3 ms·
The argument that because encryption can be used for nefarious purposes it should not be offered by DNS providers at all does not add up. ISPs can block, redire
by flarex 7y ago
The argument that because encryption can be used for nefarious purposes it should not be offered by DNS providers at all does not add up. ISPs can block, redirect and sell DNS traffic and many are already doing some or all of these.
- JohnFen 7y agoI don't think anybody is arguing that DNS lookups shouldn't be encrypted. The issue is doing DNS lookups via HTTPS.
- DaniloDias 7y agoI’m specifically arguing that dns lookups should not be encrypted. Dns can be descriptive: ntp.example.com sounds like an Ntp server. Oh- this pcap shows an ntp flow afterwards. Probably synchronizing time. Oh- adnetwork.example.com. Probably serving up ads. Oh Agrrvxdrgkndzzzvbbhydsxxjjj.net.org.com. Probably botnet related. Vs I need to look at every protocol flow and sort by IP? Who in their right mind blindly trusts all computers like this? If you ever want to troubleshoot your network, your job becomes way more tedious if dns requests are encrypted.