'The inmates have taken over the asylum': DNS godfather blasts DNS over HTTPS adoption

Thoughts?

Source: theregister.co.uk/2018/10/23/paul_vixie_slaps_doh_as_dns_privacy_feature_becomes_a_standard/

Attached: 2 048.jpg (1010x673, 193.19K)

Other urls found in this thread:

download.dnscrypt.info/dnscrypt-resolvers/v2/opennic.md
twitter.com/SFWRedditImages

how is this going to affect retarded average joe like me? all dns will goes using https, then what?

t.systemd user

Attached: mmm.jpg (184x184, 11.26K)

consider the average DNS packet vs the average HTTPS connection handshake and response.

We're talking a 1000x bloat on all website name lookups.

...

If we're doing dns over http, does that mean that a compromised CA can issue whatever responses to dns queries they want? Sounds like its good for gov and bad for hackers.

Also,

...

How would would it be good for CIA niggers?

Yes.

DNS rebind attacks to compromising material.

All five eyes partners have root certificate access, meaning this would allow mass DNS harvesting which is perfectly "legal".

so the debate is whether we should have black box dns or filtering program
thats terrible set of choices

Does anyone use DNSCrypt here? Can anyone suggest good servers?
Fucking OpenNIC is unreliable so I'm basically stuck with CloudFlare.

KIKES JUST CAN'T STOP WINNING

ns7.nh.nl.dns.opennic.glue
This one has been working reliably for me for years.

So why is this exactly an issue? From my understanding, the people in the article are complaining that they won't be able to monitor DNS requests themselves anymore. Well, that's the fucking point.

DoH is like putting the address label for a package on the inside of the box. It affords some privacy but it also makes the postman's job difficult if not impossible in the event that the shipment process has a hiccup.

DoT would not have this problem, but it won't work unless all post offices support it.

ThisIsFine.jpg

Attached: dns_discussion.jpg (1000x699, 108.49K)

Suicide is the only option now.

OpenNIC is fine, you just need to do a little research and maybe have a few backup choices. Having a local resolver like dnsmasq helps. OpenNIC have a dynamic dns aggregator for emergencies.

Knowledge is its own reward, and the time spent is a small price to pay for having greater control over your computing.

By this they mean anyone that might oppose Google.

Safe to say Google won the war on the internet. We're fucking fucked. We shouldn't have doubted the blackpill faggot.

You can probably set up a public/private key pair for encryption purposes.

this defeats the purpose though, and the browsers will likely reject it. I have never successfully gotten chromium to accept a self-signed certificate, at least I can still bypass the warning page, but I'm sure at some point they will remove that option too and pozfox will follow.

right now literally everything caches dns queries, the router, your browser, your system (systemD or dnsmasq if you have that setup), this eliminates all that caching except for the browser. is this what they propose?

https is also a resource hog on a lot of routers. i don't think most cheap routers would be able to handle https/dns even if you could generate a self signed certificate and the browser accepted it.

to see what i mean about https being a resource hog on routers try switching the admin page to https on dd-wrt/open-wrt/tomato, click around a few status pages and look at the load. now switch to http and look at the load difference. https just doing the admin page can load 50% of the cpu, imagine this with DNS and constant queries, the router will lock up.

The issue I had is that the resolvers from here download.dnscrypt.info/dnscrypt-resolvers/v2/opennic.md tend to be unreachable more often than I'd like to.

It should be optional for the purposes of managing an internal network without installing software or changing settings on each individual computer. Great as a way to communicate outside of the intranet, but keep the inside open. Yes I know there are ways around having DNS over https in the network, but those require significant change and money.

Seriously why the fuck

What are you waiting for then?

When was the last update?

Attached: 952.jpg (628x314, 30.54K)

...

...