top | item 44947667

(no title)

dbmnt | 6 months ago

No, I don't think they are proxying traffic. They are giving the website operators a spoofed EDNS Client Subnet which tricks them into thinking the traffic is coming from a different geolocation.

discuss

order

1vuio0pswjnm7|6 months ago

If this is true, then perhaps unbound users can edit the EDNS subnet module themselves. No NextDNS required

1vuio0pswjnm7|6 months ago

ECS is popular with third party DNS providers with open resolvers, like Google, but not all software that sends DNS queries sends large DNS packets with EDNS extensions and some www users avoid open resolvers

One of the things that I noticed about NextDNS when they announced their service on HN is that like the other public caches, they too sent ECS, but they claimed they could "anonymise" it