← Back to context

Comment by 1vuio0pswjnm7

3 hours ago

FWIW, I operate own DNS (including own custom root.zone) and I MiTM own TLS traffic with a localhost forward proxy. With this setup I get r/w access to response bodies, I add a CSP as an HTTP response header, and a long list of other traffic manipulation. There is no tracking, ads, telemetry, etc. Nothing leaves the computer unless I allow it. Operating DNS plus forward proxy gives me lots of control

Letting Cloudflare (CF) operate DNS and direct traffic through its proxies gives CF control

It's interesting to see how they use it under market pressures

This is a tangent, but your setup sounds interesting to me — would you share more about how to configure such for myself?

  • Many years ago I started to describe how it works in an HN comment and some reply complained about the idea of terminating TLS, i.e., decrypting, and then re-encrypting. Obviously this sacrifices something, e.g, speed, in order to gain _control_

    But this is what Cloudflare does and no one seems to mind

    Large companies also do this to protect their LANs

    I'm not running a CDN, only a small home LAN. I'm only procesing a small amount of traffic on a personal computer. This setup is fast enough for me, it's not slow at all

    The basic configuration is generally:

    1. Configure DNS to point to the local proxy listening address #1, a local address, e.g., using a wildcard in a zone file

    2. Configure the proxy to terminate TLS, "do stuff", and then forward to proxy UNIX socket path #2 or proxy listening address #2

    3. After doing the stuff, the proxy then sends the traffic over the internet

    The "do stuff" part is personal. It depends on what one wants to do. There are seemingly endless possibilities

    It's not likely the constantly changing configurations I use would be suitable for others. It's all based on personal preferences and usage habits

    I rarely use a graphical browser, for example

    I don't make piecemeal remote DNS queries like most www users. (IME, most A RR's stay the same over long periods.) I get bulk DNS data periodicallly from a variety of sources and load it into the proxy's memory. When I make an HTTP request there is either no DNS lookup because I'm using the IP address of the proxy or there is a single, local DNS lookup which returns the address of the proxy. There is no access to remote DNS

    When I first decided to start inspecting own TLS traffic by terminating and re-encrypting, I initially tested the idea using socat

    After I saw that it worked, I started using other software like haproxy

    I never expected this approach would work well enough but many years have gone by and I'm still using it. The configurations I use are much longer and more complicated than any sample I have ever seen on the www

    It's funny that Cloudflare is decrypting and re-encryting _other peoples'_ traffic, and on a massive scale, but few people seem interested in doing this with their _own_ traffic

    It can be useful, IMHO