Live data from Hacker News

Improving DNS Privacy with Oblivious DoH

blog.cloudflare.com

31–40 of 367 posts

Re: Improving DNS Privacy with Oblivious DoH

#31

Preventing the target resolver from seeing client's IP address breaks GeoDNS. This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension. Given generally DNS is just the start of an intereaction, usually followed by the connection directly between the client and intended destination, I don't see what kind of snooping these privacy measures are there to prevent.

Valid points, but...

> Preventing the target resolver from seeing client's IP address breaks GeoDNS.

If the proxy and the target are in the same metro as the user, it shouldn't really matter.

> This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension.

1.1.1.1 runs at Cloudflare's edge. Most likely it is recursing DNS from more or less the same location as the user and so ECS isn't really required when in fact it exposes the client unnecessarily to upstream name-servers.

> I don't see what kind of snooping these privacy measures are there to prevent.

The one where DNS resolvers build to sell browsing profile of its users?

Re: Improving DNS Privacy with Oblivious DoH

#32
> Sullivan said a few partner organizations are already running proxies, allowing for early adopters to begin using the technology through Cloudflare’s existing 1.1.1.1 DNS resolver.

In other words, in order to thwart efforts to make the internet anonymous , US companies are planning to takeover DNS for the vast majority of people.

Re: Improving DNS Privacy with Oblivious DoH

#33
post #20

I urge people to stop repeating Apple Advertising. Claims of privacy and security are debunked weekly. You put yourself at risk if you believe it.

Do you have actual proof of this or are you just going to make misleading claims yourself?

Privacy is a buzzword to boost sales even more. Perhaps the biggest problem with Apple is its nasty monopoly strategies, remember the times you could easily add more RAM, change batteries?

Re: Improving DNS Privacy with Oblivious DoH

#35
So I do wonder how such systems can be designed or implemented such that geoip systems can still work.

While I'm sure aws route53 and cloudflare's own routing systems can handle this properly, Cloud isn't quite the answer. Not every workload fits on the cloud (see: Discord, which runs on leased servers), and a system that breaks down if your rented datacenters aren't in alignment with Cloud operating regions doesn't make a great solution.

Re: Improving DNS Privacy with Oblivious DoH

#36
post #3

Probably better source, the blog post at Cloudflare: https://blog.cloudflare.com/oblivious-dns/ See also: https://news.ycombinator.com/item?id=25344220

Thanks. The original post redirects to:

https://guce.advertising.com/collectIdentifiers?sessionId=3_...

Which is blocked at the DNS level on my network.

Re: Improving DNS Privacy with Oblivious DoH

#39
post #4

I’m good with the Apple’s privacy-oriented stance. But I can’t stop to think what will happen when advertisers knock on Apple’s door trying to get their hands on the users’ data that one else can access. Is Apple going to sell it out for more profits?

It's just marketing. Apple has already shown they will sell you out with PRISM. Who knows what other backroom deals are happening outside our knowledge. The only reason we found out about PRISM is because the gigantic scale and Snowden sacrificed Everything to let it be known.

One thing I like to remind people of is the fact that the Snowden docs that revealed PRISM were years old at the time of Snowden gathering them, and even older at release... just imagine how much further things have progressed in the 10+ years since. (iirc lots of them had 2007 dates on them)

Re: Improving DNS Privacy with Oblivious DoH

#40

> Sullivan said a few partner organizations are already running proxies, allowing for early adopters to begin using the technology through Cloudflare’s existing 1.1.1.1 DNS resolver. In other words, in order to thwart efforts to make the internet anonymous , US companies are planning to takeover DNS for the vast majority of people.

Oh, please. ODoH is a proposed standard. Use whatever the hell proxy/resolver you feel like, wherever you like.

DNS is a shit show of unencrypted data flying around being scooped up by God-knows-who and along comes someone proposing a standard to fix said shit show and this is the response people get.

Post reply on HN