|
|
|
|
|
by Asseon
2890 days ago
|
|
Right now there are no benefits though.
Because the browser sends the domainname you contact unencrypted via the TLS handshake due to SNI. So someone listing in to your communication will learn the hostname anyway. I know people are working on encrypted SNI but that will take time. |
|
Assume a large entity willing to do some mass surveillance (NSA, ...). Now with unencrypted DNS this entity just has to MITM a link on the last hop of a few DNS providers (Google, Cloudflare) and voila, the IP's of the clients and the domains visited are pouring in.
With encrypted DNS, for an entity to get the same amount of information they need to MITM a much larger amount of links.
Though I agree the benefits are clearly limited, the idea is to eliminate all weak links. If there are 2 broken windows in your house and you can fix one - why not do it?