Re: dns over tls or https

[email protected]
Newsgroups gmane.comp.web.dillo.devel
Message-ID <[email protected]>
always suspect response when you prune from my repsonse the things that disprove what you claimed

it is the browsers job when i uses dns in clear text - and should be using encrypted dns

https://www.zdnet.com/article/how-to-enable-dns-over-https-doh-in-firefox/
https://www.chromestory.com/2019/06/dns-over-https/




On Mon, 7 Oct 2019 17:51:18 +0200
Axel Beckert <[email protected]> wrote:

> Hi,
>
> On Mon, Oct 07, 2019 at 09:06:30AM -0600, [email protected] wrote:
> > > On Mon, Oct 07, 2019 at 07:25:20AM -0600, [email protected] wrote:
> > > > Wouldn't it be great if dillo could do dns over tls (or second best
> > > > dns over https)
> > >
> > > DNS is not the browser's job but the operating system's job. So no, it
> > > wouldn't be great. One of Dillo's features is to be lean. It should
> > > stay that way.
> >
> > you might want to research what dns over tls or https is before you
> > say misinformation
>
> Ehm, I know very well what DoH and DoT are. I even run DoT enabled
> authorative DNS servers.
>
> I though get the feeling that you are not aware of what implications
> DNS resolution directly in applications has. I strongly recommend
> watching this talk from the Chaos Communication Camp 2019:
> https://media.ccc.de/v/Camp2019-10213-doh_or_don_t (No it's not
> con-DoH. But it's also not pro-DoH. It shows all the problems it
> solves and causes.)
>
> Nevertheless, I don't see any misinformation in the statement that DNS
> resolving is a job of the operating system and not of any end-user
> application.
>
> Any DNS resolving inside an application can — depending if
> application-specific DNS servers are used — causes tons of problems like
> not caring about deliberately set search domains or name servers, not
> being able to resolve organization-internal (intranet) host names,
> leaking nearly everything you do on the internet to external service
> providers you can't control, etc. (At least that's the case with DoH
> in Firefox unless you configured your very own DoH server.)
>
> Of course also the organization-internal DNS caches could provide DoT
> or DoH. This still does not give a reason to do DNS lookup inside an
> application instead of using the OS-wide resolver.
>
> 		Kind regards, Axel
> --
> PGP: 2FF9CD59612616B5      /~\  Plain Text Ribbon Campaign, http://arc.pasp.de/
> Mail: [email protected]  \ /  Say No to HTML in E-Mail and Usenet
> Mail+Jabber: [email protected]  X
> https://axel.beckert.ch/   / \  I love long mails: https://email.is-not-s.ms/
>
> _______________________________________________
> Dillo-dev mailing list
> [email protected]
> http://lists.dillo.org/cgi-bin/mailman/listinfo/dillo-dev

_______________________________________________
Dillo-dev mailing list
[email protected]
http://lists.dillo.org/cgi-bin/mailman/listinfo/dillo-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.