2 ms·
>Running your own resolver will give the authoritative servers the ip address of the request, but does this leak any assets to any potential attacker? The owner
by _null_ 8y ago
>Running your own resolver will give the authoritative servers the ip address of the request, but does this leak any assets to any potential attacker? The owner behind the authoritative servers already get the web logs so what additional information is being leaked.
This is addressed in the panel. The argument is that there is some "privacy mixing" because owner of the authoritative server only sees a highly-trafficked resolver as the source, and not your home network resolver.
- belorn 8y agoYes, the authoritative server get less data from the DNS server but the owner of the domain already get the information from web server logs and similar sources. I do not see how dns mixing provide any privacy in any common threat model. In the first case a client that request a webpage contact company X authoritative server with private information [IP ADDRESS], creating a record on the DNS server, and then visit company X web server creating a second record at the same company with the same [IP ADDRESS]. In the second case a client request a webpage of company X by contacting google, creating a record on google DNS server with [IP ADDRESS], and then visits company X and create a record there with [IP ADDRESS]. In one case one company has the data, and in the second case two companies has the data. It does not make any sense.