[Closed] keweonDNS - now with improved Certificate (iOS, Mac & Android)

Status
Not open for further replies.
Search This thread

5amar31

Senior Member
Feb 4, 2016
196
50
Great and million thanks!!!
I only want to have blocked ads and dangrous things. I don't want to block Porn, Crack or Warez.

Whenever you see a false blocked site do this:

1. Copy the URL/Domain into a TXT file
2. Send this TXT file to this mail Address: whiteli.g2o05glywjqt8zfy@u.box.com
3. That's it.

This is a semi-automated process to open incorrectly blocked pages. I'd rather have a web interface for authorized people and then it would be open within seconds, but the current system is too weak for such games. ;)

Have done this this time. Why don't you use AdZHosts? That's the most complete list & have never faced an issue like this.
 
  • Like
Reactions: MrT69

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
Have done this this time. Why don't you use AdZHosts? That's the most complete list & have never faced an issue like this.

To implement this kind of lists I would need a higher hardware and more bandwith. I already have an offer for this.

I'm talking about 75 Servers and each one with a 20GBit (it's not a typo - each of the Servers will have a TWENTY GIGABIT OPTICAL FIBER UNLIMITED) connection. All this Servers will be charged incl. Traffic at round about 45.000 EUR per month. That's a special price because I'm former Level3 employee. ;)

This sounds much money but there are a lot of people connected. And this system is required only for the entire filter.

If this system were in action, everything would be away from advertising, spyware, malware, etc., and your internet would be so incredibly fast.

But crowdfunding is also too early for the moment. It's not the technology, I just don't have the money. If I get that at some point, it will be a nightmare for some companies.
 
Last edited:

Timmmmaaahh!

Sr. Mod / Mod Cmte / Recognized Xmas Avatar Themer
Staff member
Sep 11, 2012
6,659
1
18,952
From From eh... Belgium!
OnePlus One
OnePlus 6T
...Sometimes I get complaints that the keweonDNS system is unusable because there are so many errors. I know that there are errors but unfortunately it is currently impossible for me to simply remove them....
You're not getting many complaints from me and my entire family is running on it. I have one nugget but I'll report more on that in a next post. Really, keweon is the best thing that happened to my router and all devices using it since DD-WRT.
I think the problem that many people experience here is the fact that they are not willing to give up some services, despite their privacy violating and ad infested nature. Facebook, to name the prime example of privacy invasion, is not welcome in our household. As far as I care, keweon could block everything related to it but I understand this isn't a popular goal.
I would even dare to say that having a Facebook account and using keweon is contradicting at best. But I'm not here to lecture anyone and I won't argue with any FB addicts as I have experienced this to be pointless. Sorry, I digress.

...When I suggested the system to a few investors, they said to me: There is no market potential for that. Seriously, no kidding...
It's a tough cookie, isn't it? One one hand you're sitting on a gold mine as there really is a market for privacy protection nowadays (that's the whole reason the GDPR was put in place) but on the other hand it's extremely difficult to make keweon profitable without compromising its values. I really hope you crack that cookie one day :)

...I hope you understand that this system is not easy to manage, but I am very happy that so many users are using this system.

For me it is important to get better. To have a better result in the filters and one day to be so good that companies want to license it. Whatever happens - for private and personal usage this system will always be and remain free. Without registration. Without data collection. Without the need to be careful on the internet.
Whoa there, T! People should always be careful on the net. Even the best filters won't stop the most cunning phishing mail and who knows what else is lurking behind the corner. However, keweon does provide more peace of mind and that's quite comforting.

I adore and respect your sense of transparency and altruism but I really wouldn't mind if there was a subscription option next to the always free keweon. It could be as simple as a donation subscription with no additional features or – here's an idea – a feature like having a custom stop-page when a domain is being blocked. A 'keweon pro' would definitely be something I'd be interested in. I've initiated a symbolic monthly donation of 1 USD for you to get used to it :highfive:
 

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
You're not getting many complaints from me and my entire family is running on it. I have one nugget but I'll report more on that in a next post. Really, keweon is the best thing that happened to my router and all devices using it since DD-WRT.
I think the problem that many people experience here is the fact that they are not willing to give up some services, despite their privacy violating and ad infested nature. Facebook, to name the prime example of privacy invasion, is not welcome in our household. As far as I care, keweon could block everything related to it but I understand this isn't a popular goal.
I would even dare to say that having a Facebook account and using keweon is contradicting at best. But I'm not here to lecture anyone and I won't argue with any FB addicts as I have experienced this to be pointless. Sorry, I digress.


It's a tough cookie, isn't it? One one hand you're sitting on a gold mine as there really is a market for privacy protection nowadays (that's the whole reason the GDPR was put in place) but on the other hand it's extremely difficult to make keweon profitable without compromising its values. I really hope you crack that cookie one day :)


Whoa there, T! People should always be careful on the net. Even the best filters won't stop the most cunning phishing mail and who knows what else is lurking behind the corner. However, keweon does provide more peace of mind and that's quite comforting.

I adore and respect your sense of transparency and altruism but I really wouldn't mind if there was a subscription option next to the always free keweon. It could be as simple as a donation subscription with no additional features or – here's an idea – a feature like having a custom stop-page when a domain is being blocked. A 'keweon pro' would definitely be something I'd be interested in. I've initiated a symbolic monthly donation of 1 USD for you to get used to it :highfive:

First of all thank you for your message. When I read this previously in the office, I was really speechless for the first time. Thanks a lot for this and your words.

Let me give you a little insight about keweon, me and the big global business:

Imagine that it is possible that the Keweon system can filter IP addresses. With the current system I have no chance to do that and yes I know with DNS it is actually not possible at all. But supposing for some reason it would be possible. ;)

And then imagine you have the possibility to book the system for 1 to 3 EUR per month with your Internet connection. This has the advantage that the reaction times on Keweon are reduced to about 1 to 2ms.

An advertising filter in a completely new dimension and additionally an IP address filter. An update on both systems every 10 minutes. Sure, I can't offer 100% protection. 0-second or 0-hour attacks are still possible. But a 0-day attack is definitely history. And Facebook will stay unfortunately open. I will not do some kind of censorship. ;)

I'm talking about a mid-single-digit million amount for all of this. Hardware, redundancy, a few developers and about 6 months on GoLive. Unfortunately I have to install the system first and I think it is a good idea to test everything thoroughly before it runs. Oh yes, there is also no market potential here, investors said to me and it is too expensive;)

I guess you understand that I can't say more here about my solutions. My idea is that everyone has the possibility of basic protection. This must be a fundamental right. Everything else costs a bit if someone wants to have a bit more. What you see here with Keweon here is the demo system. It's a never ending trial period. And that's not all.

Investors just want to appear on the market and everything has to be cheap. I'm sorry, I do not see that. I will not set up a "global" security system with 50,000 € and then state how great everything is. That will definitely go wrong and then it's over with Keweon. Well, do you understand why I say either how I want it or not? It will not fail in a business concept. That is not the problem.

We both know: Tell me another word for IT security. It is a simple synonym: damn expensive: D

How am I supposed to explain all this within a 2 minute pitch? It doesn't work. It's impossible. I just only need a 20 million budget? Sure, no problem. And the team? Consists of me, my 10 year old daughter and her Hello Kitty cuddly animal. For some reasons this is the point where they don't ask about the Sales or Marketing Team. What a surprise.

I certainly don't have the best preconditions to make a business out of it, but hey, one Day will someone see this and also see the options and posiblities. Messages like yours make sure that I do not lose the fun. And that's exactly the most important thing. It's all about this. It's feasible, it works - and it works even damn well. Mostly. ;)

That's why I would not sell that for any money. It's fun and right now I do not see any need to do a huge business and nobody understands that anymore. Most people think I'm crazy, I say it's confidence.

Thank you & million times a thanks again for your donation. These are things I'll never forget.
 
Last edited:

5amar31

Senior Member
Feb 4, 2016
196
50
You're not getting many complaints from me and my entire family is running on it.
I think the problem that many people experience here is the fact that they are not willing to give up some services, despite their privacy violating and ad infested nature. Facebook, to name the prime example of privacy invasion, is not welcome in our household. As far as I care, keweon could block everything related to it but I understand this isn't a popular goal.

We are only trying to make this a better system. I have stopped using Facebook 3 years back. We shouldn't even use Amazon now?
 

Timmmmaaahh!

Sr. Mod / Mod Cmte / Recognized Xmas Avatar Themer
Staff member
Sep 11, 2012
6,659
1
18,952
From From eh... Belgium!
OnePlus One
OnePlus 6T
We are only trying to make this a better system. I have stopped using Facebook 3 years back. We shouldn't even use Amazon now?

Strictly speaking, I guess not. Unless we can fend off the domains with all the tracking/ads and the main page is clean. I know it isn't reasonable to block these major services, I was just making an example and I really hate FB (they've taken my mother hostage :silly:). I personally use Amazon myself on occasion. Heck, I'd be a hypocrite to say we have to block everything that's tracking us as a Google account owner (I do use DuckDuckGo for search though!). It's actually pretty crazy how much domains take advantage of our personal data nowadays...
 

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
We are only trying to make this a better system. I have stopped using Facebook 3 years back. We shouldn't even use Amazon now?

Doing nothing is not a solution either. This has been clearly demonstrated in recent years.
I think the advertising industry is really convinced that the Internet belongs to them. That's why I fight against any kind of advertising. Privacy? Yes, we ignore it, of course. Responsible advertising? Good point to give all users a big sh*t. And if they do not accept the huge sh*t we'll go to court.

My 7-year-old daughter watched some YouTube children's videos and suddenly a bloody shooter game advertisement appeared. Of course with the warning "only over 18 years". She had nightmares for 3 days. And I'm so damn sure I'm not alone with this problem.

Freedom doesn't mean you're free. Freedom is the permission to fight for your right and freedom without any weapons.

I am not vindictive. I simple forget nothing.
 

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
Last edited:
I just set it up on my router and I have a few questions:
Under the list of dns servers you provide there's two ipv4 running 6.80 and then there's a bunch running a older version underneath. Do I just use the top two or take one from 6.80 as my primary and then use the older one as the backup?

Another question I have in regards to the whitelist, I was running my tests to see if any website is broken and noticed that arstechnica would load but the page would be broken layout wise with the keweondns icon in the favicon. Would submitting to the whitelist resolve the layout issue or is it because of the stuff the site relies on would need whitelisting.
 
  • Like
Reactions: MrT69

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
I just set it up on my router and I have a few questions:
Under the list of dns servers you provide there's two ipv4 running 6.80 and then there's a bunch running a older version underneath. Do I just use the top two or take one from 6.80 as my primary and then use the older one as the backup?

Another question I have in regards to the whitelist, I was running my tests to see if any website is broken and noticed that arstechnica would load but the page would be broken layout wise with the keweondns icon in the favicon. Would submitting to the whitelist resolve the layout issue or is it because of the stuff the site relies on would need whitelisting.

Hi & thanks for the info about arstechnica!!!

The DNS Servers are only different at the backend. This is almost only for me when a user is claiming about non working sites. Than I see what's going wrong and why and I don't need to open my documentation to see the difference.

The version 6.8.x has a complete new Server protection build in. For you and all other users it doesn't matters. You only need to find out which one is the fastest. I hope the 176.9.62.x Servers will do the Job. ;)

arstechnica

I was working right now at this website and the problem was that they are using base64 encoded links. Programmers thinks that this is a good protection against Adblocking but this is only half the truth. Indeed it is no protection but it's good that they believe this.

The website is now working and also the videos are running. If you see any additional things on the site than let me know this please.

I will to do the upload as usual and the database is active at 4:00 AM GMT +1. Than your website is working again. Thanks for your great support and let me know when I can help!!!


Have fun & enjoy it!!
 
Last edited:
  • Like
Reactions: ainurrofiq

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
Info for all Users in Germany

logo_en.png


The German Federal Office for Information Security (aka. BSI - Bundesamt für Sicherheit in der Informationstechnik) has whitelisted my both Root Servers and the current 176.9.62.58 and 176.9.62.62 Server.

The whitelisting of the both Root Server happened at October 2017 based on my request to the BSI. The public DNS (176.9.x.x) servers were automatically (!) put on the BSI DNS Server whitelist about 4 weeks ago. (1st week of May 2018)

This means the BSI keeps an eye on the keweonDNS project. That makes me real damn proud.

This is a very important step for me if the system is to be licensed by companies. Unfortunately, I have no financial means to get keweon certified by the BSI. That would be awesome if that happens one day.




At this point thanks a lot to the Team of the BSI.

.
 
Last edited:

MrT69

Senior Member
May 9, 2006
1,748
4,422
54
Königsbrunn
www.keweon.de
Update in progress


A huge update is in progress. I removed round about 30 Million Domains from the blacklist to have better positiv results. The white list requests during the last 8 weeks was below 500.000 and I guess it's time to remove the entire crap within the next few days.

The current white list has now exactly 240.931.589 entires.

The current whitelist database has now a size of 9,464 GB. That's exactly the thing I want to have. A damn huge whitelist database.

The entire filtering is reduced again to Level 6 and I guess at the end you all will have less false/positive results.

Hope you enjoy this and during the next days the entire System will become better and better.




Thanks a lot to all of you!!

.
 
Status
Not open for further replies.

Top Liked Posts

  • There are no posts matching your filters.
  • 248
    Please read this first!


    The entire system is build up for demonstration and should show a new way to protect against Internet and Online threats. It should demonstrate that it is possible within the Internet to protect user, devices and there data.

    The entire System is a pure & 100% DNS filter system without the usage of any kind of proxy. My goal is it to proof security is possible without using any kind of proxy.

    A lot of sites using HTTPS communications within the Internet and therefore I offer a special self signed Root Certificate which block any existing domain on the blacklist with a valid HTTPS connection. Different sites using broken HTTPS Traffic to detect Adblock technologies and some sites might require the keweon Root Certificate. All HTTPS connections are only used to prevent browser and application errors within your Operation Systems.

    From the technical point of few a root certificate and just a DNS server is never a threat for any users or any kind of data. The entire system is protected within various ways to prevent data stealing from users and devices.

    For actual reasons and because of many discussions I want to inform you about threat possibilities:


    1. DNS Server which are not DNS Server and they act as (transparent) Proxy are able to redirect the entire user traffic for Data Analysis or Data stealing.​


    2. DNS Server which are not DNS Server and they act as (transparent) Proxy can easily redirect traffic to a Web Server and infect your system with this kind of online threats:

    Botnets, Cryptoware, Fake Software, Malware, Miningware, Online Worms, Phishing, Ransomware, Remote Keyloggers, Rogue Security Software, Spyware, Trojans and Virus.

    This kind of infections are possible via HTTP (via 80 or any other port) or HTTPS (via 443 or any other port) with or without a valid SSL Certificate. A single Let'sEncrypt can easily support this kind of Online Threats.​


    3. DNS Server which are not DNS Server and they act as (transparent) Proxy can use all methods of attacks in Point 2 to act as Botnet or Cache Server to spread this kind of attacks by a simple HTTP infection and download additional payload via HTTP (via 80 or any other port) or HTTPS (via 443 or any other port) with a single Let'sEncrypt certificate.


    4. DNS Server which are not DNS Server and they act as (transparent) Proxy can use a self signed root certificate to steal passwords and logins when you install this. The keweon Root Certificate is designed to protect users and against HTTPS errors which will happens because of filter or blocking HTTPS traffic. When a keweonDNS Server is setup as a (transparent) Proxy it is possible to redirect the entire user traffic and get user login and passwords which is generally known as "MITM ATTACK".


    Please take note that the usage of a Root Certificate from someone you don't know can cause serious problems when the Server is build up to target user. With a MITM Attack it is possible to get data, passwords and logon credentials.


    5. The entire keweonDNS Project is build and invented to protect users, there Data and its protecting against almost all Online threats. Various fuses are build into the entire environments many times.

    6. The keweon Servers do not any kind of Data collection. This is one of my core visions. Why I should build up a system which prevent data collection system and then I will do it by myself? There is also NO (!) Data Collection even on Servers OS Level.​


    The entire keweonDNS System runs public with global access since 2014. At this point let me say thanks a lot to all users for there trust into me and the entire keweonDNS solution.


    Thanks a lot to each single user!!






    keweonShield.png





    **************************************************************

    Business inquires: Please see contact information section below.

    ***************************************************************


    **************************************************************

    Keweon quick start.
    Read the available servers and certificate sections now if you already know what you are doing. New users please skip to the "About Keweon" section below and return to the DNS and Certificate sections later:

    **************************************************************


    **************************************************************

    Available DNS servers (choose one primary and one secondary):

    Main Servers:
    IP: 176.9.62.58
    IP: 176.9.62.62

    or

    IPv6: 2a01:4f8:150:8023::58
    IPv6: 2a01:4f8:150:8023::62


    Update November 28, 2018:

    If you have installed the root certificate, I recommend that you use these two servers. This servers can be used without certificate but a lot of sites will not porpper work.

    IPv4: 213.239.207.143
    IPv6: 2a01:4f8:a0:8487::143

    IPv4: 107.191.55.215
    IPv6: 2001:19f0:6401:175d::215

    These servers have special blocklist entries which blocks things such as graph.facebook.com, pixel.facebook.com, all amazon-adsystem.com domains and all the things which are normaly not possible to block without any impact to apps, websites and other things. Also, this blocks special domains for YouTube which prevents data transmission to them.

    **************************************************************

    Available Server List for keweon Privacy & Security
    (Server Edition keweonDNS v.6.80.280.LL)

    Australia / Sidney: (vServer)
    k1ns-au-001.keweon.center
    45.76.125.130
    2001:19f0:5801:b45::130

    France / Paris: (vServer)
    k1ns-fr-001.keweon.center
    45.77.62.37
    2001:19f0:6801:95e::37

    Germany / Frankfurt (vServer)
    k1ns-de-001.keweon.center
    104.207.131.11
    2001:19f0:6c01:61f::11

    India / Bangalore (vServer)
    k1ns-in-001.keweon.center
    IPv4: 139.59.33.236
    IPv6: 2400:6180:100:d0::30d:5001

    Japan / Tokio (vServer)
    k1ns-jp-001.keweon.center
    45.77.25.72
    2001:19f0:7001:22a8::72

    Netherland / Amsterdam (vServer)
    k1ns-nl-001.keweon.center
    45.77.138.206
    2001:19f0:5001:d8d::206

    Singapore / Singapore: (vServer)
    k1ns-sp-001.keweon.center
    45.76.151.221
    2001:19f0:4400:4f31::221

    UK / London (vServer)
    k1ns-lon-001.keweon.center
    45.32.183.39
    2001:19f0:7402:a61::39

    USA / Dallas (vServer)
    k1ns-tx-001.keweon.center
    45.76.57.41
    2001:19f0:6401:9ed::41

    USA / New Jersey (vServer)
    k1ns-ny-001.keweon.center
    45.77.144.132
    2001:19f0:5:2962::132

    USA / Silicon Valley (vServer)
    k1ns-sv-001.keweon.center
    45.32.140.26
    2001:19f0:ac01:639::26
    **************************************************************


    **************************************************************
    Keweon Root certificate (not required, but will suppress certificate errors):

    http://pki.keweon.center

    For Windows Systeme (MSI File) The certificate is working for IE, Edge and Chrome Browser.
    >> CLICK HERE <<

    MSI within a ZIP file:
    >> CLICK HERE <<

    For Android and iOS devices, also for Firefox and Mozilla Browser:
    >> CLICK HERE <<

    Certificate within a ZIP file:
    >> CLICK HERE <<

    For Admins to use it within Active Directory as REG file:
    >> CLICK HERE <<

    REG within a ZIP file:
    >> CLICK HERE <<

    If you want to have a "AllInOne Package" use this link please:
    >> CLICK HERE <<


    (End of Quick Start section)

    **************************************************************


    **************************************************************
    About Keweon:

    Keweon comes from the German words "KEine WErbung ONline"--translated to English it means "no advertising online."

    Keweon is more than a generic adblock system. Keweon does:

     Advertising Blocking
     Adware Protection
     App Protection
     Bandwidth Protection for Mobile Phones
     Botnets Protection
     Cryptoware Protection
     Fake Online Shop Filter
     Fake Software Protection
     Malware Protection
     Miningware Protection
     Online Worms Protection
     Pharming Protection
     Phishing Protection
     Popup Blocker
     Privacy Protection
     Ransomware Protection
     Remote Keyloggers Protection
     Rogue Security Software Protection
     Spoofing Protection
     Spyware Protection
     Tracing Protection
     Tracking Protection
     Trojan Protection
     Virus Protection
     and a lot of other things

    Things Keweon does not do or does not have:
     Acceptible advertising exceptions
     A Malware or virus scanner
     Data collection

    Keweon will:
     Save bandwidth. Ads are blocked, not just hidden.

    **************************************************************


    **************************************************************

    Basic instructions:

    1. Take the DNS Servers
    2. Install the keweon Adblock Root Certificate (recommended, not required)
    3. Change your Internet Router or your Mobile Device to use the servers
    4. Reboot (Router and PC)


    **************************************************************


    **************************************************************

    Trusted apps for changing DNS on your device:

    - Android: https://play.google.com/store/apps/details?id=com.frostnerd.dnschanger

    - iOS/Apple: https://itunes.apple.com/us/app/dns-override-set-dns-for-wi-fi-and-cellular/id1060830093

    - Chrome OS: Click on wifi icon, click on Network, scroll to Name Servers, and input DNS entries.

    - Chrome browser help: https://www.xda-developers.com/fix-dns-ad-blocker-chrome/

    **************************************************************


    **************************************************************
    FAQ:

    1) Does my traffic runs trough the keweon System?

    Not even one byte from you or your device will flow through my servers. Also the same with HTTPS things. Take a sniffer or wireshark or NirSoft Network Suites and you will be surprised. All HTTPS Ads traffic will be terminated with "0" bytes which will show to you that there is no sniffing or spying from my side.

    2) Here are some questions from Telegram users which might be interesting for you.

    http://downloads.keweon.center/keweon/keweon_questionnaire.pdf


    3) If you have questions - please ask!
    **************************************************************


    **************************************************************

    Contact information:

    If you want to send blacklists (things that should be blocked) please send them to: blackli.wovqusywx173aog9@u.box.com

    If you want to send whitelists (things that shouldn't be blocked) please send them to: whiteli.g2o05glywjqt8zfy@u.box.com

    If you open a Website and this site looks kind of strange because of missing CSS & other things, then take the URL, copy to TXT and send this TXT to: site-error@keweon.center

    Developer email: torsten.jahnke@keweon.com (If you are a Company and if you want to test and use keweonDNS within a business environment I can offer you a faster connection within EMEA.
    This is only possible if you have a public static IP Address. Dynamic Addresses are currently not possible for security reasons.)

    **************************************************************


    **************************************************************

    New license terms because of the EU DSGVO/GDRP (25.05.2018):

    Business and Corporate usage is not allowed without my written permission.
    The usage of keweon within a private and personal environment and all released and public available files of the entire keweon System are subject of the License right of the WTFPL license.

    Excluded from this license are all server technologies, the SSL technologies and in addition all source codes which personally belongs to me.

    **************************************************************
    52
    How to use keweon?

    It's very easy:

    1. Take the DNS Servers
    2. Install the keweon Adblock Root Certificate ( <<< THIS IS ONLY A RECOMMENDATION)
    3. Change your Internet Router or your Mobile Device to it
    4. Reboot (Router and PC)
    5. Done! That's it.
    6. See the Internet within a never seen way

    In the meantime the keweon AdBlock Root Certificate has more than 4 Millions global downloads. This certificate is not required but for a few websites it is mandatory.
    This certificate will only surpress the certificate errors. Not all of them because I'm still working on this.

    On iOS Devices just open Safari. With Android use the default Browser and go to http://pki.keweon.center and after 3 sec. the download of the certificate will start. JUST THE DOWNLOAD!! You need to install it by yourself. More facts about the keweon Root Certificate will comming soon on the website.


    Test the DNS Servers within this List and choose the one which is the fastest for you:

    https://xdaforums.com/android/software-hacking/keweon-privacy-online-security-t3681139#6


    How to use it on Android devices:

    Use an App of your choice or use this. I also use this app and from my point of view this is the worldwide best App to change the DNS settings on Android devices. No Root Access is required. The developer is from Germany and I have had a good contact to him. The app is free of charge and also free of advertising. The source code for this app is also available on GitHub. If you have troubles with it or want to have additonal features than contact the developer. He would be happy about every feedback.

    https://play.google.com/store/apps/details?id=com.frostnerd.dnschanger


    How to use it on iOS/Apple devices:

    All my iOS Tester using this App. If you have a better one or you are able to translate the Android App to XCode - your welcome.

    https://itunes.apple.com/us/app/dns-override-set-dns-for-wi-fi-and-cellular/id1060830093


    You are using Chrome and the DNS thing is not working? (thanks a lot @NamitNayan for this info)

    Google wants to prevent Adblocking via DNS. Therefore they have enabled an experimental Switch by default to prevent DNS blocking.
    Take a look at here if it's not working >>> HERE <<< and fix the problem within seconds.

    50
    keweonDNS & installation Information

    ALL keweonDNS Servers:

    Version: DoT Server - DNS over TLS (updated 03/21/2019)
    Used Certificate: Let'sEncrypt Certificate
    Server Address: dot.asecdns.com
    Port: 853 & 443
    IP Addresses:
    dot.asecdns.com (159.69.48.240 - HETTNER RZ Falkenstein)
    dot.asecdns.com (116.203.117.199 - HETTNER RZ Nuernberg)
    dot.asecdns.com (95.216.192.253 - HETTNER RZ Helsinki)
    dot.asecdns.com (2a01:4f8:1c17:6e44::240 - HETTNER RZ Falkenstein)
    dot.asecdns.com (2a01:4f8:c2c:491::199 - HETTNER RZ Nuernberg)
    dot.asecdns.com (2a01:4f9:c010:3071::253 - HETTNER RZ Helsinki)

    Version: DoH Server - DNS over HTTPS (updated 03/21/2019)
    Used Certificate: Let'sEncrypt Certificate
    Server Address: doh.asecdns.com/nebulo
    Port: 443
    IP Addresses:
    doh.asecdns.com (159.69.49.250 - HETTNER RZ Falkenstein)
    doh.asecdns.com (116.203.126.207 - HETTNER RZ Nuernberg)
    doh.asecdns.com (95.216.165.29 - HETTNER RZ Helsinki)
    doh.asecdns.com (2a01:4f8:1c17:6fc7::250 - HETTNER RZ Falkenstein)
    doh.asecdns.com (2a01:4f8:c2c:e25::207 - HETTNER RZ Nuernberg)
    doh.asecdns.com (2a01:4f9:c010:1cbd::29 - HETTNER RZ Helsinki)


    Version: keweonDNS v.6.80.280.LL (updated 03/21/2019)

    Australia / Sidney: (vServer)
    k1ns-au-001.keweon.center

    45.76.125.130
    2001:19f0:5801:b45::130

    France / Paris: (vServer)
    k1ns-fr-001.keweon.center

    45.77.62.37
    2001:19f0:6801:95e::37

    Germany / Frankfurt (vServer)
    k1ns-de-001.keweon.center

    104.207.131.11
    2001:19f0:6c01:61f::11

    India / Bangalore (vServer)
    k1ns-in-001.keweon.center

    IPv4: 139.59.33.236
    IPv6: 2400:6180:100:d0::30d:5001

    Japan / Tokio (vServer)
    k1ns-jp-001.keweon.center

    45.77.25.72
    2001:19f0:7001:22a8::72

    Netherland / Amsterdam (vServer)
    k1ns-nl-001.keweon.center

    45.77.138.206
    2001:19f0:5001:d8d::206

    Singapore / Singapore: (vServer)
    k1ns-sp-001.keweon.center

    45.76.151.221
    2001:19f0:4400:4f31::221

    UK / London (vServer)
    k1ns-lon-001.keweon.center

    45.32.183.39
    2001:19f0:7402:a61::39

    USA / Dallas (vServer)
    k1ns-tx-001.keweon.center

    45.76.57.41
    2001:19f0:6401:9ed::41

    USA / New Jersey (vServer)
    k1ns-ny-001.keweon.center

    45.77.144.132
    2001:19f0:5:2962::132

    USA / Silicon Valley (vServer)
    k1ns-sv-001.keweon.center

    45.32.140.26
    2001:19f0:ac01:639::26

    Physical Instance:

    Germany / Falkenstein
    k1-de-058-fsn.keweon.center (Physical)

    176.9.62.58
    2a01:4f8:150:8023::58
    and
    176.9.62.62
    2a01:4f8:150:8023::62

    DNS Server to use with keweon Adblock Root Certificate:
    This Servers block in addition:
    - pixel.facebook.com
    - Amazon data collection and advertising
    - more things which are normally not possible will coming soon step by step


    Germany / Nuernberg
    k1-de-143-nbg.keweon.center (Physical)

    213.239.207.143
    2a01:4f8:a0:8487::143

    USA / Dallas - Texas
    k1-ns2-us02.keweon.center (vServer)

    107.191.55.215
    2001:19f0:6401:175d::215

    (Updated at 21. March 2019)
    44
    Technical Details

    Public available DNS:

    Take a look at this thread:
    https://xdaforums.com/showpost.php?p=73985083&postcount=6

    Background System:

    The current system needs 42 Server (!) in the Background that everything is working.
    Actually the entire infrastructure is hosted on 5 different providers.

    How does it work?

    The entire System works with several Servers. Ubuntu, FreeBSD 11 and my own build Operation System based on UNIX is installed. The entire developement and all source codes are not public available. There is more than 14 yrs of work inside.


    Current Blacklist size:

    39.585.224 Domains (export to TXT)
    Current Virus/Ransomware Blacklist size:
    18.853.587 Domains (export to TXT)


    Current Blacklist contains:

    Tracker, Malware, Spyware, Adware, Advertising, Poison Websites Fake Software (Adobe Flash Updates which is in real Malware/Virus) & a few false/positive Sites.
    To cover all HTTPS errors because a lot of Advertising Vendors display and spread this crap via https to the world I have created the keweon Root Certificate. Allmost every Malware and Spyware will be installed via HTTPS. The Root Certificate is only responsible to suppress all https error messages for all this Advertising and poison things.


    Which Systems are working and acting with keweon?

    The keweon System is tested on almost every Operation System and Devices (iOS, Android, Xbox, Playstation, Samsung TV, etc... ) It's currently running within 3 companies because I know the Admins there. You can use it within you private environment but please DO NOT USE it within a Business environment.


    Why I can't use it within a Business environment?

    There are 2 reasons for it.

    1. I want that the entire system becomes free for private and personal usage and I already have requests from Companies and even from the Public Sector that they are interested about to use the System. As long as there are too many error within the System I don't have the option to sell this as an Business solution. That's the deal.

    2. Private for free, Business needs to license it. Of cause, the current system needs to be a bigger and stable system..


    Does my traffic runs trough the keweon System?

    Not even one byte from you or your device will flows through my servers. Also the same with the HTTPS things. Take a sniffer or wireshark or NirSoft Network Suites and you will be surprised. All HTTPS Ads traffic will be terminated with "0" bytes which will show to you that there is no sniffing or spying from my side.
    It would not make any sense that I drop all this crap traffic, blame to the advertising Industrie and I do exactly this things which I want to prevent?
    Btw... This fact was also the problem why I have had no success with investors. They want that I enable data sniffing or user sniffing but I would rather throw away the entire system & developement than doing what they want.

    39
    I need your help and support

    1. Support me with Black and White lists

    It’s veryimportant to know that keweonDNS will NEVER (!) do a censorship of the Internet. If you want to have i.e. Facebook blocked via HOSTS file, it’s up to you. But this will never be done via keweonDNS. I have other plans with porn and violence but this is a stage with keweon kidsafe which is currently far, far away.

    IMPORTANT:

    Any list you want to send to me has to be send as an attachment within an EMail. I will give you a short example for this.

    If you have a Raspberry PI and you have a real cute blacklist than copy all the addresses (or URL’s) into a TXT file and send it to me via mail. The same with some important whitelists. Don't care about the size.

    Don’t copy the addresses or URL's into Subject or Body of this Mail because this will never arrive. I don’t want to track and check all the mails and for security reasons only attachments will be processed. Please make sure you only send ZIP files that contains the TXT file or send native TXT files. Everything else will be dropped for security reasons. Don’t care about double entries and it doesn’t matters if you send the same TXT file 5 or 10 times again and again.

    Websites which contains errors or Whitelist needs to be processed within the same way. Send the TXT or ZiP – that’s it.

    If you want to send blacklists please send them to: blackli.wovqusywx173aog9@u.box.com

    If you want to send whitelists please send them to: whiteli.g2o05glywjqt8zfy@u.box.com


    2. Support me with false/positive on keweonDNS

    If you open a Site and this site stay blank than copy the URL into a TXT file and send it to me. You do not need to collect them. If you send me 50 or 100 Mails and each of them contains only 1 link or address this doesn't matters.

    If you want to send URL’s or Links which are blocked and should be not blocked then send them to: whiteli.g2o05glywjqt8zfy@u.box.com

    If you open a Website and this site looks some kind of strange because of missing CSS & other pretty Website things than take the URL, copy to TXT and send this TXT to: site-error@keweon.center


    3. Router Compatibility:

    With a lot of SOHO Router it is possible to change the IPv6 and IPv4 default DNS Server Address. But there are are also a lot of Router outside where this is not possible.
    If you can provide some instructions and screenshots within a PDF I will release this on the Webpage. I have the experience that the AVM FritzBox sometimes will work and sometimes not. That is related to the fact that the Provider support IPv6 and you are only able to change the IPv4 DNS Server Address. With the tiny tool "FBEDITOR" it should be possible to change also the default IPv6 DNS Server Address on AVM Boxes.

    German Telekom Router are also a peace of crap. There you can change nothing except the Password and the WLAN key. The work arround by selecting "Different Provider" (anderer Anbieter) where you can set manualy the DNS Server will not work.

    Unfortunately I only have CISCO, LINKSYS and ASUS Hardware running with i.e. DD-WRT. I appreciate if you can help me with creating instructions how to change DNS v4 & v6 settings on your Home/SOHO/Wireless Router. No rush on this because all this instructions will be released on the Website.


    Million thanks in advance!