Live data from Hacker News

How to keep your ISP’s nose out of your browser history with encrypted DNS

arstechnica.com

191–195 of 195 posts

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#191

Now if we can just get a default encrypted email protocol....

I thought the reason that these critical infrastructures are not encrypted after decades and decades of use is that there are powerful agencies who want to snoop on them.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#192
post #137

Earlier quoted context omitted.

> What if we could have first class SSL certs for IP addresses? They're not routable.

What does this mean?

What's the next hop for a cryptographic hash? With IP addresses, you have a heirarchy: You match on a prefix to find the router to handle the next path, and that one matches on a longer prefix to find the next hop, and so on.

That allows you to have routing tables that don't include every single host on the internet. This is what allows efficient routing to happen.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#193
post #174

Earlier quoted context omitted.

The only thing you'll see is a list of CDNs and cloud providers.

I suppose that is true for smaller sites that don't have their own IP addresses but for larger sites you will be easily able to map it through reverse DNS.

Probably only for the very large. And even there I'm not sure if you can distinguish amazon from AWS, Microsoft from Azure and Google from Google Cloud. Facebook and Twitter should work reliably but even with a Facebook IP it could probably still be Instagram or Whatsapp.

Re: How to keep your ISP’s nose out of your browser history with encrypted DNS

#195
post #167

Earlier quoted context omitted.

>Then switch ISPs. Hahahha, and then he said "Then switch ISPs", like we have more than one high speed choice where we live".

Then vote for politicians that help with that. Due to laws designed for more broadband competition, I've got over 6 providers to choose from here in Germany.

They want a solution today, not in 20 years.
Post reply on HN