3 ms·
> What does encrypted/authenticated DNS gain you? Many things, here's three to start: * A measure of privacy - instead of every rando with ability to sniff pa
by packet_nerd 7y ago
> What does encrypted/authenticated DNS gain you?
Many things, here's three to start:
* A measure of privacy - instead of every rando with ability to sniff packets (activities you have no way to ever know about, available to many parties along the path) only the DNS server (which you choose, presumably trust, and can change) knows what names you resolve.
* Stronger foundation for TLS - LetsEncrypt and other public certificate authorities depend on DNS to issue certificates. If an attacker controls DNS, they could easily generate certificates for any site they wanted to attack.
* There have been many shady incidents with certificate authorities. I just feel that beefing up some of the other layers in the stack is a good idea.
> faking DNS responses just results in a connection that is closed immediately
On the web it's often not closed immediately, the users often get a certificate warning that they may be conditioned to click through. Of course HSTS helps with that, but still... why the hostility to securing the name resolution layer?