Hacker News new | ask | show | jobs
by qa-tari 1291 days ago
Combining encrypted DNS and TLS 1.3 with encrypted handshakes, there's a reasonable cause for deniability which service you have accessed even if you can never hide the resolved IP address.
1 comments

Even better would be to use ODoH(3), that way not even your local resolver can know who resolved what. Let's just hope TLS ECH and the rest takes off before the legislation against it.
Or anonymized DNSCrypt, which is far more deployed and reliable.
More deployed and reliable, right now. The possibility of blending in with all the rest of H/3 traffic alone is a good reason to work on (O)DoH3.