Page MenuHomeIssueTracker

NextDNS alternative?
Open, S3 LowPublic

Assigned To
Authored By
revi
Apr 26 2024, 02:08
Referenced Files
F1867: IMG_5437.png
Apr 27 2024, 13:15
F1866: IMG_5436.png
Apr 27 2024, 13:15
F1864: IMG_5431.png
Apr 27 2024, 13:15
F1863: IMG_5433.png
Apr 27 2024, 13:15
F1862: IMG_5432.png
Apr 27 2024, 13:15
F1860: IMG_5434.png
Apr 27 2024, 13:15
Subscribers

Description

NextDNS' zepto-sel has been quite unstable since late March, and I was considering moving away from them as my annual plan was due to renewal within 2 weeks.

I ultimately decided to renew nextDNS yearly plan, but logging what I want just because… 'why not'.

hard requirement

  1. Server in KR (submarine cables can be even more unstable. Especially I don't really like my traffic reaching HKG, given now HKG is de facto colony of CCP, and I have serious reasons to believe CCP wants to talk to me behind bars if they have chance.)
  2. Multiple profiles (I have multiple networks, for example one for my home network, another for rest of my family members', yet another for servers, and something else.)
  3. ability to use Unicode for device name (while I'm writing this in English, English is just a 'secondary language' and canonical selection is Korean.)
  4. as a bare minimum, have YousList in their adblock selection (KR specific list)
  5. Statistics and log retentions. I like the nice graphs and pie charts, so no-logging public DNS resolvers are out here. (And logs are frequent discovery method for digging new host to block, for example self-hosted matomo instances of not-that-popular services)
  6. No self-hosting. While I do self-hosting (for example, this site) I am not really good at keeping 9-levels of uptime required for critical infra, and I don't want to add one more systems to apply security patch.)
  7. something more but I'm phone now…

Where alternatives failed

  • ControlD: no server in KR, IIRC it cannot set unicode device name.
  • AdGuard DNS: no server in KR, I don't recall if I can set unicode device name.
    • Their self-host software is out because no-self-host.
  • Cloudflare Gateway: lack of YousList, and I think this also cannot set unicode device name… and their target audience is primarily business and I'd be paying too much for less…

Event Timeline

revi triaged this task as S4 Wishlist priority.

Some ping stats, all performed from home network wifi:

nextDNS ping, 10 times
adguard-dns.com ping, 10 times
controld.com ping, 10 times
wikimedia-dns.org ping, 10 times
cloudflare-dns.com ping, 10 times
dns.google ping, 10 times

My guess is that AS17858 (LG POWERCOMM) which is the ASN for my home network is unhappy with routing w/ AS138195 (MOACK) which is nextdns zepto-sel. AS17853 (LGTELECOM) and AS3786 (LG DACOM) had no problem with this as far as I recall. (Unsurprisingly, AS3786, AS17853, AS17858 is all controlled by one entity LG U+).

Though, AS17853 and AS17858 both routes to AS3786 before hopping to wider internet, so I have no idea what is making the differences.

Disclaimer: I only have LGP and LGT access. LGD test are via sporadic Public Wifi tests.

revi raised the priority of this task from S4 Wishlist to S3 Low.May 1 2024, 19:22

And I ain't give up secure DNS: vercel was being blocked whole weekend and I had no idea of it until now, thanks to DoH and DoT.

Fuck you, Korea Internet Endanger Agency.

nvidiafuckyou