5 ms·
Why would it leak terms to the DNS in plaintext? Aren't most DNS servers encrypted between the client and server? I know that's true for DNS over HTTPS but I th
by rgrmrts 3y ago
Why would it leak terms to the DNS in plaintext? Aren't most DNS servers encrypted between the client and server? I know that's true for DNS over HTTPS but I thought it was generally true as well these days
- packetlost 3y agohahaha no. You have to go out of your way to use DNS-over-HTTPs or DNSSEC.
- jeroenhd 3y agoDNSSEC only provides signatures, it doesn't encrypt your queries. How much you need to go out if your way depends. Firefox enables DoH by default in some areas, for example. Windows and Chrome will try to use it if your DNS server of choice supports it (i.e. if you've set up 1.1.1.1 or 8.8.8.8). Android has Private DNS enabled by default, I believe. Some manufacturers may turn it off, I don't remember the setting my devices shipped with.
- packetlost 3y agoOh! I always thought DNSSEC was encrypted, thanks for the correction
- 8organicbits 3y agoI believe DoH rollout is still ongoing. The last I see from Chrome is https://blog.chromium.org/2020/05/a-safer-and-more-private-browsing-DoH.html https://blog.chromium.org/2020/05/a-safer-and-more-private-b... and the last I see from Firefox is https://support.mozilla.org/en-US/kb/firefox-dns-over-https https://support.mozilla.org/en-US/kb/firefox-dns-over-https Those changes are driving up the adoption rate, but it's not complete. I suspect most DNS is still unencrypted at this point, but I can't confirm.