2 ms·
Using DNSCrypt would help. Sadly if your after privacy, domain names are exposed in plain-text within the HTTPS request itself.
by CommanderData 10y ago
Using DNSCrypt would help. Sadly if your after privacy, domain names are exposed in plain-text within the HTTPS request itself.
- jug5 10y agoHow is that of any benefit then? I had no idea about that
- tptacek 10y agoHuh? https://github.com/jedisct1/dnscrypt-proxy/blob/master/DNSCRYPT-V2-PROTOCOL.txt https://github.com/jedisct1/dnscrypt-proxy/blob/master/DNSCR... Oh! Sorry! I misread your comment. Yes: HTTPS can leak hostnmes.
- mh- 10y ago[..] domain names are exposed in plain-text within the https request. Only if your handshake negotiates to use SNI.
- deleted 10y ago[deleted]
- hsivonen 10y agoSNI is sent even if the server ignores it.
- EvilTerran 10y agoAnd even if your client software doesn't use SNI... the server has to send you the cert before an authenticated encrypted channel can be established, so the cert's snoopable - and has the domain name in it.
- knome 10y ago> domain names are exposed in plain-text within the https request Which exposes nothing more than the previous solution of having one ip per https domain, which made it just as obvious what domain you were connecting to. Putting the domain in the request allowed people running the servers to host any number of sites from the same ip. A convenience for the operators that exposed nothing new for the consumers.
- egh5oon 10y agoDNSCrypt still leaks your DNS queries to the legitimate resolvers. DNSCrypt over Tor helps (unless all your traffic is sent only over Tor) but I'm not seeing tools to do this around.