3 ms·
>The company Cloudflare has a publicly accessible DNS at the address 1.1.1.1 that they claim is encrypted and secure. For it to be "encrypted and secure", the
by renholder 8y ago
>The company Cloudflare has a publicly accessible DNS at the address 1.1.1.1 that they claim is encrypted and secure.
For it to be "encrypted and secure", the client would have to be configured to use DNSSEC, yeah? As far as I'm aware, most clients don't come with DNSSEC enabled (in OOBE configurations), so isn't this a bit misleading?
- xfitm3 8y agoI don’t think so. Instead you would want DoH (dns over https). DNSSEC is designed to protect against MiTM and is not really effective at anything else.
- renholder 8y agoFair enough. Cloudflar's promotional site for 1.1.1.1 seems to tout DNSSEC pretty heavily and only mentions DoH once, I believe. Still, clients still need to be configured for DoH, yeah?
- xfitm3 8y agoCorrect - third party software is needed (as far as I know) for DoH.
- acdha 8y agoYou do need client support but these days that’s not uncommon: Android Pie, Chrome, Firefox, and curl all have built-in support and there are apps for iOS and Android, and once you’ve enabled it it will work almost everywhere. I believe most clients default to dual resolution so it won’t break if you’re on a network which interferes (e.g. a ton of Cisco captive portals used that address in error) unless you’ve enabled hard-fail mode.
- tptacek 8y agoDNSSEC doesn't encrypt DNS traffic at all. "Encrypted and secure" DNS presumably refers to DoH, which doesn't rely on DNSSEC.