4 ms·
well there is dnscrypt. i use a local cache for fast revisits. ya i'm not sure everyone having full dns servers would be a good thing or even practical.
by reshie 8y ago
well there is dnscrypt. i use a local cache for fast revisits. ya i'm not sure everyone having full dns servers would be a good thing or even practical.
- js2 8y agoDNSCrypt only provides authentication, not confidentiality, and it’s only between the client and the recursive server. So it doesn’t address either the performance or the privacy concern of routing all your DNS through someone else’s recursive servers. Edit: apparently it encrypts traffic as well: https://dnscrypt.info/faq/ https://dnscrypt.info/faq/ So it’s comparable to DoH which prevents your ISP from snooping but per my other comments here doesn’t address the privacy concern of now having to trust the upstream resolver.
- ryan-c 8y agoAre you sure you're not thinking of DNSCurve? It doesn't provide confidentiality, but AFAICT DNSCrypt does.
- js2 8y agoYou’re right. I went of the Wikipedia page for it which says: DNSCrypt wraps unmodified DNS traffic between a client and a DNS resolver in a cryptographic construction in order to detect forgery. Though it doesn't provide end-to-end security, it protects the local network against man-in-the-middle attacks. https://en.wikipedia.org/wiki/DNSCrypt https://en.wikipedia.org/wiki/DNSCrypt But according to dnscrypt.info it’s encrypted.
- zrm 8y agoDNSCrypt and DNSCurve both provide confidentiality (and are very similar to each other). The thing that doesn't provide confidentiality is DNSSEC.
- Panino 8y agoDNSCurve does provide confidentiality, using x25519-xsalsa20poly1305.