5 ms·
Google could easily take the initiative on the DNS query front and implement DNSCrypt by default on Chrome. It would booster client privacy and also block ISP f
by pippy 11y ago
Google could easily take the initiative on the DNS query front and implement DNSCrypt by default on Chrome. It would booster client privacy and also block ISP from selling usage data. So it would be a win-win for Google.
- PhantomGremlin 11y agoSo it would be a win-win for Google Yes, but would it be win-win for us? Google's already demonstrated that "don't be evil" is now just a sad memory. I'm not ready to believe them to "do the right thing". Their entire existence is predicated on increasing and refining their data collection and analysis, and acting on such. Google's seedy behavior already directly impacts me every day. I, for one, don't welcome this new corporate overlord.
- eikenberry 11y agoHow would this help if they are using the ISP's DNS servers as most people do by default?
- stingraycharles 11y agoThis can be promoted by offering the user the choice of several dnssec enabled public dns servers in Chrome. Or someone makes an extension that does this by default, maybe that is easier to promote.
- mirimir 11y agoNobody paying attention uses their ISP's DNS servers. See https://www.wikileaks.org/wiki/Alternative_DNS https://www.wikileaks.org/wiki/Alternative_DNS Also, good VPN services run their own DNS servers, which are reachable only through the VPN tunnel. See https://dnsleaktest.com/ https://dnsleaktest.com/ to determine which DNS server(s) you're using.
- 46Bit 11y ago> Nobody paying attention uses their ISP's DNS servers. Very few people, as a proportion of the population, are paying attention.
- mikeash 11y agoI must not be paying attention. Is there a quick summary of why I shouldn't use my ISP's DNS servers?
- stegosaurus 11y agoSecurity: they can hijack requests (BT does this in the UK to censor requests to certain domains). I believe some ISP's intercept all queries on port 53. Privacy: your ISP has a log of the DNS queries you've made. (of course, they have a log of the IP addresses you've made HTTP/HTTPS requests to, so that may be less relevant).
- Laforet 11y ago>I believe some ISP's intercept all queries on port 53. I'd say most ISPs do it nowadays including some datacentre providers. I only noticed it when my ISP screwed up their DNS proxy making all Cloudflare domains inaccessible no matter which DNS server I point queries to, the packets simply disappear down a black hole.
- mirimir 11y agoISPs block port 53? Where, might I ask? Good reason to use a VPN, I guess.
- Laforet 11y agoVodafone New Zealand. They did not block port 53 per se, merely redirecting everything to their proxy. https://dnsleaktest.com/what-is-transparent-dns-proxy.html https://dnsleaktest.com/what-is-transparent-dns-proxy.html
- arca_vorago 11y agoWhat we really neednis DNSCurve. CRypt is full of problems from what I hear. All hail djb.
- achernya 11y agoThat is not sufficient -- TLS Server Name Indication (SNI) is still cleartext in the handshake.
- kjaer 11y agoWouldn't HSTS preloading solve that?
- therealmarv 11y agotrue, but as I said in another comment here: It will not hide the websites you are visiting. This is also a problem in the article... a secure DNS will not make you invisible it is only slightly harder to track the websites you are visiting. All IPs you are visiting can still be transformed through a reverse DNS and you will get all website addresses. And Chrome cannot be use dnscrypt by default. It uses UDP ports which are sometimes closed on other networks. So there are technical limitations. Even using another DNS than the network one is often not allowed (you will experience that if you travel often). Also some people will not like using a Google DNS by default ;)
- dmichulke 11y agoIMHO this would still be a huge step because the URL path after the hostname reveals very specific information relative to the host (say, pornhub or webmd)