On Fri, Jan 15, 2016 at 11:31:09AM +0500,
 Tariq Saraj <[email protected]> wrote 
 a message of 80 lines which said:

> Unfortunately plaintext is known,

As I said, it is not. You can sometimes *guess* some of the questions
and answers (it is safe to assume that the user's machine will query
google-analytics.com at least from time to time), it does not give you
the full plaintext (query ID, for instance). And, as Shane explained
(you should have read it), modern crypto is not vulnerable to
"known-plaintext attacks".

> I am going to work on it once I complete the confidentiality
> implementation

May I suggest that you learn some crypto first, as well as reading RFC
7626 and the other DPRIVE documents? Check also the implementations
(there are several of DNS-over-TLS, as well as the nonstandard
DNScrypt).



_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to