I really hope this doesn't catch on widely. It should be a tool for use where censorship issues can't be solved politically. Otherwise, why even have protocols at all? Just say the only protocol is HTTP. IP, etc. are just an HTTP implementation detail.
DNS over HTTPS
71–80 of 195 posts
Re: DNS over HTTPS
#72Earlier quoted context omitted.
> Side note - I just learned that performant is not a recognized word ( https://english.stackexchange.com/questions/38945/what-is-wr... ) I don't personally use the word since there are many alternatives, but its use is now definitely widespread and consistently understood. There's really no argument against the fact that it has entered the English lexicon.
I don't use it either, and I agree with the poster on that stackexchange link about it sounding like manager/marketing-speak, but when I see it, it makes me pause for a second to think about what really means (perhaps that's the point) --- I had this exchange with a coworker not long ago: CW: ...and this way it'll be more performant too. Me: Performant? As in faster? CW: Yes. Me (to self): Then why didn't you just sa…
Re: DNS over HTTPS
#73Re: DNS over HTTPS
#74Re: DNS over HTTPS
#75I can see how DNS over HTTPS addresses security, but I do not see how it helps with privacy. After resolving the IP address over secure connection HTTPS still sends the host name unencrypted, so one can just eavesdrop on that. And if encrypted DNS becomes widespread, I suspect that various state-imposed firewalls like one Russia will just look for HTTPS connection header to block a particular site.
> I suspect that various state-imposed firewalls like one Russia will just look for HTTPS connection header to block a particular site. What if that site does a lot more things? Even they can only upset their population so much by blocking entire domains. With regards to Russia, Google's DNS over HTTPS is a perfect example. "Domain fronting" is a thing for a reason.
Re: DNS over HTTPS
#76Actual DNS servers and clients have supported TLS since the early years of this decade. What's gained by adding HTTP transport overhead?
Re: DNS over HTTPS
#77Earlier quoted context omitted.
> Side note - I just learned that performant is not a recognized word ( https://english.stackexchange.com/questions/38945/what-is-wr... ) I don't personally use the word since there are many alternatives, but its use is now definitely widespread and consistently understood. There's really no argument against the fact that it has entered the English lexicon.
I don't use it either, and I agree with the poster on that stackexchange link about it sounding like manager/marketing-speak, but when I see it, it makes me pause for a second to think about what really means (perhaps that's the point) --- I had this exchange with a coworker not long ago: CW: ...and this way it'll be more performant too. Me: Performant? As in faster? CW: Yes. Me (to self): Then why didn't you just sa…
Re: DNS over HTTPS
#78Earlier quoted context omitted.
What does this shady technique (dns tunneling) have to do with dns-over-ssl?
why shady? (assuming that shady is meant in a negative way)
Re: DNS over HTTPS
#79You can also do http(s) over DNS: http://code.kryo.se/iodine/ . Nice way to avoid paying captive portals, although probably not legal.
Why not?
AIUI; not legal advice.
Re: DNS over HTTPS
#80Earlier quoted context omitted.
What does this shady technique (dns tunneling) have to do with dns-over-ssl?
why shady? (assuming that shady is meant in a negative way)