I understand why Cloudflare wants this (marketing, as well as being able to serve their customer’s content through restrictions, thus making them more valuable to those customers), but why does Apple want this? My knee-jerk is that they want to further hide/make unstoppable things like the Gatekeeper network checks, but there has to be more right?
Why would Apple care about hiding Gatekeeper traffic from internet providers?
Improving DNS Privacy with Oblivious DoH
91–100 of 367 posts
Re: Improving DNS Privacy with Oblivious DoH
#92I understand why Cloudflare wants this (marketing, as well as being able to serve their customer’s content through restrictions, thus making them more valuable to those customers), but why does Apple want this? My knee-jerk is that they want to further hide/make unstoppable things like the Gatekeeper network checks, but there has to be more right?
Firstly, Apple loves to act like they are always taking your privacy very seriously (of course that's not always true), so for the cost of a few engineers, they get a massive marketing point. "We take your privacy so seriously that we developed a new protocol to do so"
Secondly, Apple has an awful case of NIH syndrome. If they didn't develop it themselves, they would rather develop it from scratch themselves
Re: Improving DNS Privacy with Oblivious DoH
#93This seems to require DNSSEC as a key function. @tptacek ?
Re: Improving DNS Privacy with Oblivious DoH
#94Whats the point? Governments subpoena the information or just block the protocol outright. ( or in China, get it delivered to their door by Apple ) Commercial parties have a bag full of tricks from fingerprinting to embeds on the page itself to track you. Privacy seeking users are already tunneling their traffic. That leaves script kiddies at Internet cafes. TLS kind of fixed that already so... Good work?
You, the proxy, and the DNS service, can be in 3 different countries. It's not bullet proof but makes it quite hard for a single government. Unless you are a Bond villain I think this is more than you need. If you need more than that use ToR or similar.
DoH/DoT is still useful because it allows you to proxy your DNS over Tor (for example) without having to worry about tampering (or surveillance if you also use separate circuits per domain).
Re: Improving DNS Privacy with Oblivious DoH
#95This is a neat design, but, does this not just shift the issue of trust as to whether the proxy and the target are colluding: > However, each of these guarantees relies on one fundamental property — that the proxy and the target servers do not collude. So long as there is no collusion, an attacker succeeds only if both the proxy and target are compromised. I'm not sure how an end user would be expected to assess this…
Add a few more proxy hops and you’ve effectively reinvented Tor
Re: Improving DNS Privacy with Oblivious DoH
#96Re: Improving DNS Privacy with Oblivious DoH
#97Earlier quoted context omitted.
Oh, please. ODoH is a proposed standard. Use whatever the hell proxy/resolver you feel like, wherever you like. DNS is a shit show of unencrypted data flying around being scooped up by God-knows-who and along comes someone proposing a standard to fix said shit show and this is the response people get.
Decentralized spying > centralized spying
Re: Improving DNS Privacy with Oblivious DoH
#98Re: Improving DNS Privacy with Oblivious DoH
#99I suspect that practical matters will interfere with widespread adoption of encrypted DNS. In my state, Comcast is going to start charging heavy bandwidth users extra. After a few people get surprise bills, I suspect that lawmakers will require that internet providers break down a bill by application.
I’d just get Starlink. Even if the deal was worse in terms of cost it would be a way to say fuck you to the ISP. Without some way to do that ISPs will not be able to get away with such customer hostile behavior.
I guess it won't take long until the first community or HOA decides to ban Starlink dish installations for faked "optical nuisance" issues.