Philip Homburg <[email protected]> writes:

> In this draft it lists Privacy with LocalRoot as 'Complete'. But from a
> resolver point of view that is not true because queries get sent to TLDs,
> SLDs, etc. Overall privacy protection is very far from complete.

Quick reminder: the draft was written *only* from the perspective of
communicating with the RSS.  I agree completely that for queries sent
elsewhere it doesn't help (though you can do caching of other zones just
as easily in most implementations, and in fact my localroot.isi.edu
project also offers you root-servers.net and arpa by default).

(see the IMRS root server top domain list for all the types of non-TLD
queries that leak to the root -- many have argued these are far greater
than what might leak to a TLD.)
-- 
Wes Hardaker
Google

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to