Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • What does everybody here think about Daniel Berntsson, founder and co-owner of Mullvad, personally donating 5 million Swedish krona to the populist Örebro party, criticized for its stances on race & immigration?

    I'm not trying to start an unhealthy discussion about this topic, genuinely curious about your opinion on the matter.

  • He is in his full right to support whatever party he wants?

    Those parties exists for a reason, a response to certain pressures. Nothing happens in isolation. If you zoom out a bit and if you can for a second try to empathize with both sides, you will often find that both sides of an issue is correct, reasonable & rational from their own perspectives. It is often more an emotional response than one of pure survival.

    The more you force things on people or suppress them, the more they will resist & push back. The rise of the far-right is not random or just pure evil manifesting out of thin air. It is like a acute inflammatory/immune system response. Obviously it can be exploited by bad actors to further inflame/divide & accelerate certain agendas. Often times extremism takes hold when certain justices are denied (which is in fact evil).

    Life is best if you assume the guy on the other side (90% of a group) is just a bro trying to survive & have no real bad intent towards you, they don't know you or have been in your shoes, and the other way around too. Thus it is very important to become non-reactive, become observant who is trying to stoke the flames, who benefits from the chaos and so on.

  • I have no insights in Swedish politics. His actions could be really bad, or mean nothing at all. Without proper context, it’s hard to say.
  • I stopped paying for or using Mullvad because of that. I have no intention of funding more nazis, when I can help it
    by mvid
  • Irrespective of political affiliations, I felt that Mullvad addressed the outrage in a mature and non culture war manner. Because of how they handled the situation, I have a lot more respect for the company.

    It's great that they didn't try to cancel the guy or get seduced into driving a wedge into their team. It is great they chose their principle over pleasing the crowd in such a transparent way.

    I have been a customer for many years. I once even used the cash payment option out of curiosity.

    Here is their statement:

    https://mullvad.net/en/blog/donation-controversy

    They even linked his (Swedish language) private blog on which he wrote on the issue:

    https://dberntsson.info/

    by fwn
  • The old heads out there might remember a time when, rather than everyone using one service provider (ex. for Linux binaries/source), we all mutually agreed to use independently run mirrors closer to us. We sort of had to because of bandwidth and latency limits. But it meant that there were a thousand different people providing the same service. Impossible to censor everyone, everyone shares the load, too many places to hack if you wanted to massively compromise, and the users won.

    DNS is harder to do that way because it's hard to have limits on DNS. Perhaps DNS could be adapted with QUIC, to allow fast, encrypted DNS that's easier to rate-limit, and then it'd be easier for average people to run public mirrors with limits.

  • These was one of the fastest DoH services for pipelined queries over single TCP connection

    IME, it was much faster than Quad9 for this purpose

    First Mullvad shuts down its Google search proxy

    Now its DoH service

    What's next

  • Also had a ChatGPT alternative with less surveillance

    Discontinued

  • NB. I don't use Windows and I don't use "Private DNS". I'm referring to using HTTP/1.1 pipelining^1 with a TCP client plus TLS forward proxy or HTTP/2 with an ldns-based client to fetch DNS data in bulk, outside the browser, from the command line. I got some incredible speeds from Mullvad

    1. Not every service still supports 1.1, RFC recommends H2

  • I've found DoH was pretty unusable for me on Windows because the TCP connection doesn't seem to stay open between queries. No idea if it's a software or network issue, but big unpredictable delays on DNS queries broke all kinds of weird unexpected stuff.
  • They lost me as a customer when they got rid of port forwarding, which is nice to have on the high seas
  • Does anyone know of good alternatives that also block ads? Seems Quad9 doesn't.
  • I'm using numa(https://github.com/razvandimescu/numa) for ad filtering and odoh mode for privacy (shameless plug)
    by rdme
  • Since this seems to be the thread for public DoH providers, this article is probably worth mentioning (it can sort by DoH, DoT, DoQ, etc support).

    https://en.wikipedia.org/wiki/Public_recursive_name_server

  • Several (European) alternatives are available: https://eualternative.eu/categories/public-dns/
  • https://github.com/AdguardTeam/AdGuardHome/releases

    Trivial to self-host, and gives you full control of blocking.

  • nextdns.io might be an option

    https://adguard-dns.io/kb/general/dns-providers/ have a list of options that some of them have ad blocker

  • I'm not saying this is a canary, but I think it should be treated as such.
  • Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics.

    First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and with the users of the service - this is exactly how an ideal transfer should go, at least from our perspective.

    I'll try to make some short summaries of some of the points here, and a reply on each.

    "You should just run your own DNS server - it's easy." - Yes, we agree that for a small company or home running your own recursive resolver is a reasonable solution. You probably won't get the threat mitigation depth of service that Quad9 offers, but you may not want that. Privacy also suffers a bit, since it's still the same IP address (your home "public" address) sending queries to authoritative servers, probably unencrypted. A good middle compromise is to run PiHole or AdGuard software, and forward your queries to Quad9 via an encrypted connection. (see below) This mixes your queries in with a large number of other users, and gets the potential improvements of having a much larger active cache nearby which will have "hot" answers. Running a home resolver for yourself or even a few dozen (or even a few hundred) people is not difficult. But with all services, things change with scale. As the query volume and number of locations grow, you soon find yourself hitting all possible exception cases, instantly. Many millions of requests a second requires a lot of time, expertise, and money to ensure nearly 100% uptime. We are admittedly quite a small group - less than 10 full time - but even that is under-staffed for supporting more than 100 million daily users. We do quite a bit with a very small resource set, and I doubt it could be done less expensively with the same robustness for the same scale. Again, we appreciate Mullvad's sponsorship to help keep this expanding at our normal weekly growth rate of around 2%.

    "I want ad blocking, and Quad9 doesn't do that" - Correct, Quad9 does not do ad blocking at this time. There are good solutions like PiHole or AdGuard extensions that provide this functionality, and getting local control and logging of your DNS queries is probably useful for power users. There are also commercial platforms that provide this capability, and they may provide significantly more "knobs" for what you want to block. Quad9 is a non-profit - we're not out to corner the market, and as long as privacy and security is increased for the end user, we're all for commercial solutions!

    "Quad9 blocks domains in Germany" - Currently there are no mandatory blocks that Quad9 is integrating or enforcing on our DNS platform, from any external party. We did briefly block some domains as a result of legal actions against us in Germany. The good news is that we won that case in Germany, after two years and three appeals and an enormous amount of time and money (which despite Germany's "loser pays" rule, is not even close to expenditures.) https://quad9.net/news/blog/quad9-turns-the-sony-case-around... The bad news is that the identical thing is happening now in France where we have a number of legal cases open against Quad9, and we do not see an end to this any time soon as long as there is an open question in the EU about what a content-neutral intermediary is and is not required to do.

    "Mullvad exiting creates more centralization, and that is bad." On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction. It's not just large public resolvers - consolidation in the ISP industry is causing more and more of the world's internet-using population to utilize a smaller number of recursive servers. Those servers are operated (mostly) by law-abiding companies, and so there is a strong interest by various parties interested in control of content to "put a hand on the available throat" even though it's the wrong throat to choke. We're busy with some ideas of how to solve this, both from a legal defense position as well as a technology position - stay tuned in the coming months. In the meantime, you can contribute a few euros/francs/dollars to us and we'll have more funds to pay for legal defense in France and hopefully up to the EU courts. https://quad9.net/donate/

    "Government agencies can tap data" - Quad9 is based in Switzerland. Despite what may be common knowledge from movies, there is a very formal and rigorous process for governments (Swiss or non-Swiss) to demand data. It is (ultimately) transparent, and managed in a way that is quite well structured - this is, after all, what the Swiss have been doing with financial data for many years. More importantly: Quad9 stores no user data about queries. There isn't anything to demand - the box of data is quite empty. Because of this technological decision and our wide announcement of it (https://quad9.net/about/transparency-report/) we have never received a request for data. As for technological methods: Quad9 operates in 200+ widely-separated locations, with no backbone or central data transport network - it is intentionally 'islanded'. It would be a significant challenge to intercept data at all those locations, though we're certain that there are many queries that are observed due to their presence on various ISP or cable networks which are under surveillance. We support all major DNS encryption methods today (even the two that run on QUIC - HTTP/3 and DOQ) and we encourage users to use one of those for their communications to us. We are also one of the few major resolvers experimenting with ADOx, which encrypts messages between the recursive resolver and authoritative server. (https://dnsprivacy.org/adox_status_and_deployment/)

  • You are probably the guy to ask. I have always found dns over TLS to be the fastest, but with the quic versions making an entrance, maybe things have changed. Which is the one that gives me the fastest replies?
  • Thanks for the clarification, I mistakenly assumed you were also required to block sanctioned media (mostly Russian/Iranian), but upon further research apparently that only applies to ISP DNS.
  • I saw your response about not blocking ads currently. What about blocking adult content, for a child's computer? Mullvad had such an option[1] under family.dns.mullvad.net. Very useful!

    [1]https://mullvad.net/en/help/dns-over-https-and-dns-over-tls

  • Thanks for this! I was looking at your transparency report (https://quad9.net/about/transparency-report/) and I notice 2026 is not included in the 'list of years in which we have not received a request for data', despite the list being updated quarterly according to the text below it. When I saw the page earlier, I assumed that either the list isn't actually updated quarterly, or I'd discovered an exciting example of a warrant canary.
  • > Quad9 is based in Switzerland. Despite what may be common knowledge from movies, there is a very formal and rigorous process for governments (Swiss or non-Swiss) to demand data.

    Due to Lugano Convention [0] / Budapest Convention [1] / Hague Convention etc, I don't see how Switzerland is any more insulated than, say, Norway is (both these countries are part of EFTA & signatories to various UN/EU/EFTA treaties). Per this article [2], Switzerland ranks below Ireland, Portugal, Denmark, France in Data privacy laws (in fact, it ranks the same as the UK).

    If I am being honest, at this point, "based in Switzerland" (or Cyprus or Sweden or Gibraltar) comes across as marketing gimmick VPN companies are notorious for.

    [0] EU civil & commercial law enforcement in Switzerland: https://www.legal500.com/guides/chapter/switzerland-enforcem...

    [1] Mutual Legal Assistance Treaty (MLAT) is bypassed: https://rm.coe.int/16802e726c

    [2] https://www.comparitech.com/blog/vpn-privacy/surveillance-st...

  • > On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction.

    It seems all too similar to the degradation of peer-to-peer networks where nodes are replaced by few supernodes. You mentioned a couple reasons yourself: consolidation and legal pressure. Add to this the technical qualification aspect and time investment (Mullvad's position), and the financial cost of sustaining such a non-profit project. Suddenly there are very few people or even organizations worldwide, who can bear the burden.

    Thank you for existing and your tireless work.

  • For awhile I self-hosted adguard dns server. It supports iphone profiles thus forcing iOS DNS. I eventually disabled it due to timeout issues specific to iOS. Issue was something DNSSEC related.

    While reproing the issue I noted the average recursor round trip time from my OVH server hosted in Oregon to the default upstream DNS - Quad9 - was around 70ms. When I changed it to Hurricane Electric the roundtrip dropped to a steady 20ms. Later I changed it again to Cloudflare and the roundtrip was a consistent 2 to 3ms.

  • It's not that I don't trust Quad9 or dns.sb or any of the others, it's just that I trust Mullvad more.

    Sad to see this going away, but I assume this is so Mullvad can focus on their primary services.