3 ms·
It can solve the same problem, but it also solves it better. If you're using DoH to e.g. Cloudflare, Cloudflare can still see all of your DNS queries. If your o
by zrm 3y ago
It can solve the same problem, but it also solves it better. If you're using DoH to e.g. Cloudflare, Cloudflare can still see all of your DNS queries. If your own local device operated recursively using DNSCurve to the authoritative servers, there is no such third party intermediary who could be compromised or betray you. Moreover, it could also be used to encrypt the queries between Cloudflare and the authoritative servers for the people doing that.
The lack of adoption is mainly that authoritative nameserver operators have no incentive to spend resources on encrypting DNS unless their customers demand it, but the lesson from this should be to demand that your DNS provider support it.
- tptacek 3y agoYes. It doesn't matter. These are marginal problems. The major adversary for DNS privacy is ISPs, and DoH neatly solves it. AWS and DO aren't (probably can't, in fact) sniffing DNS traffic to generate marketing data feeds). Betamax was better than VHS.