3 ms·
Or you could use dnscrypt so ISP doesn’t see your lookups at all
by abcdefg12 3mo ago
Or you could use dnscrypt so ISP doesn’t see your lookups at all
- Bender 3mo agoWhen all the authoritative servers support TLS I can enable TLS outbound but very few of them do at the moment. At some point someone is decrypting, turtles all the way down. I could of course just do DoT to another instance of Unbound somewhere else but I do not need to do that as my ISP does not care about my queries. I used to keep standby DoT Unbound servers around but I have never once seen a US ISP tinker with my traffic. If they did I would put up billboards saying they what they are doing.
- abcdefg12 3mo agoThere is a bunch of public dnscrypt servers to which your client can randomly fan out encrypted queries.
- Bender 3mo agoThere are but I will wait until all the authoritative resolvers support TLS. If I wanted to hide my traffic from my ISP then I would just use DoT from my firewall Unbound instance to a few Unbound instances I already have around the web.
- abcdefg12 3mo ago« I’ll keep my house door open until there is a really secure lock installed ». You either care about tampering and snooping or you don’t.
- Bender 3mo agoI understand your concerns. I personally do not share these concerns though I did when I resided in California that is for sure. I know just about everyone at my ISP. I know where many of them live. We all live in the same small tight knit community. They tried really hard to get me to join their network team.
- aand16 3mo agoYours is not particularly problematic but I've always wondered how come advertising agencies allow highly controversial topics on their billboards in the US. I know some (all?) EU advertisers deny creatives based on optics i.e. "our name and logo is on the billboard frame, we don't wanna get associated with topic X".
- aand16 3mo agoDuring the TLS handshake, you send the domain name in clear text (Server Name Indication - SNI extension) so that the hoster can present the correct certificate for that domain. Nothing prevents the ISP from collecting that.
- ekr____ 3mo agoHence Encrypted Client Hello (https://datatracker.ietf.org/doc/rfc9849/ https://datatracker.ietf.org/doc/rfc9849/), though deployment is still thin.