Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Valid points, but...

> Preventing the target resolver from seeing client's IP address breaks GeoDNS.

If the proxy and the target are in the same metro as the user, it shouldn't really matter.

> This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension.

1.1.1.1 runs at Cloudflare's edge. Most likely it is recursing DNS from more or less the same location as the user and so ECS isn't really required when in fact it exposes the client unnecessarily to upstream name-servers.

> I don't see what kind of snooping these privacy measures are there to prevent.

The one where DNS resolvers build to sell browsing profile of its users?



> If the proxy and the target are in the same metro as the user, it shouldn't really matter.

Having ran one of the largest public DNS resolvers on the internet, I can tell you it is a big problem. GeoIP providers do not have the fine grained data to be able to tell that a resolvers unicast address is in Seattle vs Chicago for example.

Cloudflare doesn't care about edns-client-subnet because the only downside is that other CDNs appear slower to their users.


Aren't these DNS resolvers largely the ISP anyway? They know where any packets are going anyway for each user. Seems to be a trivial hurdle to jump.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: