3 ms·
I really hope this doesn't catch on widely. It should be a tool for use where censorship issues can't be solved politically. Otherwise, why even have protocol
by alien_at_work 9y ago
I really hope this doesn't catch on widely. It should be a tool for use where censorship issues can't be solved politically.
Otherwise, why even have protocols at all? Just say the only protocol is HTTP. IP, etc. are just an HTTP implementation detail.
- banachtarski 9y agoI would love this to catch on wildly! DNS through TLS means it's all end-to-end encrypted, DNS reflection attacks are harder, etc. The "why even have protocols" doesn't make sense. Protocol can be layered just fine (HTTP itself is a good example). DNS as it exists now is another random special snowflake that vendors need corresponding snowflake implementations for.
- alien_at_work 9y ago>DNS through TLS means it's all end-to-end encrypted I didn't say I'm against DNS being encrypted, even with TLS. I just hate that instead of doing the right thing (e.g. political battle with the government, opening a port on a firewall) people choose the laziest way: just tunnel it over HTTP. >Protocol can be layered just fine (HTTP itself is a good example) They can, but why do it? Just figure out a way to make your server be yet-another-"REST"-service and pat yourself on the back for cleverness. >DNS as it exists now is another random special snowflake that vendors need corresponding snowflake implementations for. As is: SMTP, POP, IMAP, SSH, AMQP, FIX, SWIFT, LDAP, ODBC and a host of other protocols. Why do you use negative language like "random special snowflake that vendors need corresponding snowflake implementations for"? These are seperate protocols, which serve seperate specific needs. This is how IP was designed to work.
- BenjiWiebe 9y agoI guess someone just needs to do a VPN over HTTP. (Probably done already too)
- gkya 9y agoPolitical battles are hard to do, and take time, sometimes very very long times they take.
- alien_at_work 9y agoI don't disagree at all. But I don't find this sufficient justification to engage in poor engineering practices. DNS has a different set of use cases than HTTP so, while it can be made to work with enough effort (anything can), HTTP can never be as good at DNS as an actual protocol designed to do DNS can.
- banachtarski 9y agoYes as a protocol designer, I couldn't care less about the type of data that runs through the protocol. The semantics are much more important. Sequenced delivery with hard requirements on delivery order and reliability? Probably should be TCP based. Something that gives something different would be RTP (specialized for sending media packets which aren't useful after a certain time has elapsed) or SCTP or UDP.
- deleted 9y ago[deleted]
- qznc 9y agoWhy do we have ports at all? Except 80 and 443 many ports are blocked anyways. I'd say there is an arms race between admins and users. Step by step features get forbidden and blocked usually in the name of security. For example, NAT took away your globally visible IP address. The next step is probably blocking domains. In a dystopian vision, Google and Facebook become the proxies for all traffic as all other domains get blocked for most users.