Live data from Hacker News

The Big DNS Privacy Debate at FOSDEM

blog.powerdns.com

61–63 of 63 posts

Re: The Big DNS Privacy Debate at FOSDEM

#61

There is a lot of misinformation and false choices. The ISP scaremongering seen here is not real and only serves to further entrench SV based global surveillance data collection unimpeded. An ISP is local, accountable to its customers and more important subject to local laws that can be enforced. An added benefit is ISPs cannot collect, collate and correlate vast amounts of global user data. This is a huge win for wi…

Here's the thing, right. SV global surveillance gets us better ads.

Meanwhile, governments ("An ISP is local" - you've GOT to be joking) actually systematically damage people based on surveillance data. Try visiting Pakistan and then see how governments react to that country's stamp being in your passport.

But it's hardly just that. Credit reports (are government mandated, and a monopoly, they are therefore government) really damage people. Police actions, "random" searches, ...

And of course, heavy handed copyright enforcement.

So we would be transfering DNS authority from entities, the SV companies, that have a VERY long history of not abusing that data, to entities, the governments that not only have a long history of abusing this data, but haven't even stopped doing so when caught with their hands in some cases literally torturing people.

Governments' accountability is a JOKE, a sad, distasteful joke. I will not be counting on that, sorry. And there is nothing local about those local ISPs in any of the countries I use them.

So: no thanks, given those choices, I'll take the Google/Cloudflare option, thank you very much.

Re: The Big DNS Privacy Debate at FOSDEM

#62
post #16

Earlier quoted context omitted.

Some would argue "still UDP based" is objectively worse, since it can be blocked. I don't think DNSCrypt is better for caching, doesn't it just protect one "leg" from a client (which can be a local cache) to a resolver (which also can be a cache) just like DoH? Similarly for pinning keys (although I think DNSCrypt made exchanging keys easier).

In the internet of the future, DNS will move from UDP to TCP because it's better, and HTTP/3 will move from TCP to UDP because it's better. Web 4.0 will consolidate these improvements, producing DNS over HTTP over QUIC over UDP.

What a mess.

Re: The Big DNS Privacy Debate at FOSDEM

#63
post #16
post #12

DNSCrypt has been around for a decade and works really well. Did everyone forget about it? It's objectively better than running DNS queries over HTTPS: still UDP based, no need to trust a CA but only the DNS server public key, can be cached locally or network-wise, perfect forward secrecy. There are clients[1] for Windows, Android, BSD, Linux, macOS and lots of providers[2]. It's really a shame it hasn't been made in…

Some would argue "still UDP based" is objectively worse, since it can be blocked. I don't think DNSCrypt is better for caching, doesn't it just protect one "leg" from a client (which can be a local cache) to a resolver (which also can be a cache) just like DoH? Similarly for pinning keys (although I think DNSCrypt made exchanging keys easier).

blocking or not blocking DNS is a two edged sword.

as we see in the discussion about the chromecast ultra: https://news.ycombinator.com/item?id=19170671 it is not necessarily desirable to have a way for apps to resolve DNS that can't be blocked at all.

Post reply on HN