4 ms·
that's why you use dnscrypt-proxy
by feld 10y ago
that's why you use dnscrypt-proxy
- iAm25626 10y agoRight; but in the article the author mentioned using DNSSEC as a way to gain privacy. Just want to point that out.
- xvolter 10y agoCorrect. I recommended the use of DNSCrypt first specifically for this reason. DNSSEC alone primarily helps prevent DNS spoofing, phishing, and MITM attacks. All useful, but DNSCrypt gives you encrypted DNS queries. Maybe I should have clarified this more.
- tptacek 10y agoDNSSEC doesn't prevent DNS spoofing attacks, at least not the kind that occur in the real world. DNSSEC is a server-to-server protocol. From client to server (like with the requests from your browser to your ISP's DNS server, or to Google's DNS server, or whatever you use), there is no cryptography whatsoever protecting the requests. Just a single bit in the header, saying that someone else did the cryptography for you.