HN Top New Show Ask Jobs

settings

Theme

Hand Mode

Feed

Comment by xenophonf

Comment by xenophonf 10 months ago

2 replies

View on Hacker News

DNSSEC is an authentication mechanism. It does not encrypt queries or responses.

You might be thinking of DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT).

There's also DNSCurve.

https://en.wikipedia.org/wiki/DNSCurve

no-dr-onboard 10 months ago

DoH and DNSSEC don't use ECH (encrypted client hello)

From what I remember, only DoT uses ECH

https://media.ccc.de/v/chaoscolloquium-1-dns-privacy-securit...

Reply View | 1 reply
  • SubzeroCarnage 10 months ago

    ECH can be used regardless of DoT, DoH, dnscrypt, or plain as long as your resolver passes HTTPS queries.

    You can easily test this: dig @8.8.8.8 https pq.cloudflareresearch.com

    Reply View | 0 replies