a VPN (with headscale for example) or only allow HTTPS requests.

    • @daviddunkelheit9952
      @daviddunkelheit9952 Před 18 dny +1

      I think you meant DoS amplification attacks. NTP and Memcached have greater amplification but there is another problem which is it could be used for DNS cache poisoning and spoofing

  • @turtleswithbombs
    @turtleswithbombs Před 8 měsíci +10

    Just learned about DNS leaks today! On an unrelated note, u should drop a tutorial on removing rogue-deepfake AIs from my walls

  • @beydb
    @beydb Před 8 měsíci +8

    thank you for taking time off playing for the boston celtics to bring us this video

  • @harveybolton
    @harveybolton Před 8 měsíci +49

    There are some things it makes sense to host yourself but recursive DNS isn't one of them, you're isolating your queries to a single VPS in the cloud with no upstream anonymity. You're much better off using an on-premise DNS cache/filter like Adguard/Pihole and configuring it to use a privacy aware upstream DNS service like Quad9, over DoH of course. Route your queries over Mullvad if you're extra paranoid but that's overkill and not necessary for 99% of threat models.

  • @autohmae
    @autohmae Před 8 měsíci +19

    putting your recursive nameserver locally will NOT solve the DNS-information leak, because at the moment still all DNS-requests done recursive nameservers are still NOT encrypted. Sadly.

  • @OcteractSG
    @OcteractSG Před 8 měsíci +11

    So it’s the most private DNS setup, even though the DNS server can be identified as yours, it talks to other DNS servers in the clear (because that’s how top-level DNS works), and you’re the only person/family using it.

    • @apache937
      @apache937 Před 8 měsíci +1

      you can use his server if you want

  • @chrisphoenix115
    @chrisphoenix115 Před 8 měsíci +6

    Mental Outlaw is a white guy from Boston.

  • @GebzNotJebz
    @GebzNotJebz Před 8 měsíci +8

    number one thing you learn about DNS in networks is that its configuration has to be by IP, otherwise you have a "Chicken first or the egg" problem

    •  Před 8 měsíci +1

      not really, as the root servers are known ahead of time, and usually hardcoded into an app, so you can do your own recursion

    • @zakyia
      @zakyia Před 3 měsíci +1

      How do you not have a handle?

  • @babelboy-akababz2889
    @babelboy-akababz2889 Před 8 měsíci +1

    04:50 I was bloody jamming to that music. Why did it have to stop. I want to live my life with that soundtrack running.

  • @ThatRandomGuyInTheComments
    @ThatRandomGuyInTheComments Před 8 měsíci +9

    Holy shit that thumbnail what the fuck

    • @ihate4chan
      @ihate4chan Před 8 měsíci +7

      Man, now I feel like I see him in a different (negative) light lol

    • @omkarnaik6305
      @omkarnaik6305 Před 8 měsíci +5

      He's a frustrated mental incel.

    • @hydr0xx_
      @hydr0xx_ Před 8 měsíci +2

      ​@@omkarnaik6305his whitecel ass tryna cope in every way possible it seems

    • @thymos6575
      @thymos6575 Před 8 měsíci

      @@hydr0xx_ cry harder scammer

    • @aakarshanraj1176
      @aakarshanraj1176 Před 8 měsíci

      @@ihate4chan he is a salty chicken man

  • @freeloaderuser6793
    @freeloaderuser6793 Před 8 měsíci +10

    The fact that I was trying to do this on the router without any success

    • @MentalOutlaw
      @MentalOutlaw  Před 8 měsíci +14

      Doing this on a router would be interesting, might be possible with dnsmasq on OpenWRT

    • @ozzieggg
      @ozzieggg Před 8 měsíci

      ​@@MentalOutlaw openwrt has unbound

    • @makam2089
      @makam2089 Před 8 měsíci

      ​@@MentalOutlawthis is possibile with Unbound package for OpenWRT.

  • @Swenthorian
    @Swenthorian Před 8 měsíci +2

    When I set up an OPNsense router, I configured the firewall to capture all NTP and DNS requests, and I configured Unbound to serve DNS and to do DNS-over-TLS to Quad9, and I configured Chrony to serve NTP and to do NTPSec to System76.

  • @kidus_tv
    @kidus_tv Před 8 měsíci +17

    Great video as always. If only DNS was real.

  • @litjay3828
    @litjay3828 Před 8 měsíci +4

    i didn't know jayson tatum knew about DNS servers

  • @nerf2752
    @nerf2752 Před 8 měsíci +3

    Care to explain the thumbnail? dark-skinned Sikh guy crying with a bindi. What exactly is it supposed to mean?

  • @petekrumb4936
    @petekrumb4936 Před 7 měsíci

    Wow, not only a full time NBA player on the best team in the league, but you run a successful hacking CZcams channel as well? Inspirational man

  • @guy_autordie
    @guy_autordie Před 8 měsíci +1

    I love how DNS-over-https is: Doh!

  • @aloice
    @aloice Před 8 měsíci +4

    using a wildcard certificate would have been more private, especially given your DNS queries wouldn't be collected and sold, so ideally no one would know that domain even exists

  • @davidcampos8795
    @davidcampos8795 Před 8 měsíci +18

    kenny pls make more farm and lifting videos
    also pls put the libre podcast somewhere where it's easy to stream

  • @chubbycatfish4573
    @chubbycatfish4573 Před 8 měsíci +2

    I've been thinking about this lately... good timing :)

  • @FeedMeLeaks
    @FeedMeLeaks Před 8 měsíci +1

    Perfect, I was planning on doing this for a few apps I wanted to deploy across a few machines

  • @bloodynoah8308
    @bloodynoah8308 Před 8 měsíci

    I actually wanted to do this for some time now. Perfect timing that you made that video

  • @mytech6779
    @mytech6779 Před 8 měsíci +1

    The net provider can still see and log the raw IP on all the packets you send; at that point reverse DNS is a pretty trivial way to get those URL logs.

  • @vectorvirus343
    @vectorvirus343 Před 8 měsíci +6

    Also combine it with pihole to have the ultimate DNS server

  • @MichaelGolpe
    @MichaelGolpe Před 8 měsíci

    4:31 feeling the groove on that music!

  • @Username5H0
    @Username5H0 Před 8 měsíci

    Happy Holidays, and upcoming new year, MentalOutlaw.

  • @johngleeson7919
    @johngleeson7919 Před 8 měsíci +3

    Technitium DNS is another nice option, particularly if you want a GUI. It also has adblock capabilities, and can do DNS wildcard, which is helpful for self hosted applications.

  • @adamm6051
    @adamm6051 Před 8 měsíci +1

    One day when I finally will understand how computers work your videos will be very helpful to me. Too bad I know jackshit atm. Keep up the good work!

  • @johnvogt621
    @johnvogt621 Před 8 měsíci +3

    Hope you'll do an update when all the features you mentioned (secure hello etc) are available. Thanks

  • @locusf2
    @locusf2 Před 8 měsíci +1

    ECH is really good if you're using TLS cipher suite based virtual host.

  • @someshkilari
    @someshkilari Před 8 měsíci +1

    Interesting thumbnail, especially the crying person in thr middle.
    Does it refer to anyone specific?

    • @Grogueman
      @Grogueman Před 7 měsíci

      His step-father, who is alleged to bang his mom in his full view.

  • @LordHog
    @LordHog Před 8 měsíci +1

    This video is very timely, thanks, sir

  • @MarloMitchell
    @MarloMitchell Před 8 měsíci +7

    is there a written guide?

  • @linuxinside6188
    @linuxinside6188 Před 8 měsíci +7

    *That thumbnail is racist and uncalled for.*

  • @da_revo5747
    @da_revo5747 Před 8 měsíci +2

    Bro what is that Indian character? Literally a mix of all the completely different stereotypes. 😂

  • @aquatrax123
    @aquatrax123 Před 8 měsíci

    DNS Cacheing will not speed anything up since 1) Caching will occur locally on your machine anyway. No need to cache anything on another DNS server. If your computer looks up the A record for google it will not ask again until the TTL expires. or you reboot your machine. 2) Today, Most DNS records have a TTL of around 5 minutes, so you will have to ask the authoritative DNS server again anyway after the TTL expires.

  • @midknightfenerir
    @midknightfenerir Před 8 měsíci

    Your are best thanks for information and everything you do in the community.

  • @whiterice6016
    @whiterice6016 Před 8 měsíci +2

    Hey Kenny, how would I start my own ISP?

  • @007Strings007
    @007Strings007 Před 8 měsíci +1

    Other than making your network faster does this really add anything. I mean DNS list are pubic and are used to associate URLs to IPs, using your own DNS server or someone else does not stop your ISP or anyone from seeing the IPs of the websites you are visiting and if they can see that they can do a reverse DNS search to fined what website URL you are going to. Am I right about this?

  • @alexlopez5800
    @alexlopez5800 Před 8 měsíci +1

    😂 thumbnails are A1

  • @sprytnychomik
    @sprytnychomik Před 8 měsíci +9

    Mom says we already have DNS at home.
    DNS at home: /etc/hosts

    • @fuehwbdb3765
      @fuehwbdb3765 Před 8 měsíci

      Uff there is some dust on your meme but I appreciate it 😂 just like my old pentium.

  • @pajeetsingh
    @pajeetsingh Před 8 měsíci +3

    20:29 Add domain to host file.

  • @stevengill1736
    @stevengill1736 Před 8 měsíci

    Nice Tee shirt. ;*=[}
    Man, this is so over my head these days....
    One of the problems of being standalone solar power is that this time of year one has to run a generator to charge the batteries, and THAT presupposes having money for gas at $5.00/gallon (yes - up here in NoCal Ecotopia Earth First gas is the sale price as Anchorage or Honolulu...from what I've heard people back east pay as little as $2.50! )
    [muffled sobbing in the BG] Don't even ask about food prices....OTOH, it was 50'F today....not sunny but not raining...a few days before New Year's.
    But don't even ask about internet - no Starlink = no real web (miraculously there's a trace of mobile which allows me to occasionally see CZcamss like this one...it makes dialup look good in retrospect!)
    Another message in a bottle launched into the heaving Sea of Packets....Happy Gnu Year!

  • @ncrvako
    @ncrvako Před 8 měsíci

    Mental, your are one of my favourite ytbers to love and hate at the same time. One day i will start paying proper attention to your videos teachings.

  • @ulysg
    @ulysg Před 8 měsíci +1

    I personnaly use Technitium DNS, and I like it very much. It's an authorative/recursive DNS, and it also can block ads.

  • @stevensneedberg4879
    @stevensneedberg4879 Před 6 měsíci

    It was super annoying when Firefox ripped out ESNI support when literally nobody in the world was using ECH, hope ECH gets implemented soon

  • @zeKotako
    @zeKotako Před 8 měsíci

    This came at the perfect time for my project

  • @AwesomeGuy445
    @AwesomeGuy445 Před 8 měsíci

    personally i don't use dns and i just memorize the ip, but this is cool!

  • @tonyscalleta
    @tonyscalleta Před 2 měsíci

    Jason Tatum 🔥

  • @13thravenpurple94
    @13thravenpurple94 Před 8 měsíci

    Excellent video 👍 Thank you 💜

  • @njts
    @njts Před 8 měsíci +2

    What software are you using for your email server?

  • @reizaifafu
    @reizaifafu Před 8 měsíci

    i never knew that Jayson Tatum also teach on how to host our own dns server

  • @Twis7
    @Twis7 Před 8 měsíci +5

    btw. I have mail server on linode too and yes, it is not ok. Most of my e-mail are marked as spam.

    • @MentalOutlaw
      @MentalOutlaw  Před 8 měsíci +4

      Is it just Microsoft and Apple blocking your emails? I tried a few different configs with a few different cloud providers but always have trouble sending to outlook, hotmail, etc

    • @Twis7
      @Twis7 Před 8 měsíci

      @@MentalOutlaw
      Microsoft blocking all my mails. Google, apple aol, yahoo are sending me to spam.
      You can de-list your ip if you send a ticket to microsoft.
      I am using glockapps to check who is marking me as spamer.

    • @user-dc9zo7ek5j
      @user-dc9zo7ek5j Před 8 měsíci

      Have you guys set up SPF record?

    • @Twis7
      @Twis7 Před 8 měsíci

      @@user-dc9zo7ek5j Yes, spf dmarc dkim are in place, but they do not help against bad IP reputation.

  • @shellcatt
    @shellcatt Před 7 měsíci

    Props for the arcade music :D

  • @erlichbachman663
    @erlichbachman663 Před 8 měsíci

    Insane thumbnail well done

  • @44544abc
    @44544abc Před 8 měsíci

    good videos buddy - keep it up

  • @Antonio-yy2ec
    @Antonio-yy2ec Před 8 měsíci

    Awesome! Thank you!

  • @MarceloVeronezzi
    @MarceloVeronezzi Před 8 měsíci

    04:09 This looked like straight from the hacking time scene of Kung Fury (and I mean it as a positive thing). 😁

  • @HerbyDigitalTV
    @HerbyDigitalTV Před 8 měsíci +1

    I want everything hosted locally.

  • @dubstep1
    @dubstep1 Před 8 měsíci +2

    Thanks drake

  • @azulamazigh2789
    @azulamazigh2789 Před 8 měsíci +1

    Voltr has offices in Israhell so it's not an option

  • @nuhanfaiyaz5541
    @nuhanfaiyaz5541 Před 8 měsíci

    If someone have no knowledge of online privacy/security,
    password and sensetive information management.
    Where should he start?
    And Do you recommend to learn how to use Linux and get rid of Windows?

  • @kaydog890
    @kaydog890 Před 8 měsíci +2

    Real men don't need a DNS, we just go directly to the IP addy

  • @paxdriver
    @paxdriver Před 8 měsíci

    21:45 "it's a trap!" lol

  • @adriansrealm
    @adriansrealm Před 8 měsíci +1

    You can't add a DNS name as a DNS server, how would it know how to resolve it?

  • @WerogIjo
    @WerogIjo Před 8 měsíci

    OMG...this really work

  • @nikoraasu6929
    @nikoraasu6929 Před 8 měsíci +2

    Luke Smith is not uploading on his main channel due to focusing on creatimg great deepfakes for this channel, good job Luke

  • @pizzza5452
    @pizzza5452 Před 8 měsíci +2

    The thumbnail lmaooo

  • @DontDissTheProgram
    @DontDissTheProgram Před 8 měsíci

    Intresting! ...thanks

  • @davidholland6164
    @davidholland6164 Před 8 měsíci

    I host adguard home on my raspberry pi with encrypted dns it's great

  • @livingcodex9878
    @livingcodex9878 Před 8 měsíci +2

    おはようございます

  • @sonny8085
    @sonny8085 Před 8 měsíci

    Can I ask what server software you use for your Linode email server?....I was thinking of using Axigen, but am looking for advice. Thanks

  • @stilldoesntclick1337
    @stilldoesntclick1337 Před 7 měsíci

    Some questions:
    Did Secure SNI got added?
    If SSNI hasn't been added is it a big disadvantage, can the ISP or Big Tech your traffic without SSNI?

  • @oopss794
    @oopss794 Před 8 měsíci +4

    vps is not safe

  • @LokiScarletWasHere
    @LokiScarletWasHere Před 8 měsíci

    Another reason this setup doesn't support ECH is the browsers that support it are very picky about which DoH servers they will allow for ECH. I tested even with a server with a real cert, with different SSL libs, and it simply will rarely if ever allow ECH on a personally owned server. They only trust certain parties for use with ECH, whether it be Chrome/Chromium or Firefox.

    • @apache937
      @apache937 Před 8 měsíci

      is there any reason for that? there may still be some advanced config change possible, or at worst case build from source with your server added. but who will do that?

    • @LokiScarletWasHere
      @LokiScarletWasHere Před 8 měsíci +1

      @@apache937 Well, seeing as DoH is the big tech version of DoT, and no browser supports ECH with DoT either, I'm sure you can infer a pattern. A build from source with your own server trusted would do the job in theory, but like you said, aint nobody gonna do that.

  • @jim7251
    @jim7251 Před 8 měsíci

    Good solution, if reverse-DNS lookups are not routinely done by ISPs on general population.

  • @Wolferia
    @Wolferia Před 7 měsíci

    I plan on this big fan 🎉🎉🎉

  • @whateveritwasitis
    @whateveritwasitis Před 8 měsíci

    if this is supposed to be for script kiddies and noobs, one only need read the comments to go completely insane. every argument sounds right. its maddening.

  •  Před 8 měsíci

    I don't understand what this is for, or how it works. You eventually need to get the data from somewhere, and you usually want the current data, so you have to regularly ask the TLD providers or the domain owners (or someone else who asked them before, like Google or Cloudflare) for that. You can cache the data for a while, but I thought, that is already been done automatically by your software (maybe the OS?), since every DNS entry has a Time To Live information.
    Or is this only for people who want to offer a DNS service for other people?

  • @kinkychad69
    @kinkychad69 Před 8 měsíci +1

    Is the host free service and is there easy way to backup with out doing it from scratch?

  • @user-jns28bz
    @user-jns28bz Před 8 měsíci

    I don’t have much knowledge of DNS, and how the internet works in general, so my question is whats the difference between this and pihole + unbound?

  • @Picture_Pig
    @Picture_Pig Před 8 měsíci +1

    Vultr Vait (Walter White)

  • @CMDRunematti
    @CMDRunematti Před 8 měsíci

    I'm using a raspi with pihole and unbound... Don't think it's encrypted tho but I definitely am more secure

  • @electroteque
    @electroteque Před 8 měsíci

    how much does it cost to run email and DNS off VPS ? Wouldnt want to do that with EC2 that is for sure. There is Vultr freebsd also. I moved to serverless as I dont have time to manage vps and security.,

  • @hanabiilesley
    @hanabiilesley Před 8 měsíci

    awesome vid

  • @vzool
    @vzool Před 8 měsíci

    Hi, what version of bind9 you had, I have an issue here:
    BIND 9.16.44-Debian (Extended Support Version)
    root@dns:/etc/bind# nano /etc/bind/named.conf.options
    /etc/bind/named.conf.options:1: unknown option 'tls'
    /etc/bind/named.conf.options:5: unknown option 'http'
    /etc/bind/named.conf.options:13: unknown option 'http-port'
    /etc/bind/named.conf.options:14: unknown option 'https-port'
    /etc/bind/named.conf.options:19: '{' expected near 'tls'
    Any suggestions?
    Thanks

  • @Jetpack4Sisyphus
    @Jetpack4Sisyphus Před 8 měsíci

    Huh? But root hints and forwarders.... The DNS all originates from authoritative (corporate/government) sources.

  • @willuhmjs
    @willuhmjs Před 8 měsíci

    fire 🗿

  • @Basieeee
    @Basieeee Před 8 měsíci

    Always done something like this, DOT or DOH at least.