|
|
|
|
|
by firebird84
2041 days ago
|
|
What's the issue with having TLS-based authoritative lookups? I know it seems out of scope for what Mozilla's asking, but it seems like the missing piece of the puzzle to me. It's great if your recursive resolver is trusted (maybe you trust cloudflare or nextdns), but what if you don't trust anyone and want to run your own TRR? From what I can see from my own TRR the queries to authoritative DNS are sent in the clear...
Edit On further thought, I realize that querying myanimememes.com's authoritative DNS CAN reveal which site you're interested in, but I believe most sites delegate their authoritative DNS these days to third parties. |
|
https://mailarchive.ietf.org/arch/msg/dns-privacy/Fv91jt_n2-...
https://github.com/fanf2/draft-dprive-adot