The Big DNS Privacy Debate at FOSDEM
blog.powerdns.com
The Big DNS Privacy Debate at FOSDEM
1–10 of 63 posts
Re: The Big DNS Privacy Debate at FOSDEM
#2It has low adoption and is not on a standards track (as far as I know) but I think it's the best proposal for DNS privacy and security so far.
Re: The Big DNS Privacy Debate at FOSDEM
#3I attended the DoH talk by Daniel Stenberg at FOSDEM. When talking about alternatives he didn't mention Dan Bernstein's DNScurve ( https://dnscurve.org/ ). It has low adoption and is not on a standards track (as far as I know) but I think it's the best proposal for DNS privacy and security so far.
Re: The Big DNS Privacy Debate at FOSDEM
#4Re: The Big DNS Privacy Debate at FOSDEM
#5As they say, if it's free, then you're the product. I (as a European) have much more confidence in my ISP to guarantee my privacy than in a company which mostly makes money out of advertisement.
Re: The Big DNS Privacy Debate at FOSDEM
#6I attended the DoH talk by Daniel Stenberg at FOSDEM. When talking about alternatives he didn't mention Dan Bernstein's DNScurve ( https://dnscurve.org/ ). It has low adoption and is not on a standards track (as far as I know) but I think it's the best proposal for DNS privacy and security so far.
Re: The Big DNS Privacy Debate at FOSDEM
#7There is no grievance management process, no way for legitimate sites to get a quick reprieve when they get blocked either due to operator error or issues with the petitions not being vetted and investigated for malicious intent (a competitor could easily knock you off in some states or regions and you wouldn’t even know).
While there are activists working on policies and campaigning for better laws, we really need stronger technological solutions against these (usually ridiculous) blocks that insult “due process” and harm people.
India is also very quick to rap on large multinational companies whenever they seem to provide something that those in power (or their supporters) frown upon. So centralized providers like Google DNS or Cloudflare DNS would have some tough times with the governments, since both have physical presence in the country with their servers/data centers.
A decentralized and yet secure/private DNS may be more resilient than these DoC (DNS over Cloud) providers if we have to deal with government censorship effectively.
Re: The Big DNS Privacy Debate at FOSDEM
#8My point is that, as alluded to in the article, changing how DNS works can have serious side effects. The fact that, as unintentional as it may have been, one of the world's biggest ad networks broke ad-blocking on a number of devices by changing how they handle DNS queries is worrying. I'm concerned that as DoH (or DoC as the article refers to it) proliferates, it'll be used less to circumvent censorship and more to take away control from end users and enterprise network administrators. Every app, the browser included, could creep towards using their own internal DNS query handler, using nameservers they trust to delivery their analytics and advertising queries.
Additionally, giving DoH/DoC choice through the browser suggests that the browser might return different results from other software on the device. This sounds disastrous.
And I suspect that the oppressive regimes that always come up in discussions about DoH would simply block the IPs of those cloud resolvers, which seem to rely on having a well-known IP or domain name.
Re: The Big DNS Privacy Debate at FOSDEM
#91. Round Robin your DoH requests across several providers. Eg, if CloudFlare sees one quarter of your DNS requests it's less revealing then if they see all of them.
2. DNS proxies. Sort of like a VPN for the DNS requests such that they're aggregated to one source IP before being passed to the DoH provider. Done at the ISP level? Or some other arrangement. The VPN here would not be privy to the requests due to TLS.
These ideas may require more work to be practical.
Re: The Big DNS Privacy Debate at FOSDEM
#10Oh well, this is the nature of evolution, like the recurrent laryngeal nerve in a giraff.