# NextDNS logging is opt-out, not opt-in as stated on PG's DNS Resolvers recommendations page

**URL:** https://discuss.privacyguides.net/t/nextdns-logging-is-opt-out-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206
**Category:** Site Development
**Created:** 2024-03-04T23:29:24Z
**Posts:** 72

## Post 1 by @anon21489307 — 2024-03-04T23:29:24Z

PG stated in the [DNS Resolvers page](https://www.privacyguides.org/en/dns) that:

> NextDNS can provide insights and **logging features on an _opt-in_ basis**.

Which is not true, as shown in my screen recording:

## When using the service with a registered user account:

[https://drive.proton.me/urls/CP0K30G8TW#rtIm1XINGLwH](https://drive.proton.me/urls/CP0K30G8TW#rtIm1XINGLwH)

## When using the service without signing up for a user account:

[https://drive.proton.me/urls/KGW3X2EQ00#I9cmVrAxuUI3](https://drive.proton.me/urls/KGW3X2EQ00#I9cmVrAxuUI3)

---

## Post 2 by @lepras — 2024-03-05T03:33:17Z

I can’t access the media

---

## Post 3 by @anon21489307 — 2024-03-05T03:37:41Z

It says file rate limit, just 7 clicks??? Does someone spam my link? :joy:

I will upload the file on ~~Google Photos~~ and I will edit the post with a new link. No, that would reveal too much of my personal info. Do you have a good place to upload video?

This is what the old link tells me :joy::

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/d/d64bab85a539110f065d7f9a3ab98def73fc2bcd.jpeg)

@lepras I updated the post with a new link.

---

## Post 4 by @lepras — 2024-03-05T03:49:03Z

> [@anon21489307](#):
>
> Do you have a good place to upload video?

> **[Security Design - Wormhole](https://wormhole.app/security)**
>
> Wormhole lets you share files with end-to-end encryption and a link that automatically expires.

[https://twitter.com/feross/status/1384320519202250753](https://twitter.com/feross/status/1384320519202250753)

---

## Post 5 by @anon97654407 — 2024-03-06T20:13:08Z

I’ve made a PR, as always.

> <https://github.com/privacyguides/privacyguides.org/pull/2426>
>
> Changes proposed in this PR:
> 
> - https://discuss.privacyguides.net/t/nextdns-lo…gging-is-opt-out-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

---

## Post 6 by @anon21489307 — 2024-03-06T20:48:24Z

Thanks!

I see [the commit](https://github.com/privacyguides/privacyguides.org/pull/2426/commits/81daf0338079286bc59510c6267ed3ca4eab307d), but I am still feeling that just changing the logging behavior/policy from `opt-in` to `opt-out` basis is still not enough. Considering that this behavior contradicts with the service [policy #3](https://nextdns.io/privacy), which is also still being described and linked on the page:

> If it’s not specifically requested, no data is logged. [https://nextdns.io/privacy](https://nextdns.io/privacy)

---

## Post 7 by @anon97654407 — 2024-03-06T20:59:32Z

Good catch! Will modify that ASAP.

@archerallstars So, we should say : “if it’s specifically requested by the user, no data is logged”, right? Or I’ve just misunderstood what you wanted to say?

---

## Post 8 by @anonymous159 — 2024-03-06T21:25:09Z

“If it’s not specifically requested, no data is logged. [Privacy Policy - NextDNS](https://nextdns.io/privacy)”

thats interesting… are u sure its not some bug and is normal behavior that logging is enabled by default?

---

## Post 9 by @anon21489307 — 2024-03-06T21:30:12Z

I create a new account, then create a new profile, without further action the logging is turn on by default, as shown in the OP’s screen recording.

It has always been like this for a long time. This is not the first time I talk about this issue in the community:

> [@NextDNS (free) security after 300K queries](https://discuss.privacyguides.net/t/nextdns-free-security-after-300k-queries/15025/1):
>
> If you’re not carefully look into the settings, logging is opt-out, not opt-in. And since you’re bound to 7 days limit with anonymous setup, there’s no way to check whether the logging is enabled :sweat_smile:

---

## Post 10 by @xe3 — 2024-03-06T21:43:01Z

While the recommendation could use some clarification, I don’t think that your PR is more accurate than the current footnote.

NextDNS like Adguard DNS operates both public and private DNS services.

To the best of my knowledge:

1. NextDNS _ **Public** _ DNS service keep no logs:

> When the service comes into contact with user data that shall not be logged, it is discarded as quickly as possible. When answering a DNS query, the server discards all request and response data immediately after sending back the response to you.

1. NextDNS _ **Personal** _ DNS service have logs (as a feature) enabled by default, users would need to opt out if they don’t want logging enabled:

> If not specifically requested by the user, no data is logged. Some features require some sort of data retention; in that case, our users are given the option, control, and full access to what is logged and for how long.
> 
> You can fine-tune what is logged, for how long and in which jurisdiction — the analytics and logs will gracefully adapt. We also follow a strict policy of “What You See Is What We Have” (WYSIWWH), letting you see, export or delete every bit of your data at any time.

The _public_ DNS (which does not require an account) is what is used for example if you choose NextDNS from the drop down menu in Brave or Firefox, or you use the NextDNS mobile apps.

So it would not be correct to call NextDNS _opt-out_ (unless you specifically qualify the statement as applying to the personal (account based) service.

Probably the clearest explanation would separately address the public and personal services. Or would not explicitly refer to opt-in or out but just quote the language of the privacy policy.

---

## Post 11 by @anon21489307 — 2024-03-06T21:54:17Z

> [@xe3](#):
>
> The _public_ DNS (which does not require an account) is what is used for example if you choose NextDNS from the drop down menu in Brave or Firefox, or you use the NextDNS mobile apps.

No, the public one is also logging by default, as shown in the screen recording below:

> **[Proton Drive](https://drive.proton.me/urls/KGW3X2EQ00#I9cmVrAxuUI3)**
>
> Securely store, share, and access your important files and photos. Anytime, anywhere.

At this point, quoting any policy from NextDNS page could be pointless, as all of that could be bogus as well. You SHOULD try for yourself if the logging is on by default.

---

## Post 12 by @anon97654407 — 2024-03-06T21:57:49Z

That isn’t the public one, it’s just the demo account to try it out, which is based in a ““personal”” config (because it uses a string of letters + numbers like a12345, a25642, etc). @xe3 is talking about the public DNS service from NextDNS which isn’t based in any personal config ([https://dns.nextdns.io/](https://dns.nextdns.io/)). It is integrated in Firefox like he mentioned.

@xe3 Thanks for your suggestion, I will check that out tomorrow because it is currently late night in my country and I have to sleep after all.

---

## Post 13 by @xe3 — 2024-03-06T22:04:49Z

> [@anon21489307](#):
>
> At this point, quoting any policy from NextDNS page could be pointless, as all of that could be bogus as well. You SHOULD try for yourself if the logging is on by default.

I have,

1. If used like any other public DNS (quad9, mullvad, cloudflare) no account is required and per their privacy policy (and other statements they have made) no logs are kept (you don’t even have the ability to opt-in to logging without an account on the public service)
2. _IF_ you choose to sign up for an account (or use the demo account), logs are enabled by default.

This doesn’t contradict what their privacy policy says (if you simply download and use the app, or point your browser to NextDNS’s default DNS servers, no logging is enabled by default. While it is not technically inaccurate, I feel that their privacy policy (and the PG guidance) could be made much more clear and explicit.

---

## Post 14 by @anon21489307 — 2024-03-06T22:35:09Z

> [@xe3](#):
>
> While it is not inaccurate, I feel that there privacy policy could be made more clear and explicit.

The [privacy policy #3](https://nextdns.io/privacy) stated clearly that: **if not specifically requested by the user, no data is logged.** According to this statement, even when you use _ **Personal** _ DNS, whether with a temp account, or any kind of DNS from them, the log should not be turned on by default, since the user (with the acc. or not) is **not _specifically_ requested** for the logging, especially, when **it’s the only channel for the users to request the logging.**

On the other hand, when you use it in _the browser DNS settings_, it’s **impossible** to request the service for logging. Therefore, I believe that privacy policy #3 has nothing to do with this usage channel, thus should revert to privacy policy #2. In other word, **privacy policy #3 is only applicable when it’s _possible_ to request the logging** , i.e. when you use the feature that requires the logging to be enabled in your user account.

For the app, it seems to be available on iOS only. So, I have no way to test it (I only own Android).

> [@xe3](#):
>
> _IF_ you choose to sign up for an account (or use the demo account), logs are enabled by default.

Which is still contradicted to privacy policy #3 as explained above.

---

## Post 15 by @wojciechxtx — 2024-03-06T23:08:35Z

> [@anon21489307](#):
>
> Do you have a good place to upload video?

yes I have: its called [Proton Drive](https://proton.me/drive)

---

## Post 16 by @anon21489307 — 2024-03-06T23:23:29Z

Thanks! Totally forget about it.

I will update all the links with Proton Drive.

---

## Post 17 by @xe3 — 2024-03-06T23:32:14Z

> For the app, it seems to be available on iOS only. So, I have no way to test it (I only own Android).

For the iOS app, nothing is enabled by default (and it uses the public resolver (so no logging) unless you go out of your way to setup an account through the website). So in the context of the app if no user action is taken, there is no logging.

> [@anon21489307](#):
>
> The privacy policy #3 stated clearly that: if not specifically requested by the user, no data is logged. According to this statement, even when you use _Personal DNS, whether with a temp account, or any kind of DNS from them, the log should not be turned on by default, since the user (with the acc. or not) is not specifically_ requested for the logging, especially, when it’s the only channel for the users to request the logging.

I agree that the language should be changed (or better yet, instead of enabling logs by default, present users with an explicit choice during signup/first-start)

All this could be cleared up by just changing the privacy policy to reflect that:

1. Public resolver = no logs
2. Personal/custom profile = logs are optional but enabled by default, configurable in user settings.

---

## Post 18 by @anon21489307 — 2024-03-07T19:05:45Z

I’ve unsolved this thread because I think the [latest PR](https://github.com/privacyguides/privacyguides.org/pull/2426) still doesn’t reflect the behavior of the opt-out basis accurately.

I make a new PR here:

> <https://github.com/privacyguides/privacyguides.org/pull/2427#issue-2174565057>
>
> Changes proposed in this PR:
> 
> - Update NextDNS footnote message in dns.md rega…rding the service's logging behavior to reflect the _ **opt-out** _ basis that's recently change in 67614c3e174739abbd96c6dccee1b6d3657c6ba4, as it's _only possible_ to specifically requested the logging when the logging is done on an **_opt-in_** basis. 
> 
> Since we had already reflected the reality of service regarding the logging on an opt-out basis, this change is necessary.
> 
> ## The screenshot showing that **clients IPs and domains** will be logged by default on an opt-out basis:
> ![ss](https://github.com/privacyguides/privacyguides.org/assets/1403194/b4e42111-c8d2-4351-a345-3ddcbc868258)
> 
> ## The screen recordings to prove that, with or without signing up for an account, the logging is on by default on an opt-out basis:
> 
> ### With an account:
> https://github.com/privacyguides/privacyguides.org/assets/1403194/1aedae4a-ec93-4e35-9bd6-a286dbe539c0
> 
> ### Without an account:
> https://github.com/privacyguides/privacyguides.org/assets/1403194/523d2aff-91cb-4a1b-817c-cd799743e353
> 
> The discussion about this issue can be found here: https://discuss.privacyguides.net/t/nextdns-logging-is-opt-out-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206.
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

---

## Post 19 by @anonymous159 — 2024-03-07T19:25:34Z

your pr doesn’t make complete grammatical sense. maybe it would be better expressed as a yellow/red warning banner instead also

i wonder what @dngray’s thoughts would be on if this is big enough to warrant a banner like that

---

## Post 20 by @anon21489307 — 2024-03-07T19:27:41Z

> [@anonymous159](#):
>
> your pr doesn’t make complete grammatical sense.

I allow the maintainer to make changes as necessary.

---

## Post 21 by @anonymous159 — 2024-03-07T19:31:38Z

no reason you can’t make some yourself. here is what i would change it to:

‘By default, user created profiles have logs (including client IP addresses and domains) enabled by default. Note that this somewhat contradicts the service’s privacy policy, which states that “If not specifically requested by the user, no data is logged.”’

I added a direct quote from the privacy policy to back up your statement too.

---

## Post 22 by @anon21489307 — 2024-03-07T19:38:44Z

Thanks! I updated the commit as suggested:

> <https://github.com/privacyguides/privacyguides.org/pull/2427/commits/6f3d0ffee6619d5ba752a19d78e1c0cb8dec64e2>
>
> As suggested here: https://discuss.privacyguides.net/t/nextdns-logging-is-opt-ou…t-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206/21
> 
> Signed-off-by: Archer Allstars <archerallstars@proton.me>

---

## Post 23 by @xe3 — 2024-03-07T21:26:54Z

I think this could still be made more clear.

To recap:

1. NextDNS public resolver = no logs kept
2. NextDNS w/ an account (including trial accounts) = logs by default, opt-out possible

Your current PR clarified option #2 which is good. But you’ve left out #1 entirely, which is still misleading, just in a different way.

I’d suggest something like,

> If used _without_ an account, NextDNS does not keep logs.  
> If used _with_ an account, NextDNS can provide insights and logging features. Logging is enabled by default. You can choose retention times and log storage locations for any logs you choose to keep, or disable logs completely. Note that this is inconsistent with the service’s [Privacy Policy - NextDNS](https://nextdns.io/privacy) [:right_arrow_curving_left:](https://www.privacyguides.org/en/dns/#fnref:5)

---

## Post 24 by @anon21489307 — 2024-03-07T21:55:21Z

> [@xe3](#):
>
> Your current PR clarified option #2 which is good. But you’ve left out #1 entirely, which is still misleading, just in a different way.

I don’t think it’s misleading, since the footnote specifically stated about **insights and logging features** , which require a user account to be usable, and also their related privacy policy.

Moreover, we can’t guarantee that the no log policy when using the service without the insights and logging features wouldn’t be bogus as well. Maybe a banner like what @anonymous159 suggested would be more appropriated than to include an _unrelated policy_ to the current footnote content.

---

## Post 25 by @FlipSid — 2024-03-07T22:04:26Z

On a side question:  
Anyone, who has a account, can open a issue at GitHub if he hopes for something to be resolved?  
Simple yes/no, as I dont want to derail

---

## Post 26 by @anon21489307 — 2024-03-07T22:12:34Z

Agreed, at this point, it would be more appropriated to discuss this issue in the [opened PR](https://github.com/privacyguides/privacyguides.org/pull/2427#issue-2174565057), unless one also has their PR opening and want to inform the others in this thread/community.

---

## Post 27 by @anon97654407 — 2024-03-07T22:27:46Z

Yes, anyone with a GitHub account can do that. Though, recommendations should be discussed first in the forum before opening a PR.

---

## Post 28 by @FlipSid — 2024-03-07T22:30:35Z

Both of you have a private message :+1:t5:

---

## Post 29 by @xe3 — 2024-03-07T22:42:13Z

> [@anon21489307](#):
>
> I don’t think it’s misleading, since the footnote specifically stated about **insights and logging features** , which require a user account to be usable, and also their related privacy policy.

Footnote #5 refers to [the logging policy for NextDNS as a whole.](https://www.privacyguides.org/en/dns/#recommended-providers) Which can be used with or without an account.

![Screenshot from 2024-03-07 15-09-15](//forum-uploads.privacyguidesusercontent.com/optimized/2X/3/3c4ca25a215ead1a3c484d09d058d5b1c6bbc168_2_690x23.png)

* * *

ControlD is in a similar situation, [and both things are clearly and separately acknowledged in the footnote](https://www.privacyguides.org/en/dns/#fn:3) It would be inconsistent and misleading to treat NextDNS differently.

![Screenshot from 2024-03-07 15-09-30](//forum-uploads.privacyguidesusercontent.com/optimized/2X/b/bbcdb2bd337ca36177c4910730f985d8708cb482_2_690x23.png)

> 1. Control D only logs for Premium resolvers with custom DNS profiles. Free resolvers do not log data.

---

## Post 30 by @anon21489307 — 2024-03-10T05:23:50Z

There’s a new PR being discussed here:

> <https://github.com/privacyguides/privacyguides.org/pull/2434>
>
> Changes proposed in this PR:
> 
> - CONTEXT: This PR revises footnote 5 in the DNS… section (NextDNS' logging policy) it builds upon and further clarifies 67614c3 and is an alternative to the proposed `PR 2427`.
> 
> - PROBLEM: The current description needs clarification and seemingly contradicts itself (it begins by stating logging is opt-out and ends by saying no logs are kept without the user 'specifically requesting it'). It also does not differentiate NextDNS's public DNS servers `dns.nextdns.io` from the personal `my.nextdns.io/<ID>`.
> 
> - There is a pending PR (2427) that proposes to amend that footnote, but the proposed changes in that PR leave out important information that can help readers make an informed choice. My assessment is that PR 2427 helpfully clarifies one inaccuracy but introduces its own inaccuracy by omission. The author of that PR has so far been unwilling to amend or modify it. So I am creating this PR as an alternative.
> 
> - GOAL: The goal of this PR is to provide readers clearer and fuller information than the current footnote provides, and provide fuller information than the other proposed pull request (2427) and use neutral language.
> 
> - SPECIFIC CHANGES: This PR is an improvement in three specific ways, (1) it clarifies the seemingly contradictory statements about logging (2) it explains to readers how the the logging policy will apply to NextDNS's public and personal DNS services, and (3) it alerts readers to the apparent contradiction between the NextDNS privacy policy, and the default account settings.
> 
> - The proposed language is:
> >When used with a user account, NextDNS will enable insights and logging features by default (note: this seemingly conflicts with their privacy policy). You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether. If used without a user account, no data is logged. [https://nextdns.io/privacy](https://nextdns.io/privacy)
> 
> - IF this PR is accepted [PR 2427](https://github.com/privacyguides/privacyguides.org/pull/2427) should be rejected. IF 2427 is accepted this PR should be rejected.
> 
> -----------------------------------
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

---

## Post 31 by @anon21489307 — 2024-03-13T07:07:06Z

Now, the PR has been merged, unfortunately, with this commit:

> <https://github.com/privacyguides/privacyguides.org/pull/2434/commits/bfa4b0f422c9eccdbbf916877680bdb689a5d7c6>
>
> Co-authored-by: Jonah Aragon <jonah@triplebit.net>
> Signed-off-by: Daniel Gray <d…ngray@privacyguides.org>

> When used with an account, NextDNS will enable insights and logging features by default (as some features require it). You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether. If used without an account, no data is logged. [https://nextdns.io/privacy](https://nextdns.io/privacy)

It’s a total disaster, IMO. This really shows there’s a favorite kid that would be protected by the teacher no matter what.

I have at lease 2 issues with the above statement that got merged to the PG repo:

1. It conflicts with NextDNS privacy policy #3 regarding the logging policy when using the service with an account, which stated that:

> **If not specifically requested by the user** , no data is logged. Some features require some sort of data retention; in that case, our users are given the option, control, and full access to what is logged and for how long.

Can anyone see the bold text in the statement above? It’s saying that the logging is NOT turned on by default, unless the user _specifically_ requested it.

So, with the merged PR’s statement:

> When used with an account, **NextDNS will enable insights and logging features by default** (as some features require it). You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.

Where the hell in the policy which stated that **NextDNS will enable insights and logging features _by default_** when the user uses the service with an account???

The policy stated it clearly that the user NEEDS to request the logging, **in which can only be done with a user account**. It means that, with or without a user account, the logging shall not be enabled without the user consent.

This is completely different from Control D’s case that [its policy #3](https://controld.com/privacy) stated it clearly what is going to be logged, and what is not.

1. PG is covering for **a service that clearly violated its policy**. Instead of contracting to NextDNS regarding the policy that’s conflicting with the service’s logging behavior, it covered the service ass even though there’s none of the service’s policy to back it up.

Just to make myself clear. I HAVE NO PROBLEM WITH THE SERVICE LOGGING. I have a problem because the service violated its policy and PG still defends it despite my concerns in the PR.

I [asked](https://github.com/privacyguides/privacyguides.org/pull/2434#discussion_r1519957946) @jonah one last time in the PR, as I see his commit suggestion could be the final version that could be merged into the repo:

> Are you sure NextDNS privacy policy number 3 refer to the usage without an account (as the logging can only be requested on a user account)?
> 
> We are not trying to cover something, are we? The service clearly violated its policy, why do we still act like nothing happened? And the last question, if this was not NextDNS, do we still recommend the service/app that violated its policy?

However, there’s no answer in sight…

I will mark this comment as a solution, as I don’t care anymore. In the end, it’s a kid game. Wishing everyone good luck, everyone.

---

## Post 32 by @dngray — 2024-03-13T12:16:41Z

I would take NextDNS’s privacy policy up with them. I don’t think they’re doing anything nefarious.

It seems to be a case of:

- No logging by default, if you use the public revolvers with no account
  - If you use an account **because you want to log** what you’ve been doing then logging **will exist** duh
  - You can choose to use an account **without logging** if you don’t care about missing out on said features that provide _you_ insight on what _you’ve_ been doing with your account.

Am I missing anything? I think the commit does get that point across.

Edit: I have put in a request with NextDNS to get them to clarify, hopefully they do.

---

## Post 33 by @anonymous159 — 2024-03-13T15:23:47Z

> - If you use an account **because you want to log** what you’ve been doing then logging **will exist** duh

that’s a huge assumption. there are many other more important reasons why someone would create an account, namely to customise the blocklists. in my case, the only reason why you would want to turn on logs in the first place is to check what is being blocked so that something can be added in the first place. that’s not something that should be on by default (and with the location of the United States instead of somewhere more private for some reason).

---

## Post 34 by @anonymous159 — 2024-03-13T15:24:33Z

added to the allowlist\*

---

## Post 35 by @jonah — 2024-03-13T15:31:31Z

I didn’t realize the privacy policy was what was in question here, I thought it was just outdated information on our end. I’m okay with removing it until their privacy policy reflects their current defaults.

In this PR it is replaced with dns0.eu:

> <https://github.com/privacyguides/privacyguides.org/pull/2330>
>
> Changes proposed in this PR:
> 
> - https://discuss.privacyguides.net/t/split-dns-…recommendations-into-secure-non-filtering-providers-and-filtering-saas-providers/15026?u=jonah
> 
> Additional changes:
> 
> - Remove NextDNS until their privacy policy reflects their current defaults: https://discuss.privacyguides.net/t/nextdns-logging-is-opt-out-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206/31
> - Add dns0.eu https://discuss.privacyguides.net/t/dns0-dns-provider/12231
> - Closes #2430
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

We desperately need to split NextDNS away from this table as noted a few months ago here anyways:

> [@Split DNS recommendations into secure/non-filtering providers, and filtering/SaaS providers](https://discuss.privacyguides.net/t/split-dns-recommendations-into-secure-non-filtering-providers-and-filtering-saas-providers/15026):
>
> Continuing the discussion from [How is a NextDNS account private?](https://discuss.privacyguides.net/t/how-is-a-nextdns-account-private/14018/18): We could probably split our recommendations between: Cloudflare Quad9 Mullvad and AdGuard Control D NextDNS The latter 3 with their account-based controls are kind of an entirely separate type of service compared to the first three, they’re more like a cloud-hosted Pi-hole, and we should probably explain that distinction more clearly. This is also kind of related to the problem this person had:

> [@anon21489307](#):
>
> It’s a total disaster, IMO. This really shows there’s a favorite kid that would be protected by the teacher no matter what.

I don’t think this is particularly fair, the committed information is still accurate anyhow.

---

## Post 36 by @dngray — 2024-03-13T15:35:13Z

I missed that one in the backlog. We should also look at adding mention of providers which support [private ECS](https://github.com/privacyguides/privacyguides.org/issues/2430).

---

## Post 37 by @jonah — 2024-03-13T15:36:15Z

Funny, I just pushed a commit to that PR which does clarify that, and I didn’t see that GitHub Issue. This PR does now address that :slight_smile:

---

## Post 38 by @BionicBison — 2024-03-31T14:35:06Z

> [@jonah](#):
>
> I’m okay with removing it until their privacy policy reflects their current defaults.

Just saw the updated version of the site. If we’re removing it for this reason, why is it still there as a cloud filtering recommendation? I thought that’s exactly where the problem was regarding the privacy policy.

---

## Post 39 by @dngray — 2024-03-31T14:38:27Z

We’re still waiting to hear back from them.

I think to be honest we could just put a warning admonition there stating that the comment about not logging relates to non-account use of NextDNS and that if you want logging disabled you must do so when creating an account.

There is also a thread I saw on their forum [Important Inaccuracy in the NextDNS privacy policy - Bug Reports - NextDNS Help Center](https://help.nextdns.io/t/35y8kn1/important-inaccuracy-in-the-nextdns-privacy-policy)

---

## Post 40 by @Valynor — 2024-03-31T17:54:51Z

I think that the default-on logging is not really a big issue. With a blocking DNS resolver you actually _want_ the logs on (say, 24h retention) so you can see what is and isn’t blocked by the service and adjust the Allow/Deny list accordingly. IMHO.

---

## Post 41 by @BionicBison — 2024-03-31T19:06:31Z

I think the main point of concern isn’t necessarily whether it’s an issue, more about how they communicate it. When they say “If not specifically requested by the user, no data is logged,” I think it’s reasonable that a user would assume that a “specific request” would involve clicking a button to turn on logs, not simply making an account. Regardless, I’m not here to dispute the original decision to remove them until they get back to us on this, I’m just more confused why the PR that involved removing them from the table for this reason also added them under the new cloud filtering category.

---

## Post 42 by @Valynor — 2024-03-31T20:10:10Z

On the homepage [nextdns.io](http://nextdns.io) they write:

> ANALYTICS & LOGS
> 
> See what’s happening on your devices with in-depth analytics and real-time logs.  
> Measure the efficiency of your security, privacy and parental control strategies.  
> Decide how long your logs are kept — from one hour up to two years — or disable logging completely for a no-logs experience.

---

## Post 43 by @xe3 — 2024-03-31T20:21:02Z

> [@Valynor](#):
>
> I think that the default-on logging is not really a big issue

The issue isn’t so much that the policy is to log by default (though arguably, the default should be a shorter timeframe like a day or a week) . The issue people are rightfully concerned about is that the privacy policy very clearly and prominently states that there is no logging by default unless a user deliberately chooses to enable it.

> **If not specifically requested by the user, no data is logged.**

Like most people using a DNS service like NextDNS or ControlD, part of the reason I use the service is for the logging and insights/personal analytics. I leave logging enabled. But regardless of that personal preference, I do strongly feel NextDNS needs to fix/clarify their privacy policy and make it clear logs are enabled by default, and until they make that clarification, I think it makes sense for PG to acknowledge the discrepancy.

---

## Post 44 by @ignoramous — 2024-04-01T03:29:56Z

> [@Valynor](#):
>
> think that the default-on logging is not really a big issue

Wait till you find out that NextDNS uses Google Cloud to deliver those logs on their dashboard which is hosted on Vercel (which itself is built on AWS) fronted by Cloudflare. :person_shrugging:

But their privacy policy mentions nothing of the sort in “sub processors” ([privacyguides _knows_ about this since I’ve reported it on GitHub before](https://github.com/privacyguides/privacyguides.org/issues/1898#issuecomment-1383281197)). If I’m allowed to be cynical, hiding truth by omission seems like a pattern here.

(disclaimer: I run a public DoT/DoH resolver)

---

## Post 45 by @anonymous166 — 2024-04-01T10:50:04Z

@anon21489307

---

## Post 46 by @BionicBison — 2024-04-01T15:48:34Z

Respectfully, I don’t believe I’ve gotten an answer to my original question, which consists of two parts now I suppose:

1. Has the team come to a consensus that NextDNS should be removed until they clarify their privacy policy?
2. If so, why was it removed from the table only to be re-added under the new cloud filtering section?

---

## Post 47 by @KeepItSimple — 2024-04-03T06:08:09Z

You guys start to lose common sense. NextDNS is one of the best options there and logs are usefull for checking what’s going on, easy to disable or change to 1h/24h. Same could be applied to Brave, you could say they show 2 checks for opt-out after install, so that is not opt-in, but opt-out and Brave is bad.

---

## Post 48 by @jonah — 2024-04-03T06:31:46Z

> [@BionicBison](#):
>
> Has the team come to a consensus that NextDNS should be removed until they clarify their privacy policy?

No, @dngray is looking to get in touch with them first.

> [@BionicBison](#):
>
> If so, why was it removed from the table only to be re-added under the new cloud filtering section?

It was removed from the table for a [reason](https://github.com/privacyguides/privacyguides.org/pull/2330#discussion_r1526341356) unrelated to this discussion in a PR I authored last November:

> [@Split DNS recommendations into secure/non-filtering providers, and filtering/SaaS providers](https://discuss.privacyguides.net/t/split-dns-recommendations-into-secure-non-filtering-providers-and-filtering-saas-providers/15026):
>
> Continuing the discussion from [How is a NextDNS account private?](https://discuss.privacyguides.net/t/how-is-a-nextdns-account-private/14018/18): We could probably split our recommendations between: Cloudflare Quad9 Mullvad and AdGuard Control D NextDNS The latter 3 with their account-based controls are kind of an entirely separate type of service compared to the first three, they’re more like a cloud-hosted Pi-hole, and we should probably explain that distinction more clearly. This is also kind of related to the problem this person had: [https://discuss.privacyguid…](https://discuss.privacyguides.net/t/too-many-dns-option-what-to-choose/12139)

---

## Post 49 by @anonymous83 — 2024-04-03T08:57:17Z

imo if they don’t answer it should be removed. the lack of any response doesn’t look good for them

---

## Post 50 by @ignoramous — 2024-04-03T12:34:10Z

> [@jonah](#):
>
> No, @dngray is looking to get in touch with them first.

Default logging or not, the fact that NextDNS uses Google Cloud (from Firefox’s network requests tab to `api.nextdns.io` or MX records on `nextdns.io`), Cloudflare (A/AAAA records on `nextdns.io`, `api.nextdns.io`, `brain.nextdns.io`, `favicons.nextdns.io`, `snapshots.nextdns.io`, `cortex.nextdns.io`, so on…), and Vercel (A/AAAA records on `my.nextdns.io`) is _verifiable_. They also use Vultr (for `steering.nextdns.io`). You’ll not find a mention of these “sub processors” in their privacy policy.

Also, `dns0.eu` explicitly is a data-gathering op (though, [for “threat-intelligence”](https://archive.is/gWiUk)), and I don’t think as such should be recommended as a “privacy friendly” alt (may be “security-friendly”, sure) until there’s more clarity on just what they do. I run a public-facing DoH / DoT resolver (serving 400bn+ requests per year; so not a small op), and I’ve been approached for such agreements (I’ve declined them every time given the terms invariably include “whitelisting” / “allowlisting” some domains under a strict NDA).

---

## Post 51 by @dngray — 2024-04-03T14:34:48Z

> [@ignoramous](#):
>
> Google Cloud

We’re not worried by GCP usage. This has been discussed thoroughly on these forums. The GCP privacy policy is in line with what [other companies provide](https://cloud.google.com/terms/cloud-privacy-notice) for similar commercial services. Just to be clear here **the GCP privacy policy relates to the customer of GCP** not service customers. For that you would need to see the individual service privacy policy of the business that is using GCP.

In other words you can have companies using GCP that are privacy friendly and have good terms or other businesses that are not. So with the NextDNS example [their privacy policy](https://nextdns.io/privacy) is the one which is relevant. **Google does not own NextDNS’s data so they cannot do anything with it** they feel like, but rather provide service to NextDNS.

> [@ignoramous](#):
>
> data-gathering op (though, [for “threat-intelligence”](https://archive.is/gWiUk)

That information though seems to be mostly public sources and not stuff which is particularly private. I think they do that in order to track spam/botnets etc

> This data originates from passive DNS data from our large-scale public DNS resolver and multiple services monitoring zone files, Certificate Transparency logs and WHOIS/RDAP. We also operate Web and DNS crawlers.
> 
> ## Feeds
> 
> We provide different types of data feeds, each with its specific use cases, and each available as a real-time stream and as daily downloadable feed.
> 
> Newly Registered Domains (NRD)  
> Newly Observed Domains (NOD)  
> Newly Observed Hostnames (NOH)  
> Newly Active Domains (NAD)  
> Newly Active Hostnames (NAH)  
> Newly Issued Certificates (NIC)  
> Passive DNS (RRsets)

They have their “zero” service which allows you to also use that data [ZERO — Hardened security for highly sensitive environments — dns0.eu](https://www.dns0.eu/zero) on a “higher security” DNS server.

> [@ignoramous](#):
>
> I run a public-facing DoH / DoT resolver (serving 400bn+ requests per year; so not a small op), and I’ve been approached for such agreements (I’ve declined them every time given the terms invariably include “whitelisting” / “allowlisting” some domains under a strict NDA).

Were you approached by dns0.eu or are you saying some other random threat intelligence companies?

---

## Post 52 by @ignoramous — 2024-04-03T19:45:59Z

> [@dngray](#):
>
> We’re not worried by GCP usage.

The point is about their privacy policy lacking any mention of all these “sub processors”.

> [@dngray](#):
>
> the GCP privacy policy relates to the customer of GCP

Then, what’s the point of NextDNS “storing” logs in Switzerland, if they’re going to be streamed through GCP servers worldwide (because if GCP is streaming logs stored in Switzerland through Indian servers, then Indian laws apply and GCP will comply with those laws)? PrivacyGuides makes it seem as if “storing” logs in the EU etc is a positive thing: `You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.`

I worked at BigCloud for more than 8 years: BigCloud don’t own ALL the infrastructure. They themselves use services of other providers who may or may not be in bed with respective governments where they operate. Besides it was routine for teams to comply with legal requests by granting access to actual customer data / metadata to the law enforcement. Some even had an automated workflow to grab all such data and bundle it up for legal. GCP I don’t _think_ is any exception (see section 7.1.2: [Cloud Data Processing Addendum &nbsp;|&nbsp; Google Cloud](https://cloud.google.com/terms/data-processing-addendum)).

> [@dngray](#):
>
> So with the NextDNS example [their privacy policy](https://nextdns.io/privacy) is the one which is relevant.

A concise privacy policy doesn’t mean it is _complete_. For reference, here’s Vercel privacy policy that clearly spells out what information is and isn’t available to various tools and services they use: [Privacy Policy](https://vercel.com/legal/privacy-policy#when-we-share)

To be honest, I don’t really have a strong opinion one way or the other, but if PrivacyGuides is serious about avoiding the next Skiff, then transparency from companies must be top priority (and err on the side of caution in absence of clarity).

> [@dngray](#):
>
> Were you approached by dns0.eu or are you saying some other random threat intelligence companies?

Can’t disclose. Under NDA.

> [@dngray](#):
>
> That information though seems to be mostly public sources and not stuff which is particularly private. I think they do that in order to track spam/botnets etc

I implore you to not assume. Ask them, and see what you get.

---

## Post 53 by @dngray — 2024-04-04T03:38:20Z

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > We’re not worried by GCP usage.
> 
> The point is about their privacy policy lacking any mention of all these “sub processors”.

This is something I raised in a subsequent email to them. I really like for example how Hashicorp does this: [Subprocessors](https://www.hashicorp.com/trust/privacy/subprocessors)

I think their policy is a bit bare bones and could do with improvements.

> [@ignoramous](#):
>
> Then, what’s the point of NextDNS “storing” logs in Switzerland, if they’re going to be streamed through GCP servers worldwide (because if GCP is streaming logs stored in Switzerland through Indian servers, then Indian laws apply and GCP will comply with those laws)? PrivacyGuides makes it seem as if “storing” logs in the EU etc is a positive thing: `You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.`

You could really argue that about any provider who uses any third party whether it be Azure, AWS or some other platform. If that is the new criteria we should just ban any service that doesn’t own their own servers and not single out GCP specifically.

That will basically mean we’re left with very few services/reliable services and will be throwing out a huge amount of products which actually do work well.

> [@ignoramous](#):
>
> I worked at BigCloud for more than 8 years: BigCloud don’t own ALL the infrastructure. They themselves use services of other providers who may or may not be in bed with respective governments where they operate. Besides it was routine for teams to comply with legal requests by granting access to actual customer data / metadata to the law enforcement. Some even had an automated workflow to grab all such data and bundle it up for legal. GCP I don’t _think_ is any exception (see section 7.1.2: [Cloud Data Processing Addendum | Google Cloud](https://cloud.google.com/terms/data-processing-addendum)).

Every service will comply with legal requests to some degree. That is the cost of continuing business arrangements. Singling out GCP because of legal requests really doesn’t address that problem and just seems like a misguided degoogle bent.

There is also no way to ensure that doesn’t happen besides throwing all your traffic in an encrypted tunnel and routing it somewhere else. If you’re worried about legal requests and the stream of traffic is persistent, I would not necessarily rely on a VPN provider to keep that confidentiality. They are also susceptible to bribes and other forms of coercion.

There is really no substitute to using Tor for a threat model where you have sustained government interest. Encrypted DNS was never really designed to give you strong confidentiality as there are [plenty of other ways](https://www.privacyguides.org/en/advanced/dns-overview/) in which your usage can and will leak. The point of encrypting queries is stop outside manipulation and snooping at a network level, not thwart legal requests or targeted interest. Also with DNS you often don’t have much of choice about which route those queries take as any provider of size uses anycast addresses.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > So with the NextDNS example [their privacy policy](https://nextdns.io/privacy) is the one which is relevant.
> 
> A concise privacy policy doesn’t mean it is _complete_. For reference, here’s Vercel privacy policy that clearly spells out what information is and isn’t available to various tools and services they use: [Privacy Policy – Vercel](https://vercel.com/legal/privacy-policy#when-we-share)
> 
> To be honest, I don’t really have a strong opinion one way or the other, but if PrivacyGuides is serious about avoiding the next Skiff, then transparency from companies must be top priority (and err on the side of caution in absence of clarity).

I don’t think NextDNS is anywhere near a “Skiff”. If you remember Skiff was quite new and pushed their addition to numerous sites very aggressively. Almost as if they were trying to inflate their user count knowing full well that the Notion deal was going to happen.

Conversely NextDNS is not new and they haven’t asked to be mentioned anywhere that I can see. NextDNS does partner with Mozilla and other companies which do care about privacy so that has to mean something. I have sent them another email (maybe the last one went to junk).

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > Were you approached by dns0.eu or are you saying some other random threat intelligence companies?
> 
> Can’t disclose. Under NDA.

That’s unfortunate, I have unfortunately noticed a theme with quite a few of your replies which have an element of [argument from authority](https://en.wikipedia.org/wiki/Argument_from_authority), without actual counter points other than “trust me, I know stuff”. In your previous reply you said:

> [@ignoramous](#):
>
> I’ve been approached for such agreements (I’ve declined them every time given the terms invariably include “whitelisting” / “allowlisting” some domains under a strict NDA).

I can’t see how you’d be bound by a NDA on an agreement you didn’t accept.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > That information though seems to be mostly public sources and not stuff which is particularly private. I think they do that in order to track spam/botnets etc
> 
> I implore you to not assume. Ask them, and see what you get.

This is perhaps something that will require extra research. Are you talking about this? or something else?

> We are looking to partner with national and pan‑European hosting providers, threat intelligence providers, CERTs and financial sponsors — talk to us at [partners@dns0.eu.](mailto:partners@dns0.eu)

CERTs (Computer Emergency Response Team), and “threat intelligence providers” in pan-European really can only mean one thing, and that is they want more data about threats in Europe for their Zero program.

---

## Post 54 by @pinkandwhite — 2024-04-04T06:53:09Z

Can we take a step back and also just ask, what’s wrong with threat intel companies? This dns0/ZERO initiative doesn’t seem like a bad thing – in fact it seems like a _good_ thing, at least from a skim of the heuristics they use as well as what they ask for on their twitter.

Also, threat intel only really gets super specific to you as a random DNS user if you’re literally a major threat actor and people look into you in particular. To assume otherwise is blowing things out of proportion because like, the average person’s info would only get into a piece of shared threat intel if they were actually doing enough “interesting” things to cause an alert to fire off.

---

## Post 55 by @ignoramous — 2024-04-04T10:43:25Z

> [@dngray](#):
>
> You could really argue that about any provider who uses any third party whether it be Azure, AWS or some other platform. If that is the new criteria we should just ban any service that doesn’t own their own servers and not single out GCP specifically.

That wasn’t my point. My point was, the part where PrivacyGuides highlights NextDNS’ “log storage location” feature is misleading in light of their use of all these other global service providers. Imagine if a VPN provider told you they stored connection logs in some location but then streamed it out to users with GCP, AWS, and Cloudflare having access to it in _plaintext_.

> [@dngray](#):
>
> That will basically mean we’re left with very few services/reliable services and will be throwing out a huge amount of products which actually do work well.

Again: It is about how transparent a provider is about the services they use. Not about what they can and can’t use.

> [@dngray](#):
>
> NextDNS does partner with Mozilla and other companies which do care about privacy so that has to mean something

You’ll notice that it is a separate endpoint and not the one sold to users or recommended by PrivacyGuides. Cloudflare does the same (they’ve got a Mozilla specific endpoint).

> [@dngray](#):
>
> I have unfortunately noticed a theme with quite a few of your replies which have an element of [argument from authority](https://en.wikipedia.org/wiki/Argument_from_authority)

Incredible. I mention how X works because I’ve been there, done that, and this is how you insult me. What a colossal dumpster fire. I feel sorry I even bother.

> [@dngray](#):
>
> I can’t see how you’d be bound by a NDA on an agreement you didn’t accept.

NDAs are signed _before_ you even take such meetings.

> [@dngray](#):
>
> This is perhaps something that will require extra research.

If I were to recommend something like this, I’d email the developers and clarify with them what data they collect from user requests, how they process / de-anonymize them, and how they vet who they share it with.

> [@pinkandwhite](#):
>
> This dns0/ZERO initiative doesn’t seem like a bad thing

Privacy and security can clash at times.

---

## Post 56 by @pinkandwhite — 2024-04-04T11:01:29Z

> [@ignoramous](#):
>
> Privacy and security can clash at times.

Could you please elaborate on how that’s the case here? As I said, threat intel is unlikely to have people’s personal data (I guess dns requests in this case) unless they’re doing something that’d make an alert fire off, because to do otherwise would make the threat intel pretty useless and overly broad ~~and I hate to argument from authority but this is something _I’ve_ “been there, done that”~~

---

## Post 57 by @ignoramous — 2024-04-04T11:10:59Z

> [@pinkandwhite](#):
>
> Could you please elaborate on how that’s the case here?

My point is, get more clarity before recommending `dns0.eu` as “no logs”. Cloudflare also gathers intel as does Quad9, and _both_ are marked as such on PrivacyGuides: [DNS Resolvers - Privacy Guides](https://www.privacyguides.org/en/dns/#fn:2)

> [@pinkandwhite](#):
>
> ~~and I hate to argument from authority but this is something _I’ve_ “been there, done that”~~

Interesting. If I may, where?

---

## Post 58 by @pinkandwhite — 2024-04-04T11:12:31Z

> [@ignoramous](#):
>
> Interesting. If I may, where?

Large, non-government organisation in Australia. Not willing to pinpoint more than that lol

---

## Post 59 by @ignoramous — 2024-04-04T11:13:22Z

> [@pinkandwhite](#):
>
> Large, non-government organisation in Australia. Not willing to pinpoint more than that lol

Wise move. If you do, you’ll be insulted.

---

## Post 60 by @dngray — 2024-04-04T13:12:56Z

> [@ignoramous](#):
>
> NextDNS’ “log storage location” feature is misleading in light of their use of all these other global service providers

This is largely speculation that GCP is logging everything regardless of a downstream privacy policy. One could make a similar argument that colocation isn’t even good enough because a datacenter might track incoming IPs on their firewall.

I do agree though they should be clearer about their sub processors though. Their Privacy policy is likely brief for brevity reasons (and maybe too much so).

Hopefully we hear back from them soon.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > NextDNS does partner with Mozilla and other companies which do care about privacy so that has to mean something
> 
> You’ll notice that it is a separate endpoint and not the one sold to users or recommended by PrivacyGuides. Cloudflare does the same (they’ve got a Mozilla specific endpoint).

That may be so, and due to scaling and provisioning. They would still have to have some competency as a service. This isn’t really evidence that the services are run in a vastly different way.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > I can’t see how you’d be bound by a NDA on an agreement you didn’t accept.
> 
> NDAs are signed _before_ you even take such meetings.

All of this really can’t be verified, so lets drop that. I do find it odd you’d sign an NDA with a company before you even know what the meeting will be about/without contacting a lawyer though.

> [@ignoramous](#):
>
> My point is, get more clarity before recommending `dns0.eu` as “no logs”. Cloudflare also gathers intel as does Quad9, and _both_ are marked as such on PrivacyGuides: [DNS Resolvers - Privacy Guides](https://www.privacyguides.org/en/dns/#fn:2)

> [@pinkandwhite](#):
>
> As I said, threat intel is unlikely to have people’s personal data (I guess dns requests in this case) unless they’re doing something that’d make an alert fire off, because to do otherwise would make the threat intel pretty useless and overly broad

Their privacy policy does state though:

> We do not log any Personally Identifiable Information (PII).
> 
> Our recursive DNS service, this website and other services we provide are fully compliant with the GDPR, and we welcome audits from reputable European entities.

The zero service seems to be information that isn’t specific to dns0. I don’t think you can really argue that Newly Registered Domains or Newly Active Domains are logging. Is it really logging if they look at whois records of requests going through their system? When people think of DNS logging they think of logging the client’s IP, ie who is requesting what domains. I don’t think their service is doing that. We don’t have any evidence that indicates that they do.

If you really can’t trust a privacy policy then you will have to depend on technical means for anonymity.

---

## Post 61 by @ignoramous — 2024-04-04T14:02:31Z

> [@dngray](#):
>
> This is largely speculation

Ask NextDNS what they use GCP for, and let us all know what answers you get. I’m really curious.

It is _verifiable_ that logs are streamed to the dashboard via Cloudflare and GCP or some combination thereof.

> [@dngray](#):
>
> Hopefully we hear back from them soon.

> [@dngray](#):
>
> That may be so, and due to scaling and provisioning

_May_ be? Or is it known for sure? One can tell Cloudflare doesn’t do so because scaling but because the privacy guarantees are actually different: [Cloudflare Resolver for Firefox · Cloudflare 1.1.1.1 docs](https://developers.cloudflare.com/1.1.1.1/privacy/cloudflare-resolver-firefox/)

> [@dngray](#):
>
> This isn’t really evidence that the services are run in a vastly different way

There isn’t really any evidence for what you claim, either.

> [@dngray](#):
>
> All of this really can’t be verified, so lets drop that

Yeah, why can’t it be? I can privately show you those emails, but you didn’t even ask. You just assumed I’m lying. But let’s “hopefully wait for NextDNS to reply” and give them all the benefit of doubt there is until they do and second guess everything else. Astonishing double standards.

> [@dngray](#):
>
> sign an NDA with a company

I fully deserve your scorn for engaging in good faith, because I’m also an idiot (like you imply as I don’t know what lawyers are and what NDA is).

> [@dngray](#):
>
> We do not log any Personally Identifiable Information

Neither does Quad 9 DNS. Why single them out?

> Quad9 safeguards our users’ privacy by not collecting our users’ personal data; we serve the public benefit directly, rather than profiting from their personal data.
> 
> [Privacy | Quad9](https://quad9.com/service/privacy)

---

## Post 62 by @dngray — 2024-04-04T14:22:52Z

> [@ignoramous](#):
>
> Ask NextDNS what they use GCP for, and let us all know what answers you get. I’m really curious.
> 
> It is _verifiable_ that logs are streamed to the dashboard via Cloudflare and GCP or some combination thereof.

That data still remains the intellectual property of NextDNS though. So I honestly don’t know where you’re going with this. Yes they use other services and those services have the data to offer NextDNS service.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > All of this really can’t be verified, so lets drop that
> 
> Yeah, why can’t it be? I can privately show you those emails, but you didn’t even ask. You just assumed I’m lying. But let’s “hopefully wait for NextDNS to reply” and give them all the benefit of doubt there is until they do and second guess everything else. Astonishing double standards.

I didn’t assume you’re lying, and in fact never said that. I said there is no real way for me to know if it is true as I can’t verify it. I didn’t think to ask you for the emails though. If you were under NDA that would be a breach.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > sign an NDA with a company
> 
> I fully deserve your scorn for engaging in good faith, because I’m also an idiot (like you imply as I don’t know what lawyers are and what NDA is).

Why even bother mentioning it if you weren’t going to provide proof? That’s the issue, arguments from from authority are generally a substitute to providing evidence people can see with their own eyes.

> [@ignoramous](#):
>
> Neither does Quad 9 DNS. Why single them out?
> 
> > Quad9 safeguards our users’ privacy by not collecting our users’ personal data; we serve the public benefit directly, rather than profiting from their personal data.
> > 
> > [Privacy | Quad9](https://quad9.com/service/privacy)

You’re right it probably shouldn’t. If you look at the more thorough document: [https://quad9.net/privacy/policy/](https://quad9.net/privacy/policy/)

It states:

> When Quad9 receives the query, it is necessarily contained within an “envelope” (more precisely, an IP protocol header) that contains both of those addresses. Quad9 necessarily holds the Reply To Address in volatile random access memory (“RAM”) for the few microseconds to milliseconds necessary to service the user’s query. During this time, Quad9 uses the Reply To Address to increment a counter of the number of queries received from the enclosing BGP-advertised prefix of the Reply To Address and a counter of the number of queries received from a geographic region that is the smaller of a nation or a population of not less than 10,000 persons.
> 
> The Reply To Address is used for no other purposes, and is purged from RAM as soon as (in the case of a query the user delivers via User Datagram Protocol) we have transmitted the reply to the user’s Reply To Address, or (in the case of a query the user delivers via the Transmission Control Protocol) the sooner of the user or Quad9 closing the TCP connection. The Reply To Address (or any representation of, or proxy for, it) is not copied to permanent storage, nor is it transmitted across the network to any destination other than the user. It leaves the machine on which we received it _only_ in the form of a reply to the user – to no other destination, in no other form, for no other purpose.

> 2.1 IP addresses

> Quad9 does not collect or record IP addresses, nor does it collect or hold any proxy for or representation of IP addresses, nor does it collect or hold any other unique identifier of individuals in lieu of IP addresses.
> 
> Because Quad9 does not collect or hold IP addresses, they cannot be combined or correlated with other information, such as query labels or timestamps, to violate the privacy of Quad9’s users.

This data doesn’t seem specific and is about tracking quality of service in my opinion

> 2.2 Data collected
> 
> Quad9’s data collection is principally in the form of integer counters. At each Quad9 server, this is the full list of items we count:
> 
> - The number of queries for each Query Type, e.g., A, AAAA, NS, MX, TXT
> - The number of each Response Type, e.g., SUCCESS, SERVFAIL, NXDOMAIN
> - The number of queries that arrive over each transport protocol and encryption type, e.g., IPv4, IPv6, TCP, UDP, DoT, DoH, DNScrypt
> - The number of queries originating in each geographic region
> - The number of queries for each malicious domain originating in each geocoded region
> - The number of queries originating in each BGP-advertised IP prefix
> - The number of queries for each malicious domain originating in each BGP-advertised IP prefix
> 
> In addition, we record:
> 
> - The times of the first and most recent instances of queries for each query label

The data doesn’t even appear to be anonymized, it’s just some statistics of how much of a thing they are doing.

> 2.3 Sharing of data
> 
> Quad9 does not share, sell, or rent any information that could identify an individual.
> 
> We do not share this information because we do not have this information. We do not have this information because we do not need this information. Because we do not need this information, we have built no mechanism to collect, retain, analyze, or distribute it.
> 
> Quad9 shares very limited statistical counters with the threat intelligence analysts who provide the threat intelligence feeds that allow us to protect our users from malicious attacks. This feedback allows threat intelligence analysts to refine their analyses and provide us with more accurate information, which in turn allows us to provide our users with better security. This information does not include any personally identifiable information or anything that could be correlated with other data to identify an individual or their Internet use. Specifically, with each threat intelligence analyst, we share the following three pieces of information:
> 
> - Timestamp of each query of each malicious domain they have identified to us
> - The number of queries for each malicious domain they have identified to us, originating in each geocoded region
> - The number of queries for each malicious domain they have identified to us, originating in each BGP-advertised IP prefix
> 
> As a convenience to the threat intelligence analysts, we also supply the originating Autonomous System Number associated with the BGP-advertised IP prefix. This is not data derived from users’ queries but instead data derived independently from BGP routing tables. It does not contain PII, nor can it be combined with PII to characterize a user.
> 
> We do not share counters associated with malicious domains with threat intelligence analysts who have not identified that specific domain to us as malicious.
> 
> Quad9 provides data to a very few carefully vetted security researchers to help them better understand and better protect the public from cyber threats. This data may consist of a sparse statistical sampling of timestamped DNS responses from our cache or upstream authoritative servers, but no address, prefix, ASN, or other data related to the user or the query. It does not contain any PII or any data that we believe could be combined or correlated with PII to characterize a user or their behavior. When we provide such assistance, we do so only under a written agreement that the researcher use information we provide solely for the purpose of improving user security, and not for any other purposes. We require that researchers conduct their analysis on servers and infrastructure owned and operated by Quad9 and do not allow data to be exported from those systems in anything other than summary form.
> 
> Quad9 publishes general information, such as number of threats blocked and infrastructure uptime, to the public.

This is an exceptionally clear Privacy Policy though. I think in the past when Quad9 was added it was not that clear.

Personally I’d vote to make this a “No” in the logging section. They simply do not log queries from customers or information that can identify customers.

---

## Post 63 by @jonah — 2024-04-04T14:45:47Z

Inclined to agree we should be more verbose about our specific criteria, the DNS page seems to rely heavily on our general site-wide criteria instead of having DNS-specific items. We can come up with a set of DNS criteria more like our email/VPN sections, our current criteria doesn’t mention logging despite that being a consideration, so it’s not clear :flushed_face:

Will track on issue: [dns0 has some logging · Issue #2484 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/issues/2484)

---

## Post 64 by @ignoramous — 2024-04-04T15:38:04Z

> [@dngray](#):
>
> That data still remains the intellectual property of NextDNS though

I think we are talking past each other. If a VPN provider stored logs in some über secure location and yet streamed them through GCP/AWS/Cloudflare (with them having plaintext access), would you still call their “log storage feature” a plus? I mean, privacyguides has been more critical for a lot less on other projects (like Windscribe, for example).

> [@dngray](#):
>
> didn’t think to ask you for the emails though. If you were under NDA that would be a breach.

I said nothing about disclosing who or what. Just the comms that happened outside the NDA. But anyway, it doesn’t matter. It isn’t important insofar that DNS service providers, in the name of threat Intel, may be in breach of privacy in ways PrivacyGuides might want to highlight before recommending such services without reservation.

> [@dngray](#):
>
> arguments from from authority are generally a substitute

You insist my arguments are “from authority” even though you agree with the arguments I made (that cloud providers may be disclosing data to law enforcement, that DNS logging is as bad as VPNs snooping on SNI and IPs). I really don’t understand why you’d personally attack me while agreeing with me?

> [@dngray](#):
>
> You’re right it probably shouldn’t

Neither does Cloudflare DNS except for 0.05% of requests in-memory for debugging and DoS protection.

> Cloudflare will only retain or use what is being asked, not information that will identify who is asking it. Except for randomly sampled network packets captured from at most 0.05% of all traffic sent to Cloudflare’s network infrastructure, Cloudflare will not retain the source IP from DNS queries to the Public Resolver in non-volatile storage. These randomly sampled packets are solely used for network troubleshooting and DoS mitigation purposes.
> 
> [1.1.1.1 Public DNS Resolver · Cloudflare 1.1.1.1 docs](https://developers.cloudflare.com/1.1.1.1/privacy/public-dns-resolver/)

Sampling logs is standard for any public resolver (rethinkdns doesn’t even do that) that limits queries in some form (for example, ControlDNS routinely blocks a range of IPs that they judge to be abusive. They couldn’t do so if they had “no logs”).

Even if you turn off NextDNS logging, they need _some_ mechanism to determine if a _free_ account has crossed their 300k limit. Again, some form of in-memory or disk-based metering is needed, that can be traced back to an account (in NextDNS case, it is email-id).

---

## Post 65 by @dngray — 2024-04-04T16:41:11Z

> [@ignoramous](#):
>
> I think we are talking past each other. If a VPN provider stored logs in some über secure location and yet streamed them through GCP/AWS/Cloudflare (with them having plaintext access), would you still call their “log storage feature” a plus?

You can select the country you want store the logs or disable it entirely. I think at the point you’re trusting NextDNS to do logging, it really doesn’t matter what platform they use.

> [@ignoramous](#):
>
> I mean, privacyguides has been more critical for a lot less on other projects (like Windscribe, for example).

On that topic we’ve been in contact with Windscribe and are going to add that to the site, as we recognize it is a good provider. Just waiting on them to release iOS source code (as it’s currently not available).

> [@ignoramous](#):
>
> You insist my arguments are “from authority” even though you agree with the arguments I made (that cloud providers may be disclosing data to law enforcement, that DNS logging is as bad as VPNs snooping on SNI and IPs). I really don’t understand why you’d personally attack me while agreeing with me?

I was referring the comments about the number of requests per year processed by RethinDNS and the NDA thing. These really don’t have any relevance to the discussion.

> [@ignoramous](#):
>
> Neither does Cloudflare DNS except for 0.05% of requests in-memory for debugging and DoS protection.

Technically they keep it for 25 hours but don’t log it which is more than quad9 keep it.

> A Public Resolver user’s IP address (referred to as the client or source IP address) will not be stored in non-volatile storage. Cloudflare will anonymize source IP addresses via IP truncation methods (last octet for IPv4 and last 80 bits for IPv6). Cloudflare will delete the truncated IP address within 25 hours.

> [@ignoramous](#):
>
> Sampling logs is standard for any public resolver (rethinkdns doesn’t even do that) that limits queries in some form (for example, ControlDNS routinely blocks a range of IPs that they judge to be abusive. They couldn’t do so if they had “no logs”).

That data however doesn’t necessarily indicate is the revolver’s IP address. That is what people are going to really care about when they use these services.

> [@ignoramous](#):
>
> Even if you turn off NextDNS logging, they need _some_ mechanism to determine if a _free_ account has crossed their 300k limit. Again, some form of in-memory or disk-based metering is needed, that can be traced back to an account (in NextDNS case, it is email-id).

That could be a simple integer value assigned with an account. Technically still no logging if they’re not keeping the contents of the query ie which domain.

I guess we need to ask ourselves do we want to consider integer counting “a log”. I think if we do that we won’t end up with any DNS providers on there.

I also think we’re quite clear that if anonyimity is something you’re trying to attain then encrypted DNS isn’t the solution to that issue as data can leak from your client in a number of other ways.

---

## Post 66 by @ignoramous — 2024-04-04T17:32:34Z

> [@dngray](#):
>
> I think at the point you’re trusting NextDNS to do logging, it really doesn’t matter what platform they use.

Except that’s not what the PrivacyGuides website points out. It specifically calls out storage location without mentioning that logs are streamed worldwide via BigCloud:

```
- You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.
+ You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.
+ The only way to access the logs is either via nextdns.io dashboard which streams them over Cloudflare or via their API which uses (GCP/AWS?), and it is possible these providers have access to your logs in plaintext.
```

> [@dngray](#):
>
> I was referring the comments about the number of requests per year processed by Rethink DNS, the resolver.

We are public about it; for ex, a graph from our Cloudflare account that runs `sky.rethinkdns.com`: [https://twitter.com/rethinkdns/status/1753126031148662830](https://twitter.com/rethinkdns/status/1753126031148662830)

> [@dngray](#):
>
> and the NDA thing

You might want to go back a few replies and read what you wrote: `I have unfortunately noticed a theme with quite a few of your replies which have an element of argument from authority ` Please stop gaslighting me on top of calling me dishonest / insinuating that I can’t prove my claims.

> [@dngray](#):
>
> These really don’t have any relevance to the discussion.

The relevance is for PrivacyGuides to do due diligence on `dns0.eu` before recommending it as “no logs”. Jonah gets that and created [a github issue for it](https://github.com/privacyguides/privacyguides.org/issues/2484). So, it did have relevance.

> [@dngray](#):
>
> That is what people are going to really care about when they use these services.

Depends on the people and the threat model. If they trust PrivacyGuides and see “no logs” (a _very_ strong guarantee), then they assume there’s absolutely _no logs_. I mean, words mean things. There’s a reason Mullvad goes to the extent they do with diskless servers, verified boot, no remote shell (which they’re working towards etc). To lump, Mullvad’s DNS as “no logs” in the same breath as other DNSes is really being disingenuous, imo.

> [@dngray](#):
>
> That could be a simple integer value assigned with an account. Technically still no logging if they’re not keeping the contents of the query ie which domain.

More assumptions, and just a few comments ago, you accuse me of speculation? My only point was, why not ask them instead? If they won’t reply, why make your own assumptions? Is recommending a service _more_ important than recommending a good one? What’s PrivacyGuides charter? Also, I find it weird someone would defend something they’re not affliated with to the extent you are, because I genuinely feel you’re not addressing the specific points I am making at all, and going off on some tangent about how absurd it is to demand “no logs” from DNS providers.

---

## Post 67 by @dngray — 2024-04-05T06:12:27Z

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > I think at the point you’re trusting NextDNS to do logging, it really doesn’t matter what platform they use.
> 
> Except that’s not what the PrivacyGuides website points out. It specifically calls out storage location without mentioning that logs are streamed worldwide via BigCloud:
> 
> ```
> - You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.
> + You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.
> + The only way to access the logs is either via nextdns.io dashboard which streams them over Cloudflare or via their API which uses (GCP/AWS?), and it is possible these providers have access to your logs in plaintext.
> ```

The reason we don’t mention “Big Cloud” is because it doesn’t really impact the threat model. If you **don’t** trust the Privacy Policy of NextDNS and their suppliers then you need to employ anonymization (Tor, VPN etc).

None of the encrypted DNS providers advertise themselves as being anonymous, simply that they do not log. This has been discussed elsewhere, but Privacy Guides doesn’t need to constantly keep an eye on every provider’s sub processors. The reason for this is there can be a variety of sub processors and it can be impossible for us to truly know depending on what they are used for. It can also change and we would have to constantly check every provider by essentially re-valuating every recommendation. Even then we only see the outside picture.

That being said we are attempting to encourage NextDNS to provide a little more detail in that regard. The data is still bound by [NextDNS’s privacy policy](https://nextdns.io/privacy), we’re up front that account usage has logging by default and you might need to disable it. They are very clear in their privacy policy that they don’t sell that data.

> [@ignoramous](#):
>
> We are public about it; for ex,

Mentioning if it was irrelevant to the conversation taking place regardless of if there is public evidence of it.

> [@ignoramous](#):
>
> Please stop gaslighting me on top of calling me dishonest / insinuating that I can’t prove my claims.

There were also some posts in the other thread about Cloudflare and the MiTM thing (when we don’t even use them as a CDN and only as nameservers). Then the goal posts moved to [CF being able to change our DNS records](https://discuss.privacyguides.net/t/any-rebuttal-to-simplified-privacys-article-privacyguides-loves-spyware/17258/25), when that is not in our threat model. A lot of the posts you make have a authoritative tone ie: we should be doing this or that. Then there was the [HPKP suggestion](https://discuss.privacyguides.net/t/any-rebuttal-to-simplified-privacys-article-privacyguides-loves-spyware/17258/26) when it isn’t even a relevant security feature anymore.

Keep in mind as you’re flaired as RethinkDNS **people might be willing to give your opinions more weighting in a debate** , than some random forum user. The reason I did flair your account was because you do offer similar features to what NextDNS does with the RethinkDNS Android app and I think it’s important for people to know that. Also when people ask about RethinkDNS, you’re able to respond in some official capacity.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > That is what people are going to really care about when they use these services.
> 
> Depends on the people and the threat model. If they trust PrivacyGuides and see “no logs” (a _very_ strong guarantee), then they assume there’s absolutely _no logs_. I mean, words mean things. There’s a reason Mullvad goes to the extent they do with diskless servers, verified boot, no remote shell (which they’re working towards etc). To lump, Mullvad’s DNS as “no logs” in the same breath as other DNSes is really being disingenuous, imo.

Even with Mullvad it’s still a “promise”. It’s also worth noting that Mullvad’s main business is a VPN and their intention is to provide anonymity. They purposefully collect no data so they cannot be asked for it.

Most of these DNS providers don’t purport to offer anonymity, which I think is the key difference. The DNS page doesn’t suggest that using an encrypted DNS promises any kind of anonymity, only confidentiality with regard to queries. This is further made obvious on the “[Learn more about DNS](https://www.privacyguides.org/en/advanced/dns-overview/)” page which provides demonstrations of where internet usage can leak in other ways.

> [@ignoramous](#):
>
> The relevance is for PrivacyGuides to do due diligence on `dns0.eu` before recommending it as “no logs”. Jonah gets that and created [a github issue for it](https://github.com/privacyguides/privacyguides.org/issues/2484). So, it did have relevance.

If you see the further comment there, it will likely result in further clarification of what logging is. I think it’s fair to say in most people’s minds that is going to be association of queries with resolver IP address (PII - Personally Identifiable Information) and not some rough global metrics that don’t identify anyone.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > That could be a simple integer value assigned with an account. Technically still no logging if they’re not keeping the contents of the query ie which domain.
> 
> More assumptions, and just a few comments ago, you accuse me of speculation? My only point was, why not ask them instead?

The dns0 privacy policy is quite clear at least in my opinion:

> We do not log any Personally Identifiable Information (PII).
> 
> Our recursive DNS service, this website and other services we provide are fully compliant with the GDPR, and we welcome audits from reputable European entities.

While they don’t elaborate on what they do log, they are very careful to state they don’t log PII which has to be people’s IP addresses. A DNS query is quite a simple transaction. A query is made and an IP address is returned. There is no account based feature with dns0.eu so that simplified things somewhat.

---

## Post 68 by @ignoramous — 2024-04-05T23:12:49Z

> [@dngray](#):
>
> None of the encrypted DNS providers advertise themselves as being anonymous

ODoH and DNSCrypt v3 build it into the protocol. So yes, providers that bill for anonymity exist.

> [@dngray](#):
>
> The reason we don’t mention “Big Cloud” is because it doesn’t really impact the threat model.

It isn’t about “threats” but about privacy, strictly speaking. Though, I get your point.

> [@dngray](#):
>
> The reason for this is there can be a variety of sub processors

For any org that claims “GDPR compliance” must be listing down these subprocessors, no? I get that PrivacyGuides isn’t a GDPR enforcer on behalf of the EU, but then again, PrivacyGuides is also recommending something that in its own eyes has gaps in its own privacy policy and potential misleading claims about “GDPR”?

> [@dngray](#):
>
> That being said we are attempting to encourage NextDNS to provide a little more detail in that regard.

The words you use: “encourage” “little more detail” stand in stark contrast to how I’ve seen PrivacyGuides operate when making other recommendations. I digress.

> [@dngray](#):
>
> Then the goal posts moved to [CF being able to change our DNS records](https://discuss.privacyguides.net/t/any-rebuttal-to-simplified-privacys-article-privacyguides-loves-spyware/17258/25),

Please stop attacking me. It can’t be this hard to be nice for once?

> [@dngray](#):
>
> Then there was the [HPKP suggestion](https://discuss.privacyguides.net/t/any-rebuttal-to-simplified-privacys-article-privacyguides-loves-spyware/17258/26) when it isn’t even a relevant security feature anymore.

I wasn’t aware Google was backing down from HPKP as their OS (Android) and its cert-pinning mechanism remains a credible deterrence against rouge CAs (even if cert-pinning has the same problems or worse problems than HPKP).

> [@dngray](#):
>
> A lot of the posts you make have a authoritative tone ie: we should be doing this or that.

Not my style. Will you please quote my exact words so I may know where I demanded anything from anyone here?

> [@dngray](#):
>
> The reason I did flair your account was because you do offer similar features to what NextDNS does

No, we don’t. We’re Android-only. The DNS server “exists” for anti-censorship purposes (quite a few anti-censorship projects use RDNS as one of the default DNS resolvers) and has blocklists but the similarities with NextDNS stop there.

> [@dngray](#):
>
> people might be willing to give your opinions more weighting in a debate

Is that why you keep insulting me so people wouldn’t? That explains a lot. /s

> [@dngray](#):
>
> Most of these DNS providers don’t purport to offer anonymity

Fair.

> [@dngray](#):
>
> I think it’s fair to say in most people’s minds that is going to be association of queries with resolver IP address

Client IP needn’t be the only PII in a DNS request or even DNS query. But: I get your point.

> [@dngray](#):
>
> A DNS query is quite a simple transaction

Depends on the query.

> [@dngray](#):
>
> The dns0 privacy policy is quite clear at least in my opinion:

My point was: for a system with 100+ servers world-wide, I don’t think abuse prevention is merely a single integer somewhere. Now, if I point out I’ve built services running on more than 100K servers, you’ll pile up on me, so I’ll leave folks to their bubble where a single integer magically solves problems relating to abuse, auditing, metering, and what not.

Ignorance is bliss (:

---

## Post 69 by @dngray — 2024-04-06T03:21:43Z

> [@ignoramous](#):
>
> ODoH and DNSCrypt v3 build it into the protocol. So yes, providers that bill for anonymity exist.

Neither of which are implemented in any OS resolver or browser to my knowledge. [RFC9230](https://datatracker.ietf.org/doc/html/rfc9230) was marked as experimental in June 2022. DNSCrypt v3 is still [a draft](https://datatracker.ietf.org/doc/draft-denis-dprive-dnscrypt/) in early stages.

> [@ignoramous](#):
>
> For any org that claims “GDPR compliance” must be listing down these subprocessors, no?

[Apparently not](https://libreddit.bus-hit.me/r/gdpr/comments/eodz1c/does_gdpr_requires_that_companies_publish/) , the provider just needs to retain a list of them. Though on this I am no GDPR expert. It also seems it depends on the complexity of the product. @ph00lt0 would be able to give a better answer I am sure.

Damn reddit sucks, blocking all VPNs now. [archive.org](https://web.archive.org/web/20240406032816/https://old.reddit.com/r/gdpr/comments/eodz1c/does_gdpr_requires_that_companies_publish/) and [archive.today](https://archive.is/auZP5) links.

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/dngray/48/21_2.png) dngray:
> 
> > That being said we are attempting to encourage NextDNS to provide a little more detail in that regard.
> 
> The words you use: “encourage” “little more detail” stand in stark contrast to how I’ve seen PrivacyGuides operate when making other recommendations. I digress.

I sent them an email and made the suggestion. There isn’t much more I can do.

> [@ignoramous](#):
>
> Is that why you keep insulting me so people wouldn’t? That explains a lot. /s

Calm down i haven’t insulted you. I just pointed a few things out from how it looks.

> [@ignoramous](#):
>
> My point was: for a system with 100+ servers world-wide, I don’t think abuse prevention is merely a single integer somewhere. Now, if I point out I’ve built services running on more than 100K servers, you’ll pile up on me, so I’ll leave folks to their bubble where a single integer magically solves problems relating to abuse, auditing, metering, and what not.

No, you would be in a position though to suggest what specific _types of data_ would not be a simple counter however. That way you’re presenting us with a fact to convince us of your position.

---

## Post 71 by @ignoramous — 2024-04-06T15:12:25Z

> [@dngray](#):
>
> Neither of which are implemented in any OS resolver or browser to my knowledge. [RFC9230](https://datatracker.ietf.org/doc/html/rfc9230) was marked as experimental in June 2022. DNSCrypt v3 is still [a draft](https://datatracker.ietf.org/doc/draft-denis-dprive-dnscrypt/) in early stages.

Is the criteria to list some protocol on PrivacyGuides that it has to be a _standard_? News to me. Should clarify that somewhere I suppose.

- The “Tor” protocol isn’t implemented by any mainstream “OS”. Recommended or not?
- The official clients for ODoH and DNSCrypt are cross-platform (including installable on open-firmware Routers). Not enough?

From what I know, Apple uses ODoH for its _iCloud Relay_. That’s potentially millions of users. While Cloudflare runs ODoH across its network (potentially 10s of 1000s of servers).

> [@dngray](#):
>
> There isn’t much more I can do.

Almost as if no one moderates what goes on and what doesn’t on `privacyguides.org` (:

> [@dngray](#):
>
> Calm down i haven’t insulted you.

Apologize or don’t but at least don’t question my intelligence.

Also: Waiting for you to quote me on where as some dictator I demanded things from moderators here.

> [@dngray](#):
>
> No, you would be in a position though to suggest what specific _types of data_ would not be a simple counter however.

Respectfully, I didn’t build this magical system that can prevent abuse, audit, account for users across 100+ servers with a single integer. Whoever built it, it behooves us to ask them (and not assume) if indeed our collective hallucination is seeped in reality.

---

## Post 72 by @dngray — 2024-04-06T15:39:43Z

> [@ignoramous](#):
>
> - The “Tor” protocol isn’t implemented by any mainstream “OS”. Recommended or not?

It is not, but it does more than encrypt your DNS queries.

> [@ignoramous](#):
>
> - The official clients for ODoH and DNSCrypt are cross-platform (including installable on open-firmware Routers). Not enough?

They are, but you have to install them, still. Without other the data being protected there will still be leaks obviously as it only protects your DNS resolution. Which means if you’re intending on a anonymous solution, by itself it isn’t very anonymous.

> [@ignoramous](#):
>
> Apple uses ODoH for its _iCloud Relay_

iCloud Relay does more than just throw [ODoH at the problem](https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overview_Dec2021.pdf), it actually has connection proxying too.

> [@ignoramous](#):
>
> Apologize or don’t but at least don’t question my intelligence.

Arrogant [much](https://en.wikipedia.org/wiki/Wikipedia:Pearl-clutching)? :clown_face:

Anyway this topic has been derailed, so I’m just going to lock it now. Will post update when NextDNS replies, or if they don’t.

---

## Post 73 by @dngray — 2024-04-06T15:56:34Z


