4 ms·
Preventing the target resolver from seeing client's IP address breaks GeoDNS. This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet
by jamescun 6y ago
Preventing the target resolver from seeing client's IP address breaks GeoDNS. This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension.
Given generally DNS is just the start of an intereaction, usually followed by the connection directly between the client and intended destination, I don't see what kind of snooping these privacy measures are there to prevent.
- deleted 6y ago[deleted]
- ignoramous 6y agoValid points, but... > Preventing the target resolver from seeing client's IP address breaks GeoDNS. If the proxy and the target are in the same metro as the user, it shouldn't really matter. > This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension. 1.1.1.1 runs at Cloudflare's edge. Most likely it is recursing DNS from more or less the same location as the user and so ECS isn't really required when in fact it exposes the client unnecessarily to upstream name-servers. > I don't see what kind of snooping these privacy measures are there to prevent. The one where DNS resolvers build to sell browsing profile of its users?
- snarf21 6y agoAren't these DNS resolvers largely the ISP anyway? They know where any packets are going anyway for each user. Seems to be a trivial hurdle to jump.
- deleted 6y ago[deleted]
- mike_d 6y ago> If the proxy and the target are in the same metro as the user, it shouldn't really matter. Having ran one of the largest public DNS resolvers on the internet, I can tell you it is a big problem. GeoIP providers do not have the fine grained data to be able to tell that a resolvers unicast address is in Seattle vs Chicago for example. Cloudflare doesn't care about edns-client-subnet because the only downside is that other CDNs appear slower to their users.
- absolutelyrad 6y agoAs I see this, this is a very clever move by Cloudflare. It's intentional to force websites to move to their CDN or atleast use a CDN with anycast and prevent you from making your own CDN like you could cheaply before (spinning up DO droplets and doing loadbalancing with geo DNS).
- jgrahamc 6y agoThat's a weird take. (a) this is a proposed standard not just some Cloudflare service and (b) you can just use Cloudflare DNS if you want and forget about the rest.
- ignoramous 6y agoIt'd have been fabulous if Cloudflare ran ODoH Proxy too.
- snarf21 6y agoEncrypted DNS only solves hi-jacking, it doesn't provide privacy. DNS must be public. It is trivial to run a DNS server to build a simple reverse lookup table. This is as much privacy as the TSA provides airline security.
- GoblinSlayer 6y agoThe DNS server is centralized storage of all your browsing habits.
- baskire 6y agoThus increasing the cloudflare value-prop of anycast based load balancing.
- jsmith45 6y ago> I don't see what kind of snooping these privacy measures are there to prevent. The point of this is to prevent some cloudflare competitor offering DoH, but logging what dns names each client looks up, and selling that information, or using it internally. Think about the ways that facebook would abuse that information if facebook ran a popular DoH resolver. For example, they detect that you have used a hookup app (based on dns lookups for their servers), and boom, now your facebook feed is full off condom adverts. Or thousands of other scenarios, some even more creepy than that.
- fulafel 6y agoGeoDNS was always a "works most of the time" hack relying on some widespread (but not universal) implementation details in routing and DNS infrastructure, no?
- judge2020 6y ago> which doesn't honour the EDNS client subnet extension. background: https://news.ycombinator.com/item?id=19828702 https://news.ycombinator.com/item?id=19828702