Re: dns over tls or https

Axel Beckert <[email protected]>
Newsgroups gmane.comp.web.dillo.devel
Organization DeuxChevaux.org -- The Citr oën 2CV Database
Message-ID <[email protected]>
Hi,

On Mon, Oct 07, 2019 at 09:06:30AM -0600, [email protected] wrote:
> > On Mon, Oct 07, 2019 at 07:25:20AM -0600, [email protected] wrote:
> > > Wouldn't it be great if dillo could do dns over tls (or second best
> > > dns over https)
> >
> > DNS is not the browser's job but the operating system's job. So no, it
> > wouldn't be great. One of Dillo's features is to be lean. It should
> > stay that way.
>
> you might want to research what dns over tls or https is before you
> say misinformation

Ehm, I know very well what DoH and DoT are. I even run DoT enabled
authorative DNS servers.

I though get the feeling that you are not aware of what implications
DNS resolution directly in applications has. I strongly recommend
watching this talk from the Chaos Communication Camp 2019:
https://media.ccc.de/v/Camp2019-10213-doh_or_don_t (No it's not
con-DoH. But it's also not pro-DoH. It shows all the problems it
solves and causes.)

Nevertheless, I don't see any misinformation in the statement that DNS
resolving is a job of the operating system and not of any end-user
application.

Any DNS resolving inside an application can — depending if
application-specific DNS servers are used — causes tons of problems like
not caring about deliberately set search domains or name servers, not
being able to resolve organization-internal (intranet) host names,
leaking nearly everything you do on the internet to external service
providers you can't control, etc. (At least that's the case with DoH
in Firefox unless you configured your very own DoH server.)

Of course also the organization-internal DNS caches could provide DoT
or DoH. This still does not give a reason to do DNS lookup inside an
application instead of using the OS-wide resolver.

		Kind regards, Axel
-- 
PGP: 2FF9CD59612616B5      /~\  Plain Text Ribbon Campaign, http://arc.pasp.de/
Mail: [email protected]  \ /  Say No to HTML in E-Mail and Usenet
Mail+Jabber: [email protected]  X
https://axel.beckert.ch/   / \  I love long mails: https://email.is-not-s.ms/

_______________________________________________
Dillo-dev mailing list
[email protected]
http://lists.dillo.org/cgi-bin/mailman/listinfo/dillo-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.