26 ms·
With a goal being to circumvent tracking I wonder why DNSSEC was used instead of DoH DNS over HTTPS?
by emptybottle 5y ago
With a goal being to circumvent tracking I wonder why DNSSEC was used instead of DoH DNS over HTTPS?
- sfshaw 5y agoWe need to better define exactly who's tracking we need to get around. I agree that DoH is a better solution to being tracked by your ISP.
- tssva 5y agoDNSSEC and DoH DNS over HTTPS serve completely different purposes. There isn't a choice to be made between them. DNSSEC sole purpose is to validate the integrity of DNS records. DoH DNS over HTTPS protects DNS requests and responses in flight but does nothing to validate that the DNS record returned was actually created by the domain owner. The author of the article states they don't care about tracking of requests by their ISP, so they don't bother to implement in flight protection of DNS.
- emptybottle 5y agoDon't you think it's a bit backwards to deploy pihole to prevent trackers, while being ok with your DNS traffic being tracked? Agreed though, the DoH recursor should use DNSSEC in actual DNS upstream queries. IMO you want to use both.
- BizarroLand 5y agoIs there a good guide for how to set that up?
- emptybottle 5y agoA dnscrypt-proxy or similar tutorial is probably a good starting point
- tssva 5y agoI do agree but my point wasn't about what I think but the thought process of the author.