a year old, but interesting to read

  • diaphragmwp@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    No. Not enough, still often overridden by router or whatever.

    Edit /etc/NetworkManager/NetworkManager.conf:

    [main]
    dns=0
    rc-manager=unmanaged
    
    Full file I suggest
    # Configuration file for NetworkManager.
    # See "man 5 NetworkManager.conf" for details.
    [main]
    hostname-mode=none
    dns=0
    rc-manager=unmanaged
    
    [device]
    wifi.scan-rand-mac-address=yes
    
    [connection]
    ethernet.cloned-mac-address=random
    wifi.cloned-mac-address=random
    connection.mdns=0
    connection.llmnr=0
    
    [ipv6]
    addr-gen-mode=1
    ip6-privacy=2
    

    And disable/delete “Avahi”.


    Restart NetworkManager twice. If you don’t know how, restart the computer twice. No, I don’t know why twice. Now, edit /etc/resolv.conf:

    nameserver 2001:470:1f15:b80::53
    nameserver 91.190.185.43
    

    Servers grabbed from here: https://servers.opennic.org/ (OpenNIC itself is kinda barely holding but the servers are pretty good).

    Note that your browser will ignore this. Open up Firefox (or derivative), Settings, Privacy and security, DNS over HTTPS, Own settings, Own, and paste something like https://dns1.slowb.ro/dns-query into it. Again, you can grab a server from opennic (look into description for URL). No, you cannot use opennic.glue addresses here.

    Now, note that this may still be tampered with, if your ISP/government cares enough. Not in the browser, but system wide yes. In this case, you will have to use dnssec-proxy, route your DNS over I2P/Tor OR run your own resolver. In all of these scenarios, you will have to make sure the program providing it is listening on port 53 (and nothing else is taking it) then just make /etc/resolv.conf this instead:

    nameserver ::1
    nameserver 127.0.0.1
    

    Obviously, all of this only affects DNS tampering and nothing else.