3 ms·
> Is there any other serious argument against encrypting DNS? In DNS over HTTPS, requests are still going to a single, potentially untrustworthy entity. Encryp
by gnode 7y ago
> Is there any other serious argument against encrypting DNS?
In DNS over HTTPS, requests are still going to a single, potentially untrustworthy entity. Encryption by itself only offers privacy against eavesdroppers, and can give a false sense of security to the unaware. Although not a fault of the technology, people in the EU have been encouraged / defaulted to use DoH provided by US companies on the grounds of privacy, where data privacy law in their own countries may be relatively strong.
I think we should be working towards DNS with a stronger privacy model than DNS over HTTPS. There is no need for centralised resolvers which get to see who are making which requests. Name resolution is a service which could be provided by a distributed network, with authority provided by cryptographically signed records.