3 ms·
It's about security. It keeps intermediate hops from hijacking your query and providing their own response. Unfortunately, it offers no privacy. DNS is usually
by DistractionRect 4y ago
It's about security. It keeps intermediate hops from hijacking your query and providing their own response.
Unfortunately, it offers no privacy. DNS is usually the precursor to a tls connection, and the domain name is sent in cleartext during the tls handshake. So the same people who would hijack your DNS queries are still privy to them if you use DoH (routers, ISPs, governments, etc).
- pabs3 4y agoDoT/DoH only stops one hop of the DNS resolution process from hijacking requests, so it isn't as good as DNSSEC for security. There is encrypted TLS handshaking for hiding the TLS domain name indicator. https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
- duskwuff 4y ago> ... so it isn't as good as DNSSEC for security. And DNSSEC doesn't provide any privacy to the end user. Both mechanisms provide something of value, and ideally they'd both be used together.