4 ms·
Round-robin and privacy do not dwell well together. Like mike-cardwell pointed out in another comment, it just distributes the same information to more parties
by madisfun 7y ago
Round-robin and privacy do not dwell well together. Like mike-cardwell pointed out in another comment, it just distributes the same information to more parties.
As there has to be at least party which will know the request, some information will be leaked. But what can be prevented, is giving "unrelated" requests in the hands of the same resolver. Few of the request per se are interesting, the combinations of them allow to build user profiles.
The policy should not be round robin, but somehow based on the domain itself, so that all requests about the same domain go to the same resolver, but to nobody else.
An even better mechanism would take into account who is the owner and the controller of the domain. So that requests about, let say, facebook.com and fbsbx.com land at the same resolver, but github.com and microsoft.com by another.
- mercora 7y agothis is more or less what happens if you have an recursive resolver. in most cases your queries will be seen by the same network that will see your traffic afterwards anyways. only the TLD nameservers will somewhat occasionally depending on the TTL know which network you are about to enter and they are arguably more trustworthy. I think about this way: i already trust whichever infrastructure provider my endpoint uses and the choice of nameservers is an extension to that.