18 ms·
Why not just send the subnet of the machine at cloudflare doing the querying?
by codexon 7y ago
Why not just send the subnet of the machine at cloudflare doing the querying?
- akerl_ 7y agoThe full IP of the Cloudflare resolver doing the recursive resolution is already provided to the authoritative server, as the source IP for the DNS query traffic.
- shawnz 7y agoI think the parent is saying, why not spoof the EDNS client subnet information?
- deleted 7y ago[deleted]
- akerl_ 7y agoTrue. Copying the information would be possible, but given they’re working on other efforts to replace the functionality of EDNS ECS in a standard way, it seems like a hacky bandaid.
- manigandham 7y agoEDNS is a working system today, doesn't seem that hacky to use it until a new system is actually ready (which doesn't seem to be anytime soon anyway).
- slenk 7y agoIt works if you don't care about privacy
- manigandham 7y agoThe suggestion was to use the EDNS of the datacenter server, how does that ruin privacy?
- zamadatix 7y agoIs there anywhere I can learn about these ongoing efforts to replace EDNS?