this post was submitted on 16 Aug 2025
87 points (98.9% liked)

Technology

373 readers
1157 users here now

Share interesting Technology news and links.

Rules:

  1. No paywalled sites at all.
  2. News articles has to be recent, not older than 2 weeks (14 days).
  3. No videos.
  4. Post only direct links.

To encourage more original sources and keep this space commercial free as much as I could, the following websites are Blacklisted:

More sites will be added to the blacklist as needed.

Encouraged:

founded 3 months ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] lena@gregtech.eu 9 points 1 day ago (1 children)

I wonder how that works, I don't know how they'd do it purely with DNS

[–] crank0271@lemmy.world 20 points 1 day ago (2 children)

According to one of the comments in the source link (by u/gustothegusto on Reddit):

For anyone wondering how it works, it’s DNS level geo spoofing. When you try to visit a site that requires ID in your country, the resolver intercepts the DNS request and instead of giving you the real IP, it points you to one of their proxy servers located in a country without the ID requirement. From your browser’s perspective, it’s still connecting to the site, but from the site’s perspective, the traffic is coming from that other country. This is similar to what ControlD does with their “teleport locations” feature.

[–] RonSijm@programming.dev 3 points 1 day ago (1 children)

instead of giving you the real IP, it points you to one of their proxy servers located in a country without the ID requirement.

Sounds a bit weird, if it's just pure dns. Because if your dns server gives you a random proxy server instead, it sounds like this would break https right?

[–] x00z@lemmy.world 2 points 23 hours ago (1 children)

No it wouldn't break. HTTPS is the end-to-end encryption of HTTP. As long as you pass the original connection without altering it it'll be safe.

[–] crank0271@lemmy.world 1 points 19 hours ago (1 children)

Right - DNS would pass your connection to a geographically different server, with which you create a secure connection.

[–] x00z@lemmy.world 2 points 19 hours ago (1 children)

The question was about a "random proxy server". You can proxy HTTPS as a third party too without breaking it.

I'm not saying that's what they are doing though. It's possible they do this by just serving an IP in a different country. I haven't looked too much into it. In neither of the cases it would break HTTPS.

[–] crank0271@lemmy.world 1 points 19 hours ago

Good point. Thanks for helping me read more carefully!

[–] scytale@piefed.zip 6 points 1 day ago

This should be trvial for the other privacy DNS providers to do then. Hopefully Mullvad DoH will follow soon.