Live data from Hacker News

Improving DNS Privacy with Oblivious DoH

blog.cloudflare.com

21–30 of 367 posts

Re: Improving DNS Privacy with Oblivious DoH

#22

Earlier quoted context omitted.

Yes, I understand that. But I don't understand what ODoH does better than a run of the mill SOCKS proxy, such as Tor.

Tor is not a run of the mill SOCKS proxy, not least in that it inserts arbitrarily high latency into the user data path. On the other hand, an actual run of the mill SOCKS proxy would have visibility of the user's queries and their identity, defeating the purpose of the design.

> an actual run of the mill SOCKS proxy would have visibility of the user's queries and their identity, defeating the purpose of the design.

Why would it have visibility of the queries? If I send a TLS connection (containing my DoH query) through that SOCKS proxy, then the SOCKS proxy is unable to decrypt that TLS connection without breaking certificate verification and thus can't read my DoH query.

Re: Improving DNS Privacy with Oblivious DoH

#24

Earlier quoted context omitted.

The user's IP address is masqueraded by the proxy, and neither the DNS mothership (Cloudflare) nor the ISP get to see both who the user is and what they requested. It's an extremely desirable property DoH currently lacks

Yes, I understand that. But I don't understand what ODoH does better than a run of the mill SOCKS proxy, such as Tor.

[deleted]

Re: Improving DNS Privacy with Oblivious DoH

#25
post #21

> ODoH ensures that only the proxy knows the identity of the internet user and that the DNS resolver only knows the website being requested Who is the proxy here, and who the DNS resolver?

This is a protocol, not a product. There is no set proxy, or resolver.

Re: Improving DNS Privacy with Oblivious DoH

#27
post #21

> ODoH ensures that only the proxy knows the identity of the internet user and that the DNS resolver only knows the website being requested Who is the proxy here, and who the DNS resolver?

From the CloudFlare blog post:

> A key component of ODoH is a proxy that is disjoint from the target resolver. Today, we’re launching ODoH with several leading proxy partners, including: PCCW, SURF, and Equinix.

Re: Improving DNS Privacy with Oblivious DoH

#28
post #23

I urge people to stop repeating Apple Advertising. Claims of privacy and security are debunked weekly. You put yourself at risk if you believe it.

Debunked where? If they were I’d expect HN to be the first to publish

Yes, they are here every week.

There are soooooo many examples.

You want iphone security? Google iphone security. Hit news.

You want Apple privacy? Google, Apple privacy. Hit news.

This isn't obscure at all. It's a weekly event.

Re: Improving DNS Privacy with Oblivious DoH

#29

Preventing the target resolver from seeing client's IP address breaks GeoDNS. This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension. Given generally DNS is just the start of an intereaction, usually followed by the connection directly between the client and intended destination, I don't see what kind of snooping these privacy measures are there to prevent.

[deleted]

Re: Improving DNS Privacy with Oblivious DoH

#30
post #4

I’m good with the Apple’s privacy-oriented stance. But I can’t stop to think what will happen when advertisers knock on Apple’s door trying to get their hands on the users’ data that one else can access. Is Apple going to sell it out for more profits?

Apple almost never bends over for advertisers. The closest they have done is pushing a privacy change launch date further down the line.

https://www.theverge.com/2020/9/3/21420176/apple-ios-14-trac...

https://www.telegraph.co.uk/technology/2020/12/08/advertiser...

Post reply on HN