3 ms·
DoH typically encrypts the connection between the client and the recursive DNS server, and TLS is reasonably suitable for this because the client is always quer
by zrm 3y ago
DoH typically encrypts the connection between the client and the recursive DNS server, and TLS is reasonably suitable for this because the client is always querying the same server and can keep the connection open or use session resumption. DNSCurve is designed to encrypt the request between the recursive and authoritative DNS server, where the requests go to all different authoritative nameservers and the TLS handshake is correspondingly slow/heavy.
Is there any technical problem with DNSCurve or is it just a technology with low current adoption, like source port randomization before the Kaminsky attack?
- tptacek 3y agoThe "go to market" story for DNSCurve involves it solving some of the problems DoH solves (see "Why DNSCurve" under "For DNS Users" on Bernstein's page). It's had minimal adoption over 15 years, and the case for it has weakened, not improved, since then.
- zrm 3y agoIt can solve the same problem, but it also solves it better. If you're using DoH to e.g. Cloudflare, Cloudflare can still see all of your DNS queries. If your own local device operated recursively using DNSCurve to the authoritative servers, there is no such third party intermediary who could be compromised or betray you. Moreover, it could also be used to encrypt the queries between Cloudflare and the authoritative servers for the people doing that. The lack of adoption is mainly that authoritative nameserver operators have no incentive to spend resources on encrypting DNS unless their customers demand it, but the lesson from this should be to demand that your DNS provider support it.
- tptacek 3y agoYes. It doesn't matter. These are marginal problems. The major adversary for DNS privacy is ISPs, and DoH neatly solves it. AWS and DO aren't (probably can't, in fact) sniffing DNS traffic to generate marketing data feeds). Betamax was better than VHS.