Enable This Setting on EVERY Web Browser

Поделиться
HTML-код
  • Опубликовано: 5 авг 2024
  • Did you know about this feature?
    ⇒ Become a channel member for exclusive features! Check it out here: ruclips.net/user/ThioJoejoin
    Links:
    • DNS Test 1 ⇨ www.cloudflare.com/ssl/encryp...
    • DNS Test 2 ⇨ 1.1.1.1/help
    • Configuration Profiles: github.com/paulmillr/encrypte...
    ▼ Time Stamps: ▼
    0:00 - Intro
    2:59 - Before Getting Started
    3:44 - Enabling on Web Browsers
    4:56 - On Android
    6:32 - On iPhone & iPad
    9:35 - On Mac
    10:35 - On Windows
    11:13 - What is ESNI & ECH?
    ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
    Merch ⇨ teespring.com/stores/thiojoe
    ⇨ / thiojoe
    ⇨ / thiojoe
    ⇨ / thiojoetv
    My Gear & Equipment ⇨ kit.co/ThioJoe
    ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
  • НаукаНаука

Комментарии • 609

  • @KiickrOcksz
    @KiickrOcksz 3 года назад +306

    He's so powerful. He can slide buttons with his fingers no mouse required.

    • @hridinsbiju9023
      @hridinsbiju9023 3 года назад +3

      Haha

    • @larsthestorf5630
      @larsthestorf5630 3 года назад +15

      Very impressive technology. I believe it is called touchscreen

    • @KiickrOcksz
      @KiickrOcksz 3 года назад +7

      @@larsthestorf5630 There's no screen behind him. He literally pulled the image out of the PC to slide the button and put it back. Catch up.

    • @Tahazif_TheCool22
      @Tahazif_TheCool22 3 года назад +1

      @@KiickrOcksz yes.

    • @darrelbryant8632
      @darrelbryant8632 3 года назад

      He's had wizard training.

  • @slindebe
    @slindebe 3 года назад +39

    A few comments:
    1. DNS lookups should preferably be done by the network stack in the operating system, not by the application, such as a browser. It might cause that different applications on your computer to connect to different IPs for the same site due to different IPs being returned by the DNS used by the browser and the DNS used by the OS.
    2. So your ISP can't just look at your secure DNS requests to see what sites you're connecting to, but instead, Cloudflare gets to see all DNS your requests, so who to trust?
    3. Some companies/organizations etc, use special domains and/or names for internal resources that are not resolvable by an external DNS provider like Cloudflare, so you might no be able to access them.
    Cloudflare's main business is hosting sites and data for other companies, accessible with high performance and protection from DDoS attacks globally. Using dynamic DNS resolvers that map a name to different IP addresses based on network and system load, your location, location of data needed to serve your request, and so on, is an important part of that service.
    Might they have additional motives to see as many DNS requests as possible? Let's say Bank A is a Cloudflare customer, would they be willing to pay for data on DNS requests for Bank B from a certain region for example? Of course, they would!
    I'm not saying that Cloudflare does it today, but we all know that there is immense value in data regarding customer behavior.

    • @jakobfel2
      @jakobfel2 2 года назад +2

      I'd say running your DNS requests through Cloudflare, a company with a pretty decent track record in regards to privacy, is a lot smarter than running it through your ISP's DNS servers, especially since most major ISPs are known to be doing anything they can to spy on their users and then sell their data. Is it a perfect solution? No, especially not if Cloudflare ever decides to go crooked, but like I said, it's better to go through a service run by a company with a good track record than go through a service run by an ISP that is almost certainly trying to sell your data.

    • @Rundik
      @Rundik 2 года назад +2

      Cloudflare can already read all the data unencrypted for all its customers. And it's quite a big prercentage of websites who are using cloudflare. So dns is not that big of a deal

  • @smft9147
    @smft9147 3 года назад +238

    who else misses the poll feature lol, I remember all his videos had a stupid poll at the beginning...

    • @GoatStormChaser
      @GoatStormChaser 3 года назад +8

      Yeah i do

    • @flop-00
      @flop-00 3 года назад +21

      wait it was REMOVED? i thought ppl just hardly used it

    • @ThioJoe
      @ThioJoe  3 года назад +84

      Yea it's a shame

    • @yeppiidev
      @yeppiidev 3 года назад +8

      @@flop-00 it was removed a long time ago

    • @Househoppper
      @Househoppper 3 года назад +12

      I didn’t know they were removed, I just thought it was a mistake when people said “You can vote in the poll” and there is no poll

  • @TheGoldenBat
    @TheGoldenBat 3 года назад +4

    Thank you for splitting the spands of the video up to different chapters, this makes it allot easier.

  • @mikeeleren9816
    @mikeeleren9816 3 года назад +4

    been using private dns a year already, so far so good it also improves my connection

  • @maineglass8104
    @maineglass8104 3 года назад +8

    Very good cursory discussion on the why this information is important. The browser demonstrations that you provided were easy to follow. Love that this video was short and got to the point.

  • @wizdude
    @wizdude 3 года назад +35

    Reason number 3: some countries like Australia have “metadata logging laws” where your ISP logs headers of your traffic and thus knows which websites you are visiting when you make requests via standard unencrypted DNS. If the DNS lookup is encrypted then this makes it harder for a third party (government, law enforcement etc) to track your browsing activities.

    • @Tmm42s
      @Tmm42s 11 месяцев назад +1

      I run a small ISP, we don’t log headers of traffic if the customer has a public IP. Only ISPs using CGNAT where the end user has a private ip need their source, destination and port accessed logged

    • @svsilentpartner647
      @svsilentpartner647 7 месяцев назад +1

      Yes they won't see your DNS traffic but they will see the ip address of the website you connect to. So it's not really stopping them. Only way I see is to use tor or vps/vpn/proxy. They will see the connection but have no information about specific activities.

  • @shootingenthusiast8
    @shootingenthusiast8 3 года назад +2

    I love the way he tries to dumb things down so even I can understand them. It didn't work, but I still appreciate the effort.

  • @meowxgamingstuff
    @meowxgamingstuff 3 года назад +3

    Bro I am one of your old subscribers... I always liked each videos of yours. Always learnt something new! You are so easy to understand. Massive respect.

    • @meowxgamingstuff
      @meowxgamingstuff 3 года назад

      He didn't see my comment 💔

    • @R1ch4rd
      @R1ch4rd 3 года назад +1

      @@meowxgamingstuff He doesn't have to. Plus, he has stuff to do. Don't be offended.

  • @anshulhedau10
    @anshulhedau10 3 года назад +31

    Me: So many work to do.
    ThioJoe: *new video*.
    Me: watches video anyway 😁.

  • @Harvestersz
    @Harvestersz 3 года назад +68

    I do this the most secure method: I handwrite each DNS request, put it in an envelope, mail it, and wait for the reply.

    • @purpmint3116
      @purpmint3116 3 года назад +6

      Government can read your mail! Oh no!

    • @davidwallin7518
      @davidwallin7518 3 года назад +6

      That's a silly way - you should be using smoke signals. And they should be in encoded Klingon.

    • @acidangel111
      @acidangel111 3 года назад +5

      I use a track and field hamster team to courier those envelopes myself ..... those hamsters are a moving...!!!!

    • @white-bunny
      @white-bunny 3 года назад +2

      The ping must hit negative time then!

    • @SS-ec2tu
      @SS-ec2tu 3 года назад +2

      @@davidwallin7518 So many people know Klingon now, you have to encrypt it to be safe.

  • @AbdRahman-px7uq
    @AbdRahman-px7uq 3 года назад +4

    Thank you for the helpful information & tutorial!

  • @Pedro5antos_
    @Pedro5antos_ 3 года назад +1

    Great, great tips! I had never heard of it, thanks Joe

  • @wvcaver774
    @wvcaver774 3 года назад +31

    been doing DNS over TLS for a while at the router level

  • @linr3v730
    @linr3v730 3 года назад +15

    Thanks, bro.

  • @davidfreedman6039
    @davidfreedman6039 3 года назад +1

    thiojoe thank you for teaching us really good tips for windows! cant wait to see u get 3m subs!

  • @radaplay
    @radaplay 2 года назад +2

    Nice video Joe keep up the good job

  • @UpStreamCharlie
    @UpStreamCharlie 3 года назад +1

    Thank you very much for this video. I learned a lot today. It's a good thing I have a new Samsung. I followed your instruction for it. Thanks, ThioJoe.

  • @parinose6163
    @parinose6163 2 года назад +1

    Thx you for clarifying this cdn affair and others! You are right: "certainly, more knowledge than you are bargaining for..."

  • @Kaushtav14
    @Kaushtav14 3 года назад +2

    Nice vid. It was very helpful. Thanks 👍🏻👍🏻

  • @eftiprwtopapadakis9310
    @eftiprwtopapadakis9310 3 года назад +1

    Amazing channel! i have seen already your ssd failure video and this one and i can say that i am so benefited. Btw what about Linux machines?

  • @ksriharsha2911
    @ksriharsha2911 3 года назад +1

    The best youtube channel.....thanks joe for sharing valuable knowledge :)

  • @barradarcy
    @barradarcy 2 года назад +3

    Thank you, your videos are always so informative! Unfortunatly I came across this one too late as esni has been pulled from Firefox-esr and replaced with something else (which seems to be incomplete). There's now no protection for SNI....unless you know something I don't and I'm pretty sure you DO! 🙂

  • @vladislavkaras491
    @vladislavkaras491 2 года назад +1

    Pretty informative and usefull video.
    Thanks!

  • @Emily-gf3we
    @Emily-gf3we 3 года назад +2

    Thanks, Thio for this video it's really useful.

  • @Articulate99
    @Articulate99 Год назад +1

    Always interesting, thanks.

  • @lomarica
    @lomarica 3 года назад

    Thank you for the information!

  • @AnirudhAnil7
    @AnirudhAnil7 3 года назад +1

    Thanks, these are pretty useful

  • @alwinanilkumar2625
    @alwinanilkumar2625 3 года назад +1

    I just set my private dns in phone with cloudflare
    Love this video❤️

  • @Yadro767
    @Yadro767 3 года назад +1

    Great content as always.

  • @PrograError
    @PrograError 3 года назад +1

    seems to me if your router had already set to a version of the "DNSS", the handshake check gives false negative ( or if you have a another app like say a app manager app with a VPN, it also happens the same. disabling that VPN gives a postive)

  • @frzdytheconsumer8094
    @frzdytheconsumer8094 3 года назад +6

    Thanks Thio! I'm one step closer to getting my pc to *MAXIMUM* power.

    • @aleksanderblinn4492
      @aleksanderblinn4492 3 года назад

      Comodo Firewall with cruelsister settings
      Bitdefender AV
      O&O Shutup10

  • @AndiDarmika
    @AndiDarmika Год назад +2

    Super helpful, especially for iOS. thank you 😃

  • @StuckInVim
    @StuckInVim 3 года назад +3

    Really useful!

  • @ShookD
    @ShookD 7 месяцев назад

    Very informative, Thanks!

  • @stevecmk
    @stevecmk 3 года назад

    Thank you for the video!

  • @mrawesome7713
    @mrawesome7713 3 года назад

    Great vid Theo

  • @mygunplabuildbyrodnycp3730
    @mygunplabuildbyrodnycp3730 3 года назад +1

    thanks bro..more power to your channel

  • @Chanceux2
    @Chanceux2 3 года назад +48

    You deserve more views :(

  • @blob6371
    @blob6371 3 года назад

    Thanks so much for the info

  • @GoatStormChaser
    @GoatStormChaser 3 года назад

    Very nice video explained everything well

  • @SA77888
    @SA77888 Год назад +3

    I do this in Control Panel which gives a....'global effect' to this setting rather than effecting just one browser.
    It can also be changed in Settings under Network & Internet \ Ethernet - then click on Edit next to DNS Server assignment

    • @EvilMonkeyZombie
      @EvilMonkeyZombie 8 месяцев назад

      Is there any benefit to doing both? I have a private DNS setup on my network adapters.

  • @rondelarosa7985
    @rondelarosa7985 3 года назад

    Thank you, your vids help alot.

  • @joegee2815
    @joegee2815 3 года назад +1

    I just checked my firefox and it's already enabled. Nice.

  • @Blindleoblake66
    @Blindleoblake66 2 года назад

    Thank you Joe !

  • @defyiant
    @defyiant Год назад +1

    Thanks for this wanted cloudflare on my iPhone

  • @Enjurin
    @Enjurin 3 года назад

    Great video!

  • @FalB27
    @FalB27 3 года назад +6

    "Wu Tang Lan" killed me

  • @sparkleshyguy85
    @sparkleshyguy85 3 года назад +4

    Just a note to anyone doing this for iOS or iPadOS: You must do this in Safari, not in your preferred browser for the profile to be acknowledged by the system. Otherwise it’ll just downlload but won’t show up in Settings.

    • @eeevans
      @eeevans 3 года назад

      Also the Profiles setting doesn’t show until you have it downloaded in safari

  • @AndroidClima
    @AndroidClima 3 года назад +1

    Muchas gracias por el gran tutorial. Pero me quede en duda. Si es posible hacer una configuración del DNS del Router de la casa... podrías ayudarme con mi duda por favor...

  • @domg7124
    @domg7124 2 года назад +1

    Great channel, wish u had more mac stuff

  • @ntroprogaming3234
    @ntroprogaming3234 3 года назад

    man i like all ur videous thnks for these things

  • @R1ch4rd
    @R1ch4rd 3 года назад +40

    6:00
    There is actually another hostname for this, 'one.one.one.one', so you don't have to remember that long hostname.

    • @orang6521
      @orang6521 3 года назад +1

      ok lemme save this real quick

    • @derpyKitsu
      @derpyKitsu 3 года назад +1

      The long one kept giving me errors, but this one is actually working

    • @R1ch4rd
      @R1ch4rd 3 года назад +1

      @@derpyKitsu glad to help. 👍

    • @vivekd005
      @vivekd005 2 года назад

      Yeah same, one given in the video giving me error too. Yours is working but on the DNS test Page it is still showing Not Secured

  • @link1565V2
    @link1565V2 3 года назад +6

    I have AdGuard DNS configured directly on my router. Greatly increases my connection speeds by automatically blocking spammy ad URLs from loading at all on my network.

    • @hafuridotus
      @hafuridotus 2 года назад

      Just setup NextDNS on my router and it's been flawless, ended up paying the $20 yearly fee because I easily topped out at the 300,000 queries mark

  • @geekhomeworld4248
    @geekhomeworld4248 3 года назад +1

    What a fascinating video.

  • @furkan9549
    @furkan9549 3 года назад +26

    What is the difference between changing DNS from WI-FI setting and chancing from browser or system settings.

    • @R1ch4rd
      @R1ch4rd 3 года назад +28

      If you set DNS up on your router, all devices in the local network will use the same DNS.
      If you set DNS up on your browser, it will only use the DNS on your specific browser.
      If you set DNS up in the settings of your phone, it will use the DNS in all apps system-wide, but only and only on this particular phone.

  • @_SJ
    @_SJ 3 года назад +40

    Wow!! I'm so happy that I'm in this video. Thank you ThioJoe

  • @akash2364
    @akash2364 3 года назад +2

    Thanks bro

  • @starrie_eyed_girl7397
    @starrie_eyed_girl7397 3 года назад +6

    Good vid thanks for the info

    • @Ninjukken
      @Ninjukken 3 года назад +2

      the video came out 16 minutes ago? this dude gone in the future and commented fr 😂💯

    • @ThioJoe
      @ThioJoe  3 года назад +3

      They got secret illuminati access

    • @GrayLeaf
      @GrayLeaf 3 года назад

      @@ThioJoe 😂

  • @imamal74
    @imamal74 3 года назад

    Thx a lot for this vid!!!!

  • @SnowyRVulpix
    @SnowyRVulpix 3 года назад

    I wish I could upvote this more than once.

  • @rashidisw
    @rashidisw 3 года назад +1

    A system wide DoH/DoT for Windows OS are possible, if it would follow upon how DNSCrypt was implemented/deployed for client side.

  • @shmookins
    @shmookins 3 года назад +1

    I changed it like you mentioned but the test site still gives me a question mark for Secure DNS.

  • @prashantdeshpande5415
    @prashantdeshpande5415 3 года назад +1

    Very useful👍

  • @antonioterrell354
    @antonioterrell354 2 года назад +2

    Turned DoT on for cloudflare in my router which has the option (The router node of an Asus XT8 mesh system). Cloudflare's browsing check says everything is secure except for the "Secure SNI" as mentioned near the end of the video.
    From my understanding this should work fine as long as the web browsers of each client on my network specifically direct all DNS queries to the router.

    • @BillAnt
      @BillAnt 4 месяца назад

      SNI is not yet supported by many routers and servers, however as long as your DNS is secure you should be fine.

  • @i_am_blur
    @i_am_blur 3 года назад

    Did it. I trust you man. Thanks.

  • @louf7178
    @louf7178 3 года назад +2

    Very informative. Thank you !
    Edit: uh...yea, I got lost. Hackers may intercept where you're going by reading an unencrypted name - I don't think it will ever be secure; just very, very complex.

  • @reeshavroy0
    @reeshavroy0 3 года назад

    Thank You Sir. 💥💯

  • @_SJ
    @_SJ 3 года назад

    I was waiting for this video but I fell asleep 😞. It's 12:30am here in the Philippines

  • @dcypher5305
    @dcypher5305 3 года назад +3

    I’ve heard that people won’t use HTTPS for DNS due to the fact that it forces your browser to resolve to a big-scale DNS rather than more local ones

  • @Midori_Hoshi
    @Midori_Hoshi 3 года назад

    It was already enabled on my Firefox browser, but thanks for the heads up.

  • @cyangalaxy
    @cyangalaxy 3 года назад +2

    Do you know how this can be set up without losing access to local IP addresses (like Router Interface etc.)?

  • @yousef5137
    @yousef5137 3 года назад

    Whenever I see a thumbnail with a person putting there fingers on a button or switch. I remember, ThioJoe

  • @akash2364
    @akash2364 3 года назад +2

    Nice one

  • @antunklaic9943
    @antunklaic9943 3 года назад

    Thank u Man, u are Great.

  • @fred-youtube
    @fred-youtube 3 года назад +2

    Turn off privacy sandbox in chrome settings though so it doesnt send your (slightly anonymised but still gives them a good picture of what you do) browsing data to websites

  • @ArthurMotta
    @ArthurMotta 3 года назад

    Thanks!

  • @arkasingha6111
    @arkasingha6111 3 года назад

    Damn good video. Keep it up.

  • @codymr1974
    @codymr1974 3 года назад +1

    After running tests, I can't seem to get any of the DNS Over HTTPS profiles to work on MacOS Big Sur 11.4 after installing the profile in SYSTEM PREFS > PROFILES.
    Installation DNS Over HTTPS worked fine on iOS 14.6.

  • @Ploskkky
    @Ploskkky 3 года назад +6

    Do I need to encrypt SNI too? Currently it is not.
    EDIT: LOL you are already addressing it. Great.

  • @MetalKingdom666
    @MetalKingdom666 3 года назад

    Thanks Man .you amazing.

  • @jkbobful
    @jkbobful 3 года назад +2

    good video Quad9 is also another good one even better than Cloudflare when it comes down to security

  • @nothingiseverperfect
    @nothingiseverperfect 3 года назад +1

    Ahhh this video is so good thnx u

  • @ardentdfender4116
    @ardentdfender4116 3 года назад +9

    No pun at all, but of all the channels i watch across many sectors for flavor, education, fun, gaming etc there is pretty much just two that teaches me tech to be better at computer tech and keep learning new stuff i didn't even know. That's Linus and this channel. There is so much stuff to keep keeping up with there is just no way the average person can keep up with just Tech singularly. So cheers to Thio for helping us all to becoming at PC Tech/Tech. I had no damn idea about this browser setting. Thanks man!

    • @pax5072
      @pax5072 Год назад

      i bet you have to throw all this tech stuff in dustbin when ar and vr are the really and no buddy use keyboard or touch screen in daily use.

  • @photonboy999
    @photonboy999 2 года назад +1

    *Windows 11 and DHCP*
    I tried to force DNS on all the time but when I try to change to MANUAL in the settings the other options are greyed out and when I SAVE the manual setting it just reverts back to AUTO. Just messing around, but I suspect this is a work in progress and possibly not something end users are allowed to mess with quite yet. I did enable it for Chrome as per the video instructions.

  • @samtees
    @samtees 3 года назад +2

    For me this works on firefox but for some reason the setting is greyed out in chrome and it won't let me turn it on

  • @sundayismyname
    @sundayismyname 3 года назад +1

    Is this similar to using a DNS on the router level? I have an Asus AC88U. There is a WAN DNS Setting under the Advanced Settings - WAN. Would this work the same without configuring individual devices?

  • @light-gray
    @light-gray 3 года назад +3

    Thio joe is the best youtuber ever

    • @ThioJoe
      @ThioJoe  3 года назад +2

      I am one of the youtubers of all time

  • @ctx_12
    @ctx_12 3 года назад +1

    Would I need to do this if I already have Cloudfare set at the router level (to point to their DNS) ?

  • @bobjohnson5934
    @bobjohnson5934 3 года назад +1

    To Enable DNS over HTTPS (DoH) on the Opera Browser,
    Click on the Opera icon to open the browser's menu,
    Pick Settings from the menu,
    In Settings, click on Advanced
    On the right, scroll down to the System section.
    Turn on the option Use DNS-over-HTTPS instead of the system's DNS settings.

  • @jsantiago1145
    @jsantiago1145 3 года назад +1

    Great stuff man,
    The only problem is for some reason in Google Chrome on desktop once I close out of Google Chrome, DNS is no longer secure and so I have to fix the setting every time I open Chrome, how do you save this browser setting?

  • @radiorexandy
    @radiorexandy 3 года назад +11

    Hey ThioJoe: I got the cloud flare dns to work on my Android but am still vulnerable to SNI hacking?

    • @cerealkiller69420
      @cerealkiller69420 3 года назад +1

      Yes. Ech is still in draft stage and no software supports it. Even Firefox's implementation is currently broken afaik. Your best bet is to grab an older version of firefox for Android with working esni and use that for web browsing

  • @cammy85
    @cammy85 3 года назад +3

    One thing to note: it won't work in Edge if you use tools like O&OShutup10 to configure Windows 10 privacy. I just enabled the DNS in my router instead.
    2023 edit: For those who don't already know, Windows 11 sets DNS over TLS separately from Edge so you can just enable it there. In most cases, just add the DNS numbers, choose "On (automatic template)", and you're good to go.

  • @JB-wn8mo
    @JB-wn8mo 3 года назад

    Should I be using "Public Network" or "Private Network"? I have a modem from my IPS & using Windows.

  • @dhiyaneshwarchess12Pro
    @dhiyaneshwarchess12Pro 3 года назад

    Hlo bro! You are my hero of computer science🖥️💻😊😊😇😉

  • @OlettaLiano
    @OlettaLiano 3 года назад +1

    One thing I like about Firefox. This setting is already enabled.

  • @aniketdive7069
    @aniketdive7069 3 года назад +2

    Owesome bro

  • @6a_abrahamvincentsusantoba665
    @6a_abrahamvincentsusantoba665 3 года назад +1

    I can't see it on chrome, I went to the Privacy and Security section but when I scrolled down to the Advance section, there's no option for secure DNS, only Manage security keys, Manage certificates, and Google Advanced Protection Program.
    Note = I'm using Chrome Version 91.0.4472.77 (Official Build) (64-bit) on Linux Mint if that help's.

  • @HarryWexler
    @HarryWexler 3 года назад

    Worked for me on mobile. Use to just put Google to redirect it but will try 1dotcloud. My work computer was grayed out, even tho I was logged in chrome with my personal account the network is "managed"

  • @helionexus6090
    @helionexus6090 3 года назад +1

    @5:40 For android; Are you saying to choose 'automatic' then? but if 'automatic' can't be chosen then to choose 'private DNS provider name' instead? You just haven't specifically specified to choose automatic so I'm asking.