3 ms·
I'd personally prefer to be greeted with a screen providing me with the option of multiple DNS-over-HTTPS providers, and the option of not using one at all, tha
by jamescun 7y ago
I'd personally prefer to be greeted with a screen providing me with the option of multiple DNS-over-HTTPS providers, and the option of not using one at all, than being silently forced into handing CloudFlare even more of my data.
- josteink 7y agoHow about to save time, we could have this choice only once, and that would apply to every application on the machine. Say it could even be handled by the OS itself! And to save users even more time, not having to configure this per machine, we could have such assignment be an automatic part of the network infrastructure... We could call it DHCP and DNS! How about it?
- testis321 7y agoAnd DNSSEC all the way to the user!
- tptacek 7y agoI'd be pretty pissed if my network connection opted me into a DNSSEC-verifying resolver, since that is pretty much pure downside for users.
- josteink 7y agoAs someone not very knowledgable about DNSSEC, can you expand on this point? To the uninformed that sounds very counterintuitive.
- wolf550e 7y agoHis blog post: https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- tptacek 7y agoApart from the blog post, if you don't know anything about DNSSEC, I think the things you want to know are: 1. Almost nobody --- major tech companies, banks, privacy and security organizations --- uses it. It's decades old, and its adoption, at least in North America and in industry, is zero. There are lots of reasons, but you don't have to care right now. 2. Since almost nothing uses it, there's no real upside to enabling it. But there is a downside! If DNSSEC is misconfigured --- which is easy to do, and it won't get noticed quickly (see: point 1) --- then sites in the DNSSEC-signed zone silently drop off the Internet, as if they never existed. That happened, for instance, to HBO when they launched HBO NOW: nobody on Comcast could see it, because it turned out they'd screwed up DNSSEC, and Comcast had DNSSEC-verifying resolvers.