No worries Dave, I think security should always include a solid dialogue and its a valid point. I'm currently reviewing Technitium DNS Server and will need to perform a bit more research before implementing. I think this may fall along the lines of your request?
Link:
https://technitium.com/dns/Looks promising, will have to look into it too.
It's amazing how much information you leak using public / your internet providers DNS.
And how many people & places still refuse to use DNS over TLS.
Look a hardware wallet connected to an encrypted PC connected to an actual cable to the SonicWall router.
And lets go to Coinbase using local ISPs DNS lookup. And now we know you have (or are interested in) crypto.
And since your local ISP probably is not using DNSSEC, who knows if you are really at Coinbase anyway.
Yes, and extreme edge case, but still worth thinking about.
-Dave
Hey Dave,
Just a quick follow up. resolvconf has been installed and the nameservers below have been set to permanent (default):
nameserver: 9.9.9.9 (Quad 9) - Main - DNS over HTTPS (aka DoH)
Link:https://quad9.net/news/blog/doh-with-quad9-dns-servers/
nameserver 1.1.1.1 (Cloudflare) - Fallback - DNS over HTTPS (aka DoH)
Link:
https://developers.cloudflare.com/1.1.1.1/encrypted-dnsnameserver: 127.0.0.53 (Local) - Fallback
Technitium looked great, however after a hearty conversation with the team no one liked the idea of this remotely resembling a DNS server