3 ms·
Forget the encryption; alter the protocol to support overfetching. (Instead of fetching a specific site, you fetch blocks of sites). In a naive version, you'd
by dmayle 6y ago
Forget the encryption; alter the protocol to support overfetching. (Instead of fetching a specific site, you fetch blocks of sites). In a naive version, you'd ask for every site from goodreads.com through to google.com, and then the client would actually visit the site it wanted. In a hardened protocol, I'd imagine you'd use hashing, along with a random salt so that there are many different ways to query the same site.
Right now, your DNS provider has a list of every website you visit (just not how many times you visited it). The shorter the DNS cache, the more closely this list matches your browsing behavior.
This definitely complicates the protocol, whether you put the burden at the resolver layer (needs larger cached) or at the level of authoritative servers (where'd they be effectively cooperating with root servers), but it's the only way to truly safeguard browsing data.
- textmode 6y ago"Instead of fetching a specific site, you fetch blocks of sites." I have been doing this for many years, putting bulk DNS data in HOSTS and personal use zone files served from loopback addresses. It is easier than ever today with so many sources of bulk DNS data. DOH now lets users retrieve DNS data from recursive DNS servers (caches) in bulk, using HTTP/1.1 pipelining. Here is a working example: https://news.ycombinator.com/item?id=23242389 https://news.ycombinator.com/item?id=23242389 Many years ago, I started doing non-recursive (no caches used) bulk DNS data retrieval for speed and also for resiliency in the event of outages. However the privacy gains are obvious. A rough analogy is downloading all of Wikipedia in bulk and browsing articles offline as opposed to making separate requests online for each article and generating all the requisite DNS and TCP/HTTP traffic. Openmoko's Wikireader experimented with the idea of offline Wikipedia. Not only does the DOH provider get a record of all the user's DNS lookups, she can now associate each request with the particular user program/device that made it.