Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm Malaysian. They even messed up DoH for the popular DNS providers like Google and Cloudflare. I think they are routing 1.1.1.1 to their own DNS, so when you try to connect to DoH you get SSL_ERR_BAD_CERT_DOMAIN. The only option it seems is to VPN or play the cat and mouse game now to find a DNS that hasn't been rerouted yet


You might get some joy from using Portmaster (windows OS) and|or the Foundation for Applied Privacy

https://wiki.safing.io/en/Portmaster/App/DNSConfiguration

https://applied-privacy.net/services/dns/

There are non standard transports for DNS via non standard providers | DNS proxies - this tool and that foundation are a start.


Are they rerouting traffic to port 443 and 853?


Where are you? My DNS seems to work perfectly fine right now in Penang (with VPN off).

It’s sad that democracies are copying the playbook of China. Will definitely be using v2ray/X-ray while here


> It’s sad that democracies are copying...

"Democracy" is a bit of a red herring here. Democracy doesn't mean the government can't censor you or restrict what information or media you can consume. Democracy just means that the voters have consented to whatever legal framework is in place, and to whatever their leaders want to do within that framework.

And that's the thing: in many democracies around the world, if there was a referendum on the law to blocking copyright infringement, online gambling, or pornography at the ISP level, I think many would pass that law.

(Certainly there are "democracies" out there that only pay lip service to the concept, and have fixed elections and repression of dissent or opposition. I'm not talking about those.)


Sarawak here (on unifi). My network uses self setup multi DNS path with enforcing encryption so no biggie but I tried some nonetheless. Quad 8, 1 are fine atm, while Quad 9 traceroute returned !X.


can you share a little on your setup?


router DNS redir to pihole(Not the shitey FiberHome) -> pihole to internal(bind9 plain local to Adguard Proxy DoQ) -> self hosted tunneled whitelist DNS quicdoq DoQ, Adguard DNS DoQ (upstream quad 101, others.)


I have a similar setup, it will not be immune if they start implementing in your area. They were rolling out by areas before they reversed course. Your upstream will stop working unless you proxy it through another network


It is proxied towards a machine outside of Malaysia (A machine I've setup elsewhere). So yeah.


Even now that they have reversed it I'm now determined to find a way to do this the cheapest way possible


Yeah, given the gomen track record, I won't be lowering the defenses anytime soon. Good luck to you on your path to it!


I'm in PJ. It seems that they have reversed the move after wide media coverage, claiming that it there has been a "confusion"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: