BolehVPN Support
Sales Queries => Product Enquiries => Topic started by: Indingo on May 06, 2014, 05:23:37 AM
-
I have noticed over the last few days that BolehVPN's servers hosted in the Luxembourg region have had their DNS servers changed to Google DNS. Normally this would not be a concern as Google is a good DNS company, but their blatant logging policy's which come with all their services should heed warning against using Google DNS as the DNS for a VPN services servers. I'm not sure if the changes were implemented by BolehVPN yourselves or if their server farms made the change but I thought I would bring it up anyway. I also noticed a reduced speed in DNS lookup since the servers have been changed over what they were before, which is also not a good thing.
Could I get any information on why the changes were made and if you are going to change them back? It poses a security risk due to DNS lookup/ JAVA/FLASH exploits and the way Google does GEO resolving. In simple, Youtube/Google Services can figure out who users are due to browser security holes and DNS lookup through their servers and match the browser fingerprints to the DNS lookup.
-
We changed over to Google DNS as the privacy foundation DNS goes offline sometimes. We chose Google DNS because it provides better speed and reliability compared to OpenDNS, and also because Google DNS has a better privacy policy than OpenDNS. You can compare them here, https://developers.google.com/speed/public-dns/privacy (https://developers.google.com/speed/public-dns/privacy) http://www.opendns.com/privacy-policy/ (http://www.opendns.com/privacy-policy/)
A DNS query is just a DNS query, the browser security holes and fingerprinting are done at the website level such as www.whatismyipaddress.com (http://www.whatismyipaddress.com). DNS query will only show the IP who requested DNS, which is our VPN server.
However, cookies in your browser may give away your IP, which is why we always recommend clearing the cache, cookies, and using an anonymous browsing session to make sure there's no tracking.
-
There are so many reasons why using Google DNS is a privacy risk which is insane for a VPN company. I agree OpenDNS is bad as well. I would strongly urge you to find another DNS provider or you could do what so many other VPN services do and host your own DNS server for your clients, mullvad being one of these companies. I won't use servers connected to Google DNS and its a shame so many other users will without knowing the privacy risks. Google has been well known in the past and through experimentation to use Browser Geo-Location and DNS queries/fingerprints to actually match users who use VPN's. I was part of a whole discussion trying to figure out why someone who was using a VPN kept having their real location shown in GMAIL. We eventually found out it was because GoogleDNS servers were being matched on GMAIL with browser fingerprinting bypassing the VPN to discover the identity of the user.
Please can you guys look into changing this? I also notice you use Google DNS on your Canadian servers. I understand you do it for convenience but its really not in the best interests for your customers.
Thanks
A DNS query is just a DNS query,
Come on now, I know you know better then that Chris.
-
Sure we will look into this.
If you're using Gmail and concerned about privacy...Did you confirm that as long as Google's DNS servers were used (and not from a DNS leak) the Gmail would report your true location? Or were there other things such as cookies or profile info? Would be interested if you could share such results. It's boggling to think why Google would go to such extents to match fingerprints just from their DNS. Sounds like something else was leaking
Was the browser in Incognito mode?
-
Btw hosting your own DNS server is not so simple. It becomes a constant battle to maintain it against vulnerabilities which pop up all the time. Or if someone somehow breaks into our DNS server...it becomes a single failure point and we frankly don't have the resources to continue performing security audits in a timely manner as opposed to a large DNS provider. It's all fine and dandy to say "Yes let's host our own DNS server" and to do that is easy but do they really really check how vulnerable their DNS is? DNS poisoning is not a trivial risk to mitigate.
As you can see even the Privacy Foundation's own DNS servers have lagged behind and gone down in certain instances.
-
We also note that it's been recommended that we use the ISP's own DNS servers which we feel is also insecure since not all ISPs are upfront about their policies. Same can be said about Google I suppose but at least they have a clear and unambiguous privacy policy.
Would be interested to hear what DNS servers you have in mind. Looking at OpenNIc
-
We have decided to go with OpenNIC servers and Privacy Foundation and just keep them updated. This may mean less reliability but better privacy.
-
We have decided to go with OpenNIC servers and Privacy Foundation and just keep them updated. This may mean less reliability but better privacy.
Thanks Reuben,
That's good to hear, I'm sure other members will be glad that your using OpenNIC/PrivacyFoundation servers now despite the slightly less reliability. I understand that some people just use a VPN for Netflix/Iplayer but at the core it should still be focused on privacy as a main-stay for its consumers. I appreciate you looking into the issue for me, its one of the reasons I love you guys, we have a problem and you fix it for us, your great like that.
I am not sure about google, but about a year and a half ago we were locating ourselves in GMAIL and some other Google services after we locked our systems down for testing, we went through heavy testing and eventually found that by changing our DNS server the location look-up failed. We never could find a clear reason why this happened or what caused it, only knowing that a DNS change fixed it. We came to the conclusion somehow that there was some DNS/Browser fingerprinting going on which stored your "Real" location on Gmail's servers and when connecting with a VPN checked your browser and found out they were the same and displayed your previous country/IP so Gmail was in the correct language. I don't know why they do this, they just seem to do so, which is why i brought the issue up as a privacy concern.
I personally recommend GermanPrivacyFoundation/SwissPrivacyFoundation DNS servers myself. I believe they have the best track record.
Thanks again guys, I appreciate your help looking into the matter ;)
-
No problem, the nightmare begins for us :P Some of Germany Privacy Foundation's DNS servers are not active anymore. OpenNIC's Canada servers are also totally down Grrrr
-
No problem, the nightmare begins for us :P Some of Germany Privacy Foundation's DNS servers are not active anymore. OpenNIC's Canada servers are also totally down Grrrr
If you can't use the German Privacy Foundation, there is always their Swiss Privacy Foundation. Both of these should be fine for most of Europe, only needing to find an OpenNIC solution in the Asia's and North America/Canada. I thank you for your hard work, it pays off in the end. I am the most obsessive compulsive VPN user in existence and I stick with you guys because you show us you care, which is important and I would not trade it for a VPN company all the 1GB/s servers in the world.
Peace guys, thanks again for all your hard work. Hopefully everything will go well and fit into place nicely! :P
-
Quick update: Lux servers should have been off Google DNS since this morning.
-
Quick update: Lux servers should have been off Google DNS since this morning.
Yep, I am getting " ns3.ezdns.it" which is an OpenNIC DNS server I believe.
Thanks again.
-
Back to google dns again?
Lux server xxx.xxx.176.3:
IP Hostname ISP Country
74.125.73.17 none Google United States
74.125.73.19 none Google United States
74.125.73.20 none Google United States
74.125.73.16 none Google United States
74.125.73.18 none Google United States
Same on new swiss server :(
-
Back to google dns again?
Lux server xxx.xxx.176.3:
IP Hostname ISP Country
74.125.73.17 none Google United States
74.125.73.19 none Google United States
74.125.73.20 none Google United States
74.125.73.16 none Google United States
74.125.73.18 none Google United States
Same on new swiss server :(
Yeah, I noticed and posted about that. I am sure they are just busy with the IPT thing. If you want to use Lux without Google DNS you can make a copy of the Luxembourg config, You then go to it and remove everything between # Server List & remote-random and just leave the server named #New lux , as this one does not have Google dns on it, thankfully. Just save it and on next launch it should show up, I recommend naming it differently so your normal lux config shows up.
-
Thanks Indigo.
Im using the BRLU01 (LUX) now
IP Hostname ISP Country
62.141.38.230 none myLoc managed IT AG Germany
Reuben, Chris, will be you be changing the USA Google DNS soon on the new swiss and some of the lux servers?
-
Hi there,
We are weighing the pros and cons of each DNS. While they may have a good case privacy and location wise, OpenNIC has been less than reliable in our experience.
-
Thanks Indigo.
Im using the BRLU01 (LUX) now
IP Hostname ISP Country
62.141.38.230 none myLoc managed IT AG Germany
Reuben, Chris, will be you be changing the USA Google DNS soon on the new swiss and some of the lux servers?
Alright, cool. that DNS is run by OpenNIC and has logging disabled. Glad you got the config fixed, I hope the DNS gets fixed on these servers, as there is no real reason to not use non-logging OpenNIC/GermanPrivacy/SwissPrivacy foundation DNS servers over the ones that good provides.
-
Hi there,
We are weighing the pros and cons of each DNS. While they may have a good case privacy and location wise, OpenNIC has been less than reliable in our experience.
Then why not use Swiss/German Privacy foundation servers? When I first brought the issue up you said it was because of server downtime. I was playing around and for me the up-time seems to be at a good 99%+, If you really wanted to you could use one of each DNS servers, but really you don't need to, they have never failed on me or been down before, I think they are more then adequate, and the privacy value is much greater then with Google or OpenDNS. Its one of the reasons I asked for a "Input DNS" box in the new version of the client, so if people wanted to use their own DNS server, they can.
(Or maybe just use the Default DNS for the OpenVPN server we are connecting on, which most other VPN companies do, and BolehVPN did before changing it for some reason)
Just to give a clear explanation to why Google is a bad DNS provider for a VPN service.
(Privacy
It is stated that for the purposes of performance and security, only the querying IP address, which is deleted after 24 hours, ISP, and location information (kept permanently) are stored on the servers.[15][16][17]
According to Google's privacy policy, "We [Google] may combine personal information from one service with information, including personal information, from other Google services". While there is no mention of the DNS service in the main policy—the privacy page of the DNS service states that information is not "correlated or combined" with "personally identifiable information"—the question remains whether a generic but persistent tracking identity is considered "personally identifiable information".[18])
In bold is the issue, using the exploit I have explained before they can correlate DNS requests to email accounts, YouTube and pretty much anywhere on the web with a Google trackers or analytic. Basically say goodbye to the privacy afforded by a VPN.
-
Google is like antonym of privacy. They are always in mood to store every bit of information about every living human being on this planet. I am not that IT expert but one thing I have learned over years while using internet is google is bad for privacy and google and VPN(true) service provider have exactly opposite intentions. If alternatives are available then google should be avoided. Having said that I'll like to add I have complete trust on boleh people and I am sure they will take care of our privacy and will do what is best for boleh users.
Thanks to indingo for bringing this issue up. Truly appreciate all those users who are creating awareness and not have taken things for granted.
-
When we were testing out Swiss/Germany privacy foundation servers, we ran into periods of time where they simply didn't respond or were extremely slow. As this was on our gigabit servers, quite a few of our users were affected. Thus the move away.
We'll give the Swiss privacy foundation one last try on our new Swiss servers and see how this goes.
-
When we were testing out Swiss/Germany privacy foundation servers, we ran into periods of time where they simply didn't respond or were extremely slow. As this was on our gigabit servers, quite a few of our users were affected. Thus the move away.
We'll give the Swiss privacy foundation one last try on our new Swiss servers and see how this goes.
That is very strange, in the past I had used them on a nearly 24/7 basis and never had issues. If it does not work out, again maybe the solution would be to manage your own DNS. I am sure there is a public list without modifications that can be trusted, I am not exactly sure because I have never run a DNS myself with OpenNIC but don't they have their own list everyone uses? If so maybe you can run your own DNS using OpenNIC's update-able list and you won't have to worry about security or downtime because you will be running it yourself. I can however say with absolute certainty that the following DNS servers are no good for privacy. (PS: If you do make your own DNS I would recommend Canada & Switzerland as your two DNS locations, as that will have the best coverage and those countries have good DNS/data laws)
Google DNS
OpenDNS
Symantec/Any Security Vendor DNS. "including C.O.M.O.D.O DNS."
I only really trust Swiss/German Privacy foundation DNS servers, and OpenNIC.
& I would avoid Chaos Computer Club, I don't trust them.
Thanks to indingo for bringing this issue up. Truly appreciate all those users who are creating awareness and not have taken things for granted.
Thanks Robustheart.
I just want to help in anyway I can to improve BolehVPN and help out our community, I will always bring up any security or related issues when and if I find them. I just hope the BolehVPN team don't get too annoyed by my constant pestering haha. ;D