home.social

#dnscrypt — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dnscrypt, aggregated by home.social.

  1. Habe gerade #inviziblepro für mich entdeckt. Was für eine geile #APP ist das denn bitte !? 😶
    #Vpn
    Schützt dich mit #dnscrypt
    Verschleiert die IP via #tornetzwerk
    #i2pnetzwerk Zugang
    Kein Datenvolumen limit in der #F-droid Variante !

  2. Habe gerade #inviziblepro für mich entdeckt. Was für eine geile #APP ist das denn bitte !? 😶
    #Vpn
    Schützt dich mit #dnscrypt
    Verschleiert die IP via #tornetzwerk
    #i2pnetzwerk Zugang
    Kein Datenvolumen limit in der #F-droid Variante !

  3. Habe gerade #inviziblepro für mich entdeckt. Was für eine geile #APP ist das denn bitte !? 😶
    #Vpn
    Schützt dich mit #dnscrypt
    Verschleiert die IP via #tornetzwerk
    #i2pnetzwerk Zugang
    Kein Datenvolumen limit in der #F-droid Variante !

  4. DoH vs DNSCrypt: technical comparison 🔐

    **DNSCrypt:**
    ✅ No insecure bootstrap
    ✅ No CA dependency
    ✅ Resistant to CA compromise
    ✅ Can hide client IP (Anonymized DNSCrypt)
    ❌ Less common support

    **DoH:**
    ✅ IETF-standardized (RFC 8484)
    ✅ Port 443 (blends with HTTPS)
    ✅ Self-hostable
    ✅ Browser native support
    ✅ Harder to detect/block
    ❌ Requires TLS bootstrap

    My: self-hosted DoH → Unbound. Zero third parties, encrypted.

  5. LOL, I was trying to figure out why dnscrypt-proxy wouldn't resolve on port 5053. Turns out the ListenStream and ListenDatagram on /usr/lib/systemd/system/dnscrypt-proxy.socket was set to 127.0.2.1#53. I just changed the port to 5053, not seeing the third digit was set to 2, not 0. It took me some minutes to see that !

    I was following this guide, pretty easy, but I gotta say that "2" was pretty sneaky, but it's alright now: docs.pi-hole.net/guides/dns/dn

    #dnscrypt #pihole

  6. We are deprecating #DNSCrypt support.

    ffmuc.net/services/dns/2026/01

    Maintenance cost (in an Anycast setup) is too high for so little usage that's why we decided to deprecate it.

    #DNS

  7. So #OPNsense is driving me a little crazy🤪, with stuff like:
    On DnsCrypt‑Proxy when adding stamps, the stamps spec defines to include the sdns:// prefix but unless you tick the help on the right corner of the add overlay, you will not see that OPNsense does not want you to add the sdns:// prefix🤪😠
    Wasting my time in trying to fix #DNScrypt

    What is making me crazy mad to no end!🤪😠
    Is how outdated the OPNsense manual is!!

    #Networking #Network #Networks #DNS #Router #Routers #OpenSource #Firewall

  8. What private DNSCrypt or DNS-over-HTTPS services running some foss software do you use?
    Preferably owned and hosted in Europe.

  9. @hobbyblogging #PiHole (mit #DNSCrypt Verbindung), #NextDNS und #Ghostery zusammen, sorgen bei mir für Ruhe im Internet.
    Zu Hause, mobil, bei der Arbeit 🙂
    Und mit Private Relay, IPv6 und rotierenden Mac-Adressen, auch schwerer zu anhand der IP zu identifizieren (ja, Apple = böse und so. Mir egal 🤣)

  10. Hapy Juneteenth, folks.
    Today we celebrate emancipation and reflect on how freedom extends into our digital lives.
    ✍️Digital liberation matters too.
    Follow Us to find out more.
    #juneteenth2025 #OnlineSafety #DigitalFreedom #DNSCrypt

  11. CW: DNS Linux Server stuff

    Is there a way to query every single configured dnscrypt relay at once? A friend recently just tried to access bsky.app, but was most likely sent to a malicious IP. He uses dnscrypt-relay via pihole, and unfortunately we can't tell which relay sent the offending A Record. Would be good to know which relay should be investigated and/or removed from the configured dnscrypt-relay project entirely.

    #selfhosted #dns #linux #dnscrypt #privacy #infosec

  12. This Weekend's Project:

    Dual Raspberry Pi 3s running DNSCrypt-proxy and DNSmasq serving DNS to my home network.

    Normal DNS is unencrypted and I don't really trust my ISP's DNS. So I put some old Pi 3s back in service as DNSCrypt servers.

    They pull DNS Data from Quad9 (with malware blocking) in encrypted form, and every device on my network gets their DNS served from these two devices.

    What a nice project.

    (Also I chose not to do Pi-Hole, since blocking ads are done on a device-level for me. Blanket blocking many servers seems to cause unpredictable behaviour.)

    #raspberrypi #dnscrypt #networking #dns

  13. If you want to test #DNSCrypt #DoH #DoT the @freifunkMUC servers are happy to take your traffic :).

    Ofc researchers or experiments are also welcome.

    doh.ffmuc.net - IPv4: 5.1.66.255 / 185.150.99.255 IPv6: 2001:678:e68:f000:: / 2001:678:ed0:f000::

    #38c3

  14. @gerowen check out doing recursive dns with pihole and also check out pi alert - sending all syslog verbose to security onion for central logging could be an option or syslog-ng? #514 I would try a yabs (yet another benchmark script) and this will give you a good report. I will try to determine who stops by the r proxies by doing lookups - I probably need to work on my dns setup also #dnscrypt

  15. #DNS is a #privacy minefield. Here's my best shot at charting a safe course through.

    New #blog post up now re: combining #AdGuardHome with rotating stable of #DNSCrypt resolvers, with #Tailscale #E2EE over #Mullvad exit nodes, and #Caddy obtaining certificates for #DOHsij.law/dns/

    #infosec #selfhosting #debian #linux #hetzner #server #pihole #unbound #macos #ios #DNSOverride #DeepDive #LittleSnitch #Cloudflare #Quad9 #9999

  16. #DNS is a #privacy minefield. Here's my best shot at charting a safe course through.

    New #blog post up now re: combining #AdGuardHome with rotating stable of #DNSCrypt resolvers, with #Tailscale #E2EE over #Mullvad exit nodes, and #Caddy obtaining certificates for #DOHsij.law/dns/

    #infosec #selfhosting #debian #linux #hetzner #server #pihole #unbound #macos #ios #DNSOverride #DeepDive #LittleSnitch #Cloudflare #Quad9 #9999

  17. #DNS is a #privacy minefield. Here's my best shot at charting a safe course through.

    New #blog post up now re: combining #AdGuardHome with rotating stable of #DNSCrypt resolvers, with #Tailscale #E2EE over #Mullvad exit nodes, and #Caddy obtaining certificates for #DOHsij.law/dns/

    #infosec #selfhosting #debian #linux #hetzner #server #pihole #unbound #macos #ios #DNSOverride #DeepDive #LittleSnitch #Cloudflare #Quad9 #9999

  18. #DNS is a #privacy minefield. Here's my best shot at charting a safe course through.

    New #blog post up now re: combining #AdGuardHome with rotating stable of #DNSCrypt resolvers, with #Tailscale #E2EE over #Mullvad exit nodes, and #Caddy obtaining certificates for #DOHsij.law/dns/

    #infosec #selfhosting #debian #linux #hetzner #server #pihole #unbound #macos #ios #DNSOverride #DeepDive #LittleSnitch #Cloudflare #Quad9 #9999

  19. #DNS is a #privacy minefield. Here's my best shot at charting a safe course through.

    New #blog post up now re: combining #AdGuardHome with rotating stable of #DNSCrypt resolvers, with #Tailscale #E2EE over #Mullvad exit nodes, and #Caddy obtaining certificates for #DOHsij.law/dns/

    #infosec #selfhosting #debian #linux #hetzner #server #pihole #unbound #macos #ios #DNSOverride #DeepDive #LittleSnitch #Cloudflare #Quad9 #9999

  20. @aikensource @cloudflare I use #dnscrypt and dnscrypt-proxy and enable relays, it can take a little while to start when it checks latency but once it's running i've never had any issues. I also front with #unbound to forward specific domains to local nameservers

  21. So there is this one domain that has like 42 TXT records, and each record is large, so many that it is breaking the #DNSCrypt tool.

  22. Also noticed that #DNSCrypt provides a large amount of binary distributions for #FreeBSD, #OpenBSD, #NetBSD, #DragonFlyBSD, #Solaris, among several other OSs, plus many architecture-specific binaries. That is really nice! Next thing will be deploying it on the beastie server.

  23. Setting up DNSCrypt was easier than anticipated on my Debian machine without systemd-resolved. I really like the binary distribution, which is available as a self-contained directory with the binary and sample configuration. You can run the whole thing from that portable directory and move it around or specify locations on the command line if you wanna spread it.

    Also, the gradual and modular approach to the generic Linux installation was a delight to follow, always being reminded to take small and verifiable steps along the way.

    For anyone interested, this is it: github.com/DNSCrypt/dnscrypt-p

    #DNSCrypt #DNSSEC #DNS #sysadmin #debian #netsec #networksecurity #it

  24. InviZible Pro - Захистіть свій пристрій від небезпечних сайтів, позбудьтеся набридливої реклами та стеження, отримайте доступ до заблокованих ресурсів у вашій країні!

    InviZible Pro містить добре відомі модулі DNSCrypt, Tor і Purple I2P. Ці модулі використовуються для досягнення максимальної безпеки, конфіденційності та зручності користування Інтернетом.

    InviZible Pro може використовувати root, якщо на вашому пристрої є привілеї root, або використовувати локальну VPN для передачі інтернет-трафіку в мережі Tor, DNSCrypt і I2P.

    Особливості:

    • Не обовʼязково потрібні root права
    • Приховує розташування та IP
    • Розблоковує обмежений веб-вміст
    • Запобігає відстеженню
    • Дозволяє отримати доступ до прихованих мереж
    • Виявлення підміни ARP
    • Вбудований брандмауер

    #android #fdroid #foss #tor #i2p #dns #crypt #dnscrypt #invizible_pro #security #privacy #додаток #приватність #безпека #vpn #root

  25. InviZible Pro
    Android application for Internet privacy and security

    InviZible Pro combines the strengths of Tor, DNSCrypt, and Purple I2P to provide a comprehensive solution for online privacy, security, and anonymity. You can use them all together or activate only one or two at once.

    Download & Guide: github.com/Gedsh/InviZible/wiki

  26. InviZible Pro
    Android application for Internet privacy and security

    InviZible Pro combines the strengths of Tor, DNSCrypt, and Purple I2P to provide a comprehensive solution for online privacy, security, and anonymity. You can use them all together or activate only one or two at once.

    Download & Guide: github.com/Gedsh/InviZible/wik

    #foss #android #OpenSource #Privacy #Security #Tor #dnscrypt #i2p #purplei2p #inviziblepro #root #adblockers #oss #FLOSS

  27. InviZible Pro
    Android application for Internet privacy and security

    InviZible Pro combines the strengths of Tor, DNSCrypt, and Purple I2P to provide a comprehensive solution for online privacy, security, and anonymity. You can use them all together or activate only one or two at once.

    Download & Guide: github.com/Gedsh/InviZible/wik

    #foss #android #OpenSource #Privacy #Security #Tor #dnscrypt #i2p #purplei2p #inviziblepro #root #adblockers #oss #FLOSS

  28. InviZible Pro
    Android application for Internet privacy and security

    InviZible Pro combines the strengths of Tor, DNSCrypt, and Purple I2P to provide a comprehensive solution for online privacy, security, and anonymity. You can use them all together or activate only one or two at once.

    Download & Guide: github.com/Gedsh/InviZible/wik

    #foss #android #OpenSource #Privacy #Security #Tor #dnscrypt #i2p #purplei2p #inviziblepro #root #adblockers #oss #FLOSS

  29. InviZible Pro
    Android application for Internet privacy and security

    InviZible Pro combines the strengths of Tor, DNSCrypt, and Purple I2P to provide a comprehensive solution for online privacy, security, and anonymity. You can use them all together or activate only one or two at once.

    Download & Guide: github.com/Gedsh/InviZible/wik

    #foss #android #OpenSource #Privacy #Security #Tor #dnscrypt #i2p #purplei2p #inviziblepro #root #adblockers #oss #FLOSS

  30. Set up #OpenAlias on my #domain. Type it into almost any #Monero wallet (using #monerujo here) and it’ll resolve to my public subaddress, verified by #DNSSEC and requests sent through #DNSCrypt on the client side for #security and #privacy.

    This is easy to do for any domain you have full control of with a single #DNS TXT entry. You can also add #BTC, #LTC, and any other #cryptocurrency wallet addresses, although it only has wide adoption for #XMR wallets including the official one. For XMR it’s virtually a universal standard.

    Of course relying on centralised authorities isn’t ideal, but it’s a simple open standard and by piggybacking off an already universal standard it’s easy to implement for anyone who has a domain.

    Official site: https://openalias.org/

  31. Set up #OpenAlias on my #domain. Type it into almost any #Monero wallet (using #monerujo here) and it’ll resolve to my public subaddress, verified by #DNSSEC and requests sent through #DNSCrypt on the client side for #security and #privacy.

    This is easy to do for any domain you have full control of with a single #DNS TXT entry. You can also add #BTC, #LTC, and any other #cryptocurrency wallet addresses, although it only has wide adoption for #XMR wallets including the official one. For XMR it’s virtually a universal standard.

    Of course relying on centralised authorities isn’t ideal, but it’s a simple open standard and by piggybacking off an already universal standard it’s easy to implement for anyone who has a domain.

    Official site: https://openalias.org/

  32. Set up #OpenAlias on my #domain. Type it into almost any #Monero wallet (using #monerujo here) and it’ll resolve to my public subaddress, verified by #DNSSEC and requests sent through #DNSCrypt on the client side for #security and #privacy.

    This is easy to do for any domain you have full control of with a single #DNS TXT entry. You can also add #BTC, #LTC, and any other #cryptocurrency wallet addresses, although it only has wide adoption for #XMR wallets including the official one. For XMR it’s virtually a universal standard.

    Of course relying on centralised authorities isn’t ideal, but it’s a simple open standard and by piggybacking off an already universal standard it’s easy to implement for anyone who has a domain.

    Official site: https://openalias.org/

  33. Set up #OpenAlias on my #domain. Type it into almost any #Monero wallet (using #monerujo here) and it’ll resolve to my public subaddress, verified by #DNSSEC and requests sent through #DNSCrypt on the client side for #security and #privacy.

    This is easy to do for any domain you have full control of with a single #DNS TXT entry. You can also add #BTC, #LTC, and any other #cryptocurrency wallet addresses, although it only has wide adoption for #XMR wallets including the official one. For XMR it’s virtually a universal standard.

    Of course relying on centralised authorities isn’t ideal, but it’s a simple open standard and by piggybacking off an already universal standard it’s easy to implement for anyone who has a domain.

    Official site: https://openalias.org/

  34. Set up #OpenAlias on my #domain. Type it into almost any #Monero wallet (using #monerujo here) and it’ll resolve to my public subaddress, verified by #DNSSEC and requests sent through #DNSCrypt on the client side for #security and #privacy.

    This is easy to do for any domain you have full control of with a single #DNS TXT entry. You can also add #BTC, #LTC, and any other #cryptocurrency wallet addresses, although it only has wide adoption for #XMR wallets including the official one. For XMR it’s virtually a universal standard.

    Of course relying on centralised authorities isn’t ideal, but it’s a simple open standard and by piggybacking off an already universal standard it’s easy to implement for anyone who has a domain.

    Official site: https://openalias.org/