1 Mar
2017
1 Mar
'17
3:13 a.m.
DNS-over-TLS (RFC 7858) is important for privacy but, today, few DNS resolvers support it. It would be interesting to measure if this is changing, but the probes do not seem to be able to query their resolver with TLS over port 853. (Also, I seem to remember that old probes do not have a full TLS implementation.) It is not just a matter of encrypting the data, it's also an authentication issue (Google Public DNS was already impersonated <http://bgpmon.net/turkey-hijacking-ip-addresses-for-popular-global-dns-providers/>) So, how about adding a 'use_tls': True after 'use_probe_resolver': True?