safing / portmaster

🏔 Love Freedom - ❌ Block Mass Surveillance
https://safing.io
GNU General Public License v3.0
9.2k stars 292 forks source link

DNS server for the SPN #1676

Closed NolonQ closed 3 weeks ago

NolonQ commented 3 weeks ago

Pre-Submit Checklist:

What happened: Does safing host it's own DNS server that should be used with the SPN so we can browse the web privately without DNS leaks?

What did you expect to happen?:

How did you reproduce it?:

Debug Information:

vlabo commented 3 weeks ago

Safing does not host a DNS server. You should choose one that you trust.

More info about DNS leaks

NolonQ commented 3 weeks ago

Safing does not host a DNS server. You should choose one that you trust.

More info about DNS leaks

If i chose a DNS that is not brought with the encrypted SPN tunnel, will this not leak my activity to my ISP?

vlabo commented 3 weeks ago

Not sure I understand the question compliantly.

If SPN is enabled the DNS requests will be routed through SPN. If you are using secure DNS (the default one is) the ISP wont be able to see your activity even if the SPN is disabled.

NolonQ commented 2 weeks ago

I thought the spn works like a vpn but instead of using a single ip adress we can hop through multiple proxys and use many ips for all our different programs, even if the spn tunnel is encrypted cant my isp see my dns queries since the spn has no dns? i am so confused.