DNS Malware Filtering Compared: Quad9 VS Cloudflare VS DNS Filter VS OpenDNS / Cisco Umbrella

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 พ.ค. 2020
  • Connecting With Us
    ---------------------------------------------------
    + Hire Us For A Project: lawrencesystems.com/hire-us/
    + Tom Twitter 🐦 / tomlawrencetech
    + Our Web Site www.lawrencesystems.com/
    + Our Forums forums.lawrencesystems.com/
    + Instagram / lawrencesystems
    + Facebook / lawrencesystems
    + GitHub github.com/lawrencesystems/
    + Discord / discord
    Lawrence Systems Shirts and Swag
    ---------------------------------------------------
    ►👕 lawrence.video/swag
    AFFILIATES & REFERRAL LINKS
    ---------------------------------------------------
    Amazon Affiliate Store
    🛒 www.amazon.com/shop/lawrences...
    UniFi Affiliate Link
    🛒 store.ui.com?a_aid=LTS
    All Of Our Affiliates that help us out and can get you discounts!
    🛒 lawrencesystems.com/partners-...
    Gear we use on Kit
    🛒 kit.co/lawrencesystems
    Use OfferCode LTSERVICES to get 5% off your order at
    🛒 lawrence.video/techsupplydirect
    Digital Ocean Offer Code
    🛒 m.do.co/c/85de8d181725
    HostiFi UniFi Cloud Hosting Service
    🛒 hostifi.net/?via=lawrencesystems
    Protect you privacy with a VPN from Private Internet Access
    🛒 www.privateinternetaccess.com...
    Patreon
    💰 / lawrencesystems
    Forum post with the script and details
    forums.lawrencesystems.com/t/...
    Part two:DNS Malware Filtering Followup: Comments, Concerns, Cisco Corrections and Conversation
    • DNS Malware Filtering ...
    Also, The IP visible at the top of the OpenDNS page is not my office IP address.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 133

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS  4 ปีที่แล้ว +17

    The Forum Post:
    forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflave-vs-dns-filter-vs-opendns-cisco-umbrella/5072
    Part Two:DNS Malware Filtering Followup: Comments, Concerns, Cisco Corrections and Conversation
    th-cam.com/video/sDuhxCWd3wU/w-d-xo.html
    The IP visible at the top of the OpenDNS page is not my office IP address.
    Also I did a test with NextDNS and posted the results in my forums

    • @regchan
      @regchan 4 ปีที่แล้ว +4

      th-cam.com/video/imlFubYv8YY/w-d-xo.html your ip is visible
      at the top of the open dns site

    • @macsavant
      @macsavant 4 ปีที่แล้ว

      The OpenDNS numbers are horrible. Did you configure it to block malware for your IP address? Be certain it's configured for your IP address.

    • @ernestoarellano5012
      @ernestoarellano5012 4 ปีที่แล้ว

      You need to configure your IP in cisco umbrella for it to apply the policy or use the roaming client. Even if it resolves it will show the block page.

    • @stephanefaure489
      @stephanefaure489 3 ปีที่แล้ว

      Unfortunatelly you didn't test Cisco Umbrella but only OpenDNS personnal. The Umbrella dashboard, possibilities and filter are way far more different.
      Do you have a list of you tested domains so I can test it with a proper Umbrella DNS and SIG deployement ?
      I guess you should probably change the video name to remove Umbrella or make an addon.
      Have a nice day :)

    • @stephanefaure489
      @stephanefaure489 3 ปีที่แล้ว

      Sorry I forgot, in your first page of resolution you have a 146.112.61.108, wich is an Open DNS IP, so your request has been redirect to an OpenDNS block page, did you take it in your maths ?

  • @pix_by_joshua
    @pix_by_joshua 4 ปีที่แล้ว +40

    Oh my gosh. Excellent Data Analysis! I'm going back to Quad9 even though the speed is slightly slower (by about 15ms) compared to Cloudflare. Thanks for sharing.

    • @christophersoutherlin2631
      @christophersoutherlin2631 2 หลายเดือนก่อน

      That's miniscule. The key benchmark is to stay below 50ms as a performance metric. For my network, Cloudflare was the fastest, but it's not stable and consistent. Upload speed was the most affected.

  • @PhrozenN
    @PhrozenN 3 ปีที่แล้ว +33

    Would love to see a followup on this! Maybe make it an annual event?

    • @BrianThomas
      @BrianThomas 2 ปีที่แล้ว +2

      Agreed 👍🏾

    • @ohjaysimpson397
      @ohjaysimpson397 ปีที่แล้ว

      Yes, it's been awhile. Whats the new DNS we should be using now

  • @Duder_abides
    @Duder_abides 4 ปีที่แล้ว +10

    This is great, and surprising. Thanks for the quality content, really like your videos. Switched all my gear to quad9. Interesting to see Umbrella crap the bed, they sure market the hell out of that.

  • @christianlempa
    @christianlempa 4 ปีที่แล้ว +5

    Thank's man, you're making so nice and valuable content, keep going ❤️

  • @goteamgorilla
    @goteamgorilla 3 ปีที่แล้ว +3

    I'm trying out Quad9 on my pi-hole. Thanks for the great review!

  • @maokinus
    @maokinus 4 ปีที่แล้ว +3

    For some constructive feedback, it would be great to see the exact config used in each subscription or in an included writeup. Great that you reviewed some but not really complete if you don't do the same for all.

  • @ldnzz
    @ldnzz ปีที่แล้ว +9

    Catching this after 2 years. Wonder how much has changed in that time? And if OpenDNS is still so far behind?

  • @podcaster_emeritus
    @podcaster_emeritus 4 ปีที่แล้ว

    Great video Tom. Thanks for the comparison.

  • @yajnalgibno6536
    @yajnalgibno6536 8 หลายเดือนก่อน

    Would be nice to see this test ONCE every year. Thank you BTW for the effort of this video

  • @brunoejb
    @brunoejb 4 ปีที่แล้ว

    This is great info! Will be doing something around it soon...

  • @ldnzz
    @ldnzz 8 หลายเดือนก่อน +2

    Lawrence please can you redo this test. It would be hugely beneficial for everyone. Would nice to see how NextDNS ranks against newer ones such as control d. Etc.

  • @sam_sheridan
    @sam_sheridan 4 ปีที่แล้ว

    Really useful great comparison

  • @Knaveofspades6
    @Knaveofspades6 ปีที่แล้ว +2

    Hello :-) is this still the same 3 years later? Be good to see an update. Love your videos.

  • @lamarchedutemps7427
    @lamarchedutemps7427 ปีที่แล้ว +3

    Quad9 all the way, great info ! :-) Subscribed

  • @TerryPullen
    @TerryPullen 4 ปีที่แล้ว +11

    I became a patron today. Thanks, Tom.

  • @nickrafuse984
    @nickrafuse984 4 ปีที่แล้ว

    very nice, thanks for this

  • @thoughtscribe
    @thoughtscribe 4 ปีที่แล้ว +3

    Very interesting comparison. I did notice that the portal your using for OpenDNS is the free version and not their paid tenant portal. Curious if there is a different level of protection between the 2.

    • @maokinus
      @maokinus 4 ปีที่แล้ว

      There are a lot more features included in Umbrella the enterprise DNS-Layer protection such as a selective proxy. Indeed this test does use the consumer edition which is OpenDNS branded not Umbrella. If you are curious to see some tests Umbrella the enterprise package check out these tests performed by AV-TEST www.av-test.org/fileadmin/pdf/reports/AV-TEST_DNS_Layer_Protection_Test_Feb_2020.pdf

  • @knowclueless
    @knowclueless 4 ปีที่แล้ว

    Did you create an OpenDNS account and create a policy and associate your internet facing IP? By default it doesn't filter suspicious sites.

  • @jgelliot
    @jgelliot 4 ปีที่แล้ว +22

    Looks like you missed an IP @ 3:12. You blurred one but missed the other

    • @JDSileo
      @JDSileo 3 ปีที่แล้ว +2

      shhhhhhh. Loose lips sink ships

  • @jkbobful
    @jkbobful 2 ปีที่แล้ว

    You should do another one of these

  • @petethompson1282
    @petethompson1282 ปีที่แล้ว +1

    Time to do NextDNS /Cleanbrowsing in this mix and run it generally as a new update

  • @dhill835
    @dhill835 ปีที่แล้ว +1

    It would be cool to see an updated test again.

    • @michnl1772
      @michnl1772 11 หลายเดือนก่อน +1

      +1 every year audit

  • @doffpv1854
    @doffpv1854 4 ปีที่แล้ว

    Not really surprise and i started to do this test some months ago ;) Thanks for sharing

  • @jcnash02
    @jcnash02 4 ปีที่แล้ว +1

    I’m wondering if more of the malware sites would have been blocked by dnsfilter if more categories were used...they might have them under other categories.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +5

      Putting malware domains under any other category would not make any sense. I mean would they be under finance since some are ransomware?

  • @bogdandubas3978
    @bogdandubas3978 3 ปีที่แล้ว +1

    Good start, but I don't think that this test is representable enough. It is possible that Quad9 just happens to use that exact list for constructing block list. Or Quad9 could just concentrate on a specific part of malware domains that is represented in the list used for testing. All in all, this test only increases Quad9's chances to beat other services, but it is to early to state that it's so much better.

  • @StefanoVazzoler
    @StefanoVazzoler 4 ปีที่แล้ว +2

    Would be nice to see nextdns

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +1

      I did a test of NextDNS and posted the results in my forums. forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflare-vs-dns-filter-vs-opendns-cisco-umbrella/5072

    • @StefanoVazzoler
      @StefanoVazzoler 4 ปีที่แล้ว

      @@LAWRENCESYSTEMS thank you, I was gonna run it myself later today but you saved me a few minutes. Interesting results...

  • @tyro4416
    @tyro4416 5 หลายเดือนก่อน

    Hi everytime i search for my primary and secondary DNS IP ADRESS i have 6 Malwares and i don’t know how to remove it, i have multiplie times searched for malwares on antivirus programs as Malwarebyte / F-Secure and Avast. They don’t find anything. But everytime i go to totalvirus i see my malwares. I need help to remove this please help me out.

  • @jcritch42
    @jcritch42 6 หลายเดือนก่อน +1

    There is also MDBR & MDBR+ from CIS (Akamai)

  • @reaperhammer
    @reaperhammer 2 ปีที่แล้ว +2

    I don't think you have to sign up to opendns to use it for home use

  • @PhilWrightAU
    @PhilWrightAU 9 หลายเดือนก่อน

    Do you have an updated link to the list or a list of lists pf the rogue domains please?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  9 หลายเดือนก่อน

      no, because all the public lists are also in Quad9 and most other popular DNS systems.

  • @johnnybananas1497
    @johnnybananas1497 4 ปีที่แล้ว +14

    I'm guessing quad9 comes out on top

  • @sergioabrantes
    @sergioabrantes 2 ปีที่แล้ว +1

    it's time for a new video to update the results

  • @pedromain
    @pedromain 8 หลายเดือนก่อน

    This need an update. Its been 3 years already. If I may I wish to sugest getting Quad9, NextDNS and Coltrol D antimalware against each other. Cloudflare, Google, OpenDNS are a waste of time, they will be bad at the end anyway.

  • @QuantumKurator
    @QuantumKurator 4 ปีที่แล้ว +8

    Can you please cover NextDNS?

    • @tomcapote
      @tomcapote 4 ปีที่แล้ว +1

      David Hartley Yes, THIS!

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +5

      I did a test of NextDNS and posted the results in my forums. forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflare-vs-dns-filter-vs-opendns-cisco-umbrella/5072

  • @JuanLopez-db4cc
    @JuanLopez-db4cc 4 ปีที่แล้ว +1

    Cheers from Florida!

  • @xugo91
    @xugo91 ปีที่แล้ว

    I wish there were something like quad9 but faster. Because I get a few issue in some game because of that

  • @ZeroGhostVR
    @ZeroGhostVR 3 ปีที่แล้ว +4

    Open dns is still faster than all in my area

  • @vikashyadav1872
    @vikashyadav1872 3 ปีที่แล้ว +3

    I'm confused which one to use!! Actually I need something that blocks malware, blocks antiphising, doesn't store ip address, deletes all history and does not save any users information. plz suggest me which one to use Quad9, Cloudflare or OpenWatch. Or some other dns which i don't know

    • @winsomenz
      @winsomenz 3 ปีที่แล้ว

      Use NextDNS or Quad9 if you need malware protection and privacy. Rest are just marketing DNS query farms.

  • @Szydelski
    @Szydelski 4 ปีที่แล้ว

    Pi-Hole is a nice element in DNS filtering :).

    • @-----------------------------
      @----------------------------- 4 ปีที่แล้ว

      Can't use your pi hole outside your network unless you want to VPN into your network daily on a mobile device.

    • @vgamesx1
      @vgamesx1 4 ปีที่แล้ว

      Well you can't really use a cloud based DNS either without the use of an app, at least on android you have to change the DNS on each individual network and for the most part you can't change settings for your 3G/4G connection at all and technically you can use pi-hole outside, it's not as if port forwarding is hard you just need a good way to automatically update your IP but of course it generally isn't recommended opening your devices up to the internet, the alternative is using an app such as Netguard which creates a local VPN that allows your device to do its own filtering via hosts file, so again extra work to manually update the lists but otherwise the best option for filtering outside your network.

    • @TheElderOne2003
      @TheElderOne2003 4 ปีที่แล้ว

      @@----------------------------- I use it on my Note 8 daily without fail. Android has an option for private dns address to be input. Granted one vm instance of with pihole I use is dedicated only for off site devices.

    • @Szydelski
      @Szydelski 4 ปีที่แล้ว

      @@----------------------------- I'm not saying the pi-hole is ultimate solution for every issue. However I'm actually using solution you suggested.:)

  • @AtikBayraktar
    @AtikBayraktar 4 ปีที่แล้ว +6

    I'm suspecting you didn't go thoroughly into settings for NextDNS. NextDNS has more security and privacy features, plus you select the blacklists yourself and there are many! It should just wipe out others in your test.
    edit: You also didn't go into advanced settings for OpenDNS? It logs you out and you didn't bother?

  • @ChrisBarrow1990
    @ChrisBarrow1990 4 ปีที่แล้ว +2

    Does anyone know how pi hole compares to these?

    • @bren.r
      @bren.r 3 ปีที่แล้ว

      Pihole just sits in between your computer and a big name DNS resolver. If we want to talk about performance, clearly a local DNS server is superior. I personally use it to have network wide DOH resolutions.

  • @drydengeary6860
    @drydengeary6860 4 ปีที่แล้ว +3

    Where’s WebTitan?

  • @aricmayberry
    @aricmayberry 4 ปีที่แล้ว +2

    Looked like you were signed into an OpenDNS account and not Cisco Umbrella. The Umbrella dashboard is totally different. Cisco has made no improvements to the original OpenDNS service. I did similar testing with OpenDNS a few years back and actually found that the malware filtering was better without creating an account. When I created an account and provided my WAN IP malware was no longer filtered.

    • @jackripper8791
      @jackripper8791 4 ปีที่แล้ว

      It is not quite true but I worked for Umbrella and I'm not surprised with test results tbh.

    • @johnhanly2948
      @johnhanly2948 4 ปีที่แล้ว

      I would also be interested in how Cisco Umbrella does.

    • @maokinus
      @maokinus 4 ปีที่แล้ว +1

      @@johnhanly2948 Public results here for Cisco Umbrella www.av-test.org/fileadmin/pdf/reports/AV-TEST_DNS_Layer_Protection_Test_Feb_2020.pdf There is also a OpenDNS Prosumer package that provides the Umbrella dashboard to consumers with a limited feature set.

  • @joelsantoro5221
    @joelsantoro5221 2 ปีที่แล้ว

    Does someone knows secondary iPV4 adress of DNSFilter?

  • @Rick9814
    @Rick9814 4 ปีที่แล้ว

    Does Quad9 block ads as well or just malware?

    • @DibyaK
      @DibyaK 4 ปีที่แล้ว +1

      If you want to block ads, and you are comfortable running your own services at home, then an excellent tool would be something like pi-hole, which you can setup to forward to Quad9.

    • @homemark22
      @homemark22 3 ปีที่แล้ว +4

      why not use adguard dns?

    • @bren.r
      @bren.r 3 ปีที่แล้ว

      @@homemark22 privacy

    • @homemark22
      @homemark22 3 ปีที่แล้ว

      @@bren.r Cares about your privacy
      Protecting your personal data is our top priority. With AdGuard, you and your sensitive data will be safe from any online tracker and analytics system that may attempt to steal your data while surfing the web. - that was from their website

    • @chuckhalo
      @chuckhalo 2 ปีที่แล้ว

      @@homemark22 yeah that doesn’t help

  • @YazhShah
    @YazhShah 4 ปีที่แล้ว +1

    Nextdns is underrated

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +2

      I did a test of NextDNS and posted the results in my forums. forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflare-vs-dns-filter-vs-opendns-cisco-umbrella/5072

  • @TwstedTV
    @TwstedTV 3 ปีที่แล้ว +1

    Wow so shocked that Cisco, the #1 networking security company in the world has lousy protection......LOL

  • @mrf_71
    @mrf_71 ปีที่แล้ว

    Can you please make a video about RethinkDNS?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  ปีที่แล้ว

      I don't use it or plan to. We use pfblocker and ublock.

    • @mrf_71
      @mrf_71 ปีที่แล้ว

      @@LAWRENCESYSTEMS do you have a video on pfblocker?

    • @mrf_71
      @mrf_71 ปีที่แล้ว

      @@LAWRENCESYSTEMS so if you don't use a product you won't make a video?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  ปีที่แล้ว

      @@mrf_71 I don't have time to test every tool on the market so I pick ones that are interesting or complementing.

  • @Reepix
    @Reepix 3 ปีที่แล้ว +1

    Can someone please summarise?
    I'm confused, that's a lot info to process spoken really fast... so quad9 is safest?

  • @Mangold108
    @Mangold108 ปีที่แล้ว +1

    Ciao. MAke sense since I am using Surfshark VPN to use also Surfshark DNS? or it is no need? thanks

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  ปีที่แล้ว +1

      I still prefer Quad9, even when I am using a privacy VPN.

    • @Mangold108
      @Mangold108 ปีที่แล้ว

      @@LAWRENCESYSTEMS huh! better then cloudflare?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  ปีที่แล้ว

      I think so.

  • @catsdgs
    @catsdgs 4 ปีที่แล้ว +3

    Cloudflave?

  • @shadow.banned
    @shadow.banned 3 ปีที่แล้ว

    You're telling me that Cloudflare let ALL of the malware through? Yeesh...

  • @Allltha8matters
    @Allltha8matters 2 ปีที่แล้ว

    Need 2022 comparison please

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 ปีที่แล้ว +1

      Still using Quad9

    • @Allltha8matters
      @Allltha8matters 2 ปีที่แล้ว +3

      @@LAWRENCESYSTEMS quad9 is too slow here in India/Asia, and cloudflare zero trust DNS filtering seems to be improved a lot. so a new 2022 comparison video would be awesome

    • @swiftypopty1102
      @swiftypopty1102 ปีที่แล้ว

      @@Allltha8matters It's work just fine for me in SEA

  • @Kingpingamer
    @Kingpingamer 4 หลายเดือนก่อน

    this video need a 2024 update

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 หลายเดือนก่อน

      There is a new version here th-cam.com/video/NUT4K3tk9Ns/w-d-xo.html

  • @petethompson1282
    @petethompson1282 3 ปีที่แล้ว

    be nice if you checked the adult content filtering too... malware is one but family safety is another.

  • @robertstan7243
    @robertstan7243 4 ปีที่แล้ว +1

    Only 1 issue with your videos: you talk too fast and a lot of words are not understandable by me or by the auto subtitle. Please, slow down just 5% and try to pronounce every at least technical word correctly. Love ya

  • @clausdk6299
    @clausdk6299 4 ปีที่แล้ว +2

    Your methodology might give a lot of wrong results. Using "dig" will not always give the right IP. Many malware sites have a low TTL on their A records and change the IP multiple times. Also sometimes they use Cloudflare first > and send the user to another site/IP afterwards. And as we know Cloudflare is awesome if you want to host malware sites, since Cloudflare rarely blocks sites or take them down.

    • @clausdk6299
      @clausdk6299 4 ปีที่แล้ว

      I wonder how many of those IP's belongs to Cloudflare....

    • @maokinus
      @maokinus 4 ปีที่แล้ว +1

      @@clausdk6299 Good point @8:15 the results show around line 16 or 17 IP address 146.112.61.108. The entire address block of 146.112.0.0 is registered to Cisco Umbrella. talosintelligence.com/reputation_center/lookup?search=146.112.61.108

  • @rjnickolparmar4214
    @rjnickolparmar4214 3 ปีที่แล้ว +1

    talk less show more performance... don't talk walk the talk