2 ms·
Let's take the case that it's a local machine - on your local network - acting as the ODNS Stub. The DNS request is then encrypted from your machine to the tru
by deaps 8y ago
Let's take the case that it's a local machine - on your local network - acting as the ODNS Stub. The DNS request is then encrypted from your machine to the trusted ODNS Stub - but then from that ODNS Stub out to some resolver on the internet, there exists the DNS query (whether encrypted or unencrypted) - sourced from your same public IP that your machine would have sourced it from in the first place, correct?
I'm certain I don't understand the entirety of ODNS - but the basics still have to exist - something still needs to make a query on behalf of the initial user to some authoritative server (unless the answer is already cached). I guess, what I'm picturing in this case, is that if the trusted resource (ODNS Stub) exists in your local infrastructure, then the source outgoing to the internet might as well just be your local machine in the first place - because that's how 'the internet' sees it anyway.
Anyway, I'm all for making DNS more secure...and this seems to be one way to change where your trust lies, but not a definitive solution, to me.
- deleted 8y ago[deleted]
- detaro 8y ago> The DNS request is then encrypted from your machine to the trusted ODNS Stub No. The stub is doing the encryption and sending the encrypted query to a resolver in the internet. > but then from that ODNS Stub out to some resolver on the internet, there exists the DNS query (whether encrypted or unencrypted) Yes. But since it's encrypted, the resolver only knows that I have made a DNS request, not what the query is in it. The resolver can't decrypt it, it can only pass it on to a server that can decrypt it, but won't be able to see your source IP then. I think they overstate the usefulness against the kind of attacker they describe though, since such a powerful adversary could correlate across servers.