3 ms·
Haha Big ISPs...there’s absolutely no reason why regular HTTP requests/responses should be TLS encrypted while DNS queries should not...they go hand in hand for
by deckarep 7y ago
Haha Big ISPs...there’s absolutely no reason why regular HTTP requests/responses should be TLS encrypted while DNS queries should not...they go hand in hand for maintaining end-user privacy and YOUR integrity.
- GhettoMaestro 7y ago"Going blind" is a term I've heard recently when talking with operators. Where as "going dark" referred to the DOJ/FBI's term for ubiquitous encipherment of the content, "going blind" refers to the metadata (DNS in this case). My view is pretty basic: If I can see your DNS, I can pretty much guess on a very short list what kind of [browsing] behavior you are engaging in.
- joewee 7y agoYou don’t have to guess. You can actually see it. What you can infer is why and who. Which is the real danger. I would trust google to protect sensitive data like sexual preferences before I trust my ISP.
- GhettoMaestro 7y agoIt all depends how much is abstracted behind a common host (eg name based virtual hosting). I can see you are going to Google. But I don't know what within Google you are really accessing or using in most cases.