4 ms·
Cloudflare and Apple design a new privacy-friendly internet protocol
- musicale 5y agoIt may be more accurate to say that Cloudflare and Apple seem to have implemented ODNS: https://odns.cs.princeton.edu https://odns.cs.princeton.edu
- raywu 5y agoWhy did they change the name to ODoH?
- bandie91 5y agoas i read they add an extra TLS/HTTPS layer to ODNS traffic in order to pipe dns query yet an other party. first TLS gets unwrapped, then forwarded to ODNS resolver, so the DOH provider sees who (which IP/netblock) queries but not what; and the ODNS sees what is queried but not by whom. my problem with it is that DOH and ODNS providers are altough intended to be separate entities, but it's not guaranteed and eventhough they are, they can still share data off-band. and this obscurity in DNS won't stop ISPs to spy on what sites user visits, based on bare IP connections pattern, see https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an-ip-address/ https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an... of course if all of the Internet would be behind aws/cloudflare CDN then this method won't be so effective for ISPs.
- raywu 5y agoInteresting. Thanks for sharing your take. This is new to me so I really appreciate it
- atonse 5y agoBravo. This is likely what they’re using for the iCloud+ privacy enhanced browsing features they announced yesterday.
- Lammy 5y ago> Dubbed Oblivious DNS-over-HTTPS, or ODoH for short, the new protocol makes it far more difficult for internet providers to know which websites you visit. > Here’s how it works: ODoH wraps a layer of encryption around the DNS query and passes it through a proxy server, which acts as a go-between the internet user and the website they want to visit. A proxy server provided by Apple or Cloudflare? That sounds a lot less private than what I have now honestly.
- ThePowerOfFuet 5y ago> A proxy server provided by Apple or Cloudflare? That sounds a lot less private than what I have now honestly. You're not the target demographic; it's a hell of a lot more private than >90% of their user base has now.
- brnt 5y agoFor US users.
- ThePowerOfFuet 5y agoFor almost everyone, especially given that it's double-hop and neither hop knows both the user and the traffic.
- brnt 5y agoISPs are not allowed to do what this concern addresses in most of Europe.
- ThePowerOfFuet 5y agoIt's not just the ISP; web sites won't get the client's true IP either, further stymying user tracking via IP correlation.
- 5y ago
- bandie91 5y agoi'm wondering how does it compare to CurveDNS. once the root nameservers (or at least the TLD NSes) support curvedns, the ISPs won't see what the users query or the dns answer, only the IPs of the NSes the users queries. it maybe give some insight for ISPs to know approximately which domain names users look up, but "big corp" ODNS and DOH provides won't get this info. and eventhough, ISPs still have a better resolution on what sites the user visits based on bare IP traffic (see https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an-ip-address/ https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an... ). IMO to minimize even that info that which NS IPs users query, zone and NS admins should cooperate to have as many secondary NS per zone as possible, even at 3rd party NS providers AND sign zones by DNS-SEC to prevent tampering at 3rd party NSes. in this ways the zone–to–nameserver-ip mapping becomes a many–to–many relation which ISPs can not rely on.