• Cousin Mose@lemmy.hogru.ch
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      18 hours ago

      This confuses the fuck out of me because my VPN in Switzerland using TLS DNS shows Germany as the country in DNS leak tests.

      The Swiss DNS provider doesn’t have servers in Switzerland?

      • Glitchvid@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        15 hours ago

        Quad9 is a Swiss org, but it operates at hundreds of PoPs inside many different countries (anywhere PCH has a presence), their addresses are anycast so it’ll use whatever the upstream routes/BGP dictate.

        Both Quad9 and CloudFlare have the closest DNS for my network, at around 1ms RTT. However CloudFlare doesn’t support ECS, so I use the alternate Quad9 service that does, since it gives me better performance on a number of CDNs.

        • Cousin Mose@lemmy.hogru.ch
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 hours ago

          Right, I understand all that but I still can’t figure out why DNS is going to a 14 Eyes country instead of staying in Switzerland.

          • Glitchvid@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            28 minutes ago

            If it was a simple geoip lookup that isn’t really reliable wrt anycast addresses (or even addresses in general).

            9.9.9.9 for example gets reported as Berkely, CA (US). Which is only partially accurate, for complicated business holding and ASN reasons, but is not representative of what DNS PoP you’re actually using at any given time.

            • Cousin Mose@lemmy.hogru.ch
              link
              fedilink
              English
              arrow-up
              1
              ·
              19 minutes ago

              That’s true and that all makes sense. I guess I kind of forget because generally the IP address is physically very near to where I’m testing from.

              I just switched to a Swiss DNS resolver regardless. I like Quad9’s malware blocking but it’s more important to me to keep the DNS server in Switzerland (despite it needing to query outside the country regardless).

    • uiiiq@lemm.ee
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      2
      ·
      1 day ago

      Not sure why would it be better. EU provides strict personal data regulations guarantees