4 ms·
Can someone please help me understand something please? I understand that the main feature of 1.1.1. is privacy from the ISP, however, after the DNS resolution
by odedregev 8y ago
Can someone please help me understand something please? I understand that the main feature of 1.1.1. is privacy from the ISP, however, after the DNS resolution when my device will actually go to the destination, lets say to www.example.com domain - my ISP will know about this too, so what exactly am I hiding here?
- Gaelan 8y agoMany sites these days are hosted on cloud services not owned by the company owning the site, and in these cases it can fairly hard to find the actual domain from the IP address. In other cases, however, you’re right—the ISP can still figure out where you’re going.
- homero 8y agoEncrypted sni will add some plausible deniability
- nly 8y agoIIRC, a prerequisite for the confidentiality of eSNI is in fact secure DNS.
- tialaramex 8y agoYou need that your adversary can't snoop your DNS queries (which DoH and other DPRIVE offerings provide) and if the adversary is active you also need DNSSEC with validation so that the adversary can't lie to your DNS provider and say eSNI isn't available. Cloudflare do both
- dingaling 8y agoI think this is mainly a USian mindset. I trust my UK ISPs ( Goscomb, AA.net ) to whom I pay a monthly fee for service more than I do some US-based company who wants to provide me a critical service for 'free'. And yet which at other times prevents me reaching websites with a 'One more step...' blocker page.
- kasey_junk 8y agoIn conjunction with tls your ISP loses the ability to know the domain. IP then becomes the thing they can track but in many cases that will just route to big IP blocks for hosting providers. Having netflix.com is a lot more revealing than having an AWS block.