Hacker News new | ask | show | jobs
by red0point 2896 days ago
Of course there are benefits.

Assume a large entity willing to do some mass surveillance (NSA, ...). Now with unencrypted DNS this entity just has to MITM a link on the last hop of a few DNS providers (Google, Cloudflare) and voila, the IP's of the clients and the domains visited are pouring in.

With encrypted DNS, for an entity to get the same amount of information they need to MITM a much larger amount of links.

Though I agree the benefits are clearly limited, the idea is to eliminate all weak links. If there are 2 broken windows in your house and you can fix one - why not do it?