Quick question about DNS and DoH that I thought about after reading this post:

https://packmates.org/@[email protected]/111176886781705659

Wouldn’t it make sense for Firefox or another third party to bundle and transparently forward all DoH requests to cloudflare so that:

A) Cloudflare doesn’t know who made what request due to not knowing the origin

B) Firefox doesn’t know who made what request due to TLS

#Infosec #Privacy
CC: @privacyguides

  • peregus@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 months ago

    The TTL nowadays is about 3600 seconds, so I think that at about that rate your DNS server would flush stored entries every hour one by one and ask to 9.9.9.9 an update. That’s basically how every DNS server works (and I guess that even the ones embedded in router’s works like that with caching). Is your setup different? If yes, in which way? Thanks

    • phanto@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 months ago

      I set it up a long time ago, so I don’t honestly remember. I followed some guide, and did a few domain redirects to point at stuff on my home network and to shut Zuck out of my life, but I didn’t do anything crazy. So, I doubt it, but I don’t know.