4 ms·
The article mentions preventing ISPs from knowing which websites you visit, but won't they still know the IP address of the server you access? Given that websit
by Wehrdo 9y ago
The article mentions preventing ISPs from knowing which websites you visit, but won't they still know the IP address of the server you access? Given that websites have relatively static IPs, doesn't that make it trivial to map back to a domain? Sorry if I'm completely misunderstanding the situation.
- chrissnell 9y agoYes, unless you are using a VPN or Tor, the IP of the site you're connecting to is present in every TCP/UDP/ICMP packet you send out. For some sites that are hosted on big virtual host IPs with dozens/hundreds of sites being served from the same IP, it's slightly more vague. For big sites where there is a 1:1 relationship between website and IP, there is no question about what you're visiting.
- detaro 9y agoNo, you are not misunderstanding it. (they don't even have to match the IP in most cases, since the domain is in the request you send) The main value of protected DNS is in stopping the provider or some other middleman from changing the DNS responses you get, not in hiding your requests.
- Ajedi32 9y agoBut if you're connecting to a site using HTTPS, would it even matter if a middleman changed the DNS response? If they respond with the IP of the wrong server, you'll just get a certificate error. And if you're not using HTTPS, they don't need to mess with DNS responses; they can serve you any content they want over any URL.
- annabellish 9y agoUnless the host you're connecting to has some kind of certificate pinning in play, typing `example.org` into your browser will make the initial request in the clear, which can be hijacked even if it immediately bounces you to https.
- Ajedi32 9y agoThat's true even if the DNS response isn't hijacked though, which was the point of my second paragraph.
- cryptonector 9y agoDNSSEC does that too...
- detaro 9y agoI thought DNSSEC only has value when the queried domain has it enabled, but I might be confusing things?
- md_ 9y agoYou're correct. DNS-over-TLS secures you<-->resolver; DNSSEC secures validating-resolver<-->authority, essentially. If your resolver is validating, then it secures you<-->authority. Point being DNSSEC can be used to secure more hops than DNS-over-TLS, but DNS-over-TLS can secure the last hop without any opt-in by the domain owner.
- cryptonector 9y agoWell, yes, but it'd be nice to get to where it's universally enabled. EDIT: Also, DNSSEC gives you something the ohter things don't: authenticated data, including authenticated non-existence. That's a big deal. Of course, DJB's DNS encryption would also give you privacy. Add DANE and drop SNI and you'd have privacy protection, especially if PTR RRs had nothing useful or weren't used at all for the sites you visit.