3 ms·
Why did they change the name to ODoH?
by raywu 5y ago
Why did they change the name to ODoH?
- bandie91 5y agoas i read they add an extra TLS/HTTPS layer to ODNS traffic in order to pipe dns query yet an other party. first TLS gets unwrapped, then forwarded to ODNS resolver, so the DOH provider sees who (which IP/netblock) queries but not what; and the ODNS sees what is queried but not by whom. my problem with it is that DOH and ODNS providers are altough intended to be separate entities, but it's not guaranteed and eventhough they are, they can still share data off-band. and this obscurity in DNS won't stop ISPs to spy on what sites user visits, based on bare IP connections pattern, see https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an-ip-address/ https://blog.apnic.net/2019/08/23/what-can-you-learn-from-an... of course if all of the Internet would be behind aws/cloudflare CDN then this method won't be so effective for ISPs.
- raywu 5y agoInteresting. Thanks for sharing your take. This is new to me so I really appreciate it