3 ms·
It offers privacy too. With encrypted DNS, you can only see that the source IP is making a request to the destination IP, not what type of request or what it co
by manigandham 4y ago
It offers privacy too. With encrypted DNS, you can only see that the source IP is making a request to the destination IP, not what type of request or what it contains.
If the source device then connects to whatever IP was in the answer, and you have that IP mapped, then you can reveal what they might be connecting to, but that requires more data and processing compared to plaintext DNS and still won't reveal the actual encrypted traffic.
With shared IPs from CDNs, hosting providers, and VPNs, it provides far more obfuscation for the average user.
- TurningCanadian 4y agoThere's still TLS Server Name Indication leaking the hostname.
- manigandham 4y agoSNI can be encrypted in an extension of TLS 1.3 called ESNI (encrypted server name indication). With both EDNS and ESNI, there's sufficient privacy coverage. The next standard is ECH (encrypted client-hello) which secures the entire handshake: https://blog.cloudflare.com/encrypted-client-hello/ https://blog.cloudflare.com/encrypted-client-hello/
- gsich 4y agoIs it still in draft state?
- manigandham 4y agoYes: https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-15 https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-15