Conversation

DNS-over-TLS does have the advantage of a lighter and more efficient implementation but DNS-over-HTTPS doesn't add any substantial attack surface in practice as long since it's already present. Using regular HTTPS traffic over port 443 also makes it more censorship resistant.
1
1
They could improve the Tor network by asking people to opt-in to being a relatively low bandwidth relay. As long as the DNS server is a hidden service, it wouldn't put more burden on exit nodes which is the main bottleneck largely because it's so risky to run one in practice.
1
2
I don't think it will actually end content blocking, because they can move on to having their blocking maintain a list of IP addresses refreshed from DNS instead. It makes things harder and in many cases there will be some collateral damage due to centralization like Cloudflare.
1
Similarly, they can still see the IP being connected to and in many but not all cases that's as good as seeing the domain name. The collateral damage can deter some of the blocking but I don't think it stops it in general. For IPv6, there's also generally not IP reuse like that.
1
Show replies