4 ms·
I’ve never understood the purpose of DOH. It doesn’t really hide your traffic from any party, does it?
by surround 6y ago
I’ve never understood the purpose of DOH. It doesn’t really hide your traffic from any party, does it?
- floatingatoll 6y agoIt encrypts your DNS traffic over the public wire in a way that only the DOH endpoint operator can decrypt, preventing plaintext interception/modification attacks by unauthorized malicious actors positioned between you and the DOH endpoint It represents your DNS traffic over the wire as encrypted HTTPS traffic, which decreases the effectiveness of deep packet inspection and traffic shaping systems operated by some network providers. When hosted at heavily-used CDN endpoints that receive other (non-DOH) HTTPS traffic, it requires a network provider who wishes for whatever reason to block your DNS traffic to block all HTTPS traffic to all CDN endpoints.
- beezle 6y agoOK sure but what good is that when my next TCP/UDP activity after a dns lookup is to actually connect to that host? The upstream ISP knows exactly where you are going right? They can store and reverse that info and do with it as they wish.
- SheinhardtWigCo 6y agoAn IP address is often less specific than a hostname, and will become less useful over time due to IPv4 address space exhaustion and concentration of internet services among a small number of cloud providers. Widespread use of DOH therefore makes it harder for ISPs and middleboxes to interfere without collateral damage. It's far from perfect, but it'll help.
- Santosh83 6y agoProvided we get eSNI everywhere too, or it is easy for middlemen to sniff out your actual hostname even though the IP may be shared with thousands/millions of other hosts.
- SheinhardtWigCo 6y agoYep, I’m assuming that will happen eventually.
- pabs3 6y agoYou might want to read this study on that topic: "What can you learn from an IP?" https://irtf.org/anrw/2019/slides-anrw19-final44.pdf https://irtf.org/anrw/2019/slides-anrw19-final44.pdf
- SheinhardtWigCo 6y agoInteresting reference, thanks. I’m surprised there are so many site-unique IPs. Fingerprinting is less compelling in the case of blocking (I think?) but is certainly still a privacy problem. Ultimately, all security is about raising the cost for attackers, and I think it’s a good thing that DOH will make middleboxes more expensive and less accurate. It would be a mistake to pitch it as being even close to a perfect solution to any problem, though.
- deleted 6y ago[deleted]
- Nemo_bis 6y agoThat's unclear to me. By running DoH, Comcast gets to spy Comcast customers. But Comcast of course can already see what IP addresses talk with Comcast customers, so what changes really? That the spying might become marginally easier maybe?