3 ms·
dnscurve is a way to encrypt DNS packets between an authoritative DNS server and a client (or if you prefer, a cache). CurveDNS is an implementation of dnscurv
by textmode 10y ago
dnscurve is a way to encrypt DNS packets between an authoritative DNS server and a client (or if you prefer, a cache).
CurveDNS is an implementation of dnscurve.
dnscurve protects the integrity of packets from tampering. That's all it does. Encryption of packets on a per packet basis.
(For example, there are people running shared DNS caches that rewrite users' DNS queries with varied information -- without the users knowing about it.)
dnscurve does not provide for "authentication". The protocol cannot tell the user who is running an authoritative DNS server. A user could use ed25519 ssh keys for that.
"DNSCrypt" was a project from a company that makes money by running shared DNS caches and filtering domains, serving ads, and who knows what else. Now they are part of Cisco.
There is nothing about dnscurve that forces anyone to use a shared DNS cache.
A user can run their own personal DNS cache on the loopback.
Moreover, a user can query dnscurve compatible authoritative servers (e.g. running CurveDNS) directly using a dnscurve compatible stub resolver. Non-recursive queries.
That's all I know. I might be wrong.