Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-11 Thread Owen DeLong
> On Mar 11, 2020, at 19:25 , Jan Schaumann wrote: > > Owen DeLong wrote: > >> DOH isn?t inherently bad, but every implementation >> of DOH that I am aware of involves depriving the >> user of choice and/or control > > I don't think that's quite correct. > > There is an unfortunate and

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-11 Thread JASON BOTHE via NANOG
The enterprise as well. I’m certain many are blindly unaware as this could have negative impacts beyond traditional control. J~ > On Mar 11, 2020, at 20:43, Owen DeLong wrote: > >  > >> On Mar 11, 2020, at 18:31 , Rubens Kuhl wrote: >> >> >> >>> On Tue, Mar 10, 2020 at 5:30 PM Owen

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-11 Thread Jan Schaumann
Owen DeLong wrote: > DOH isn?t inherently bad, but every implementation > of DOH that I am aware of involves depriving the > user of choice and/or control I don't think that's quite correct. There is an unfortunate and persistent conflation of "DoH" with "DoH to a centralized third-party

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-11 Thread Owen DeLong
> On Mar 11, 2020, at 18:31 , Rubens Kuhl wrote: > > > > On Tue, Mar 10, 2020 at 5:30 PM Owen DeLong > wrote: > For anyone considering enabling DOH, I seriously recommend reviewing Paul > Vixie’s keynote at SCaLE 18x Saturday morning. > >

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-11 Thread Rubens Kuhl
On Tue, Mar 10, 2020 at 5:30 PM Owen DeLong wrote: > For anyone considering enabling DOH, I seriously recommend reviewing Paul > Vixie’s keynote at SCaLE 18x Saturday morning. > > https://www.youtube.com/watch?v=artLJOwToVY > > It contains a great deal of food for thought on a variety of forms

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-11 Thread Scott Weeks
--- o...@delong.com wrote: From: Owen DeLong For anyone considering enabling DOH, I seriously recommend reviewing Paul Vixie’s keynote at SCaLE 18x Saturday morning. https://www.youtube.com/watch?v=artLJOwToVY It contains a great deal of food for thought on a variety of forms of giving

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2020-03-10 Thread Owen DeLong
For anyone considering enabling DOH, I seriously recommend reviewing Paul Vixie’s keynote at SCaLE 18x Saturday morning. https://www.youtube.com/watch?v=artLJOwToVY It contains a great deal of food for thought on a variety of forms of giving control over to corporations over things you

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-27 Thread Curtis Maurand
powerdns dnsdist supports dns over https so you don't have to be held hostage by cloudflare or google. On 9/18/19 10:19 AM, Mike Hammett wrote: Why on Earth would anyone want that (Firefox deciding to do it's own DNS) as default behavior? - Mike Hammett Intelligent Computing

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-18 Thread John Levine
In article <8580e3e4-98b8-2828-e43f-6115c92fa...@massar.ch> you write: >Currently though: > >use-application-dns.net. 172800IN NS >ns-cloud-b1.googledomains.com. >use-application-dns.net. 172800IN NS >ns-cloud-b2.googledomains.com. >use-application-dns.net.

RE: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-18 Thread Keith Medcalf
t;To: Jeroen Massar >Cc: NANOG >Subject: Re: DNS Recursive Operators: Please enable QNAME minimization >(RFC7816) for the enhanced privacy of your users > >Why on Earth would anyone want that (Firefox deciding to do it's own DNS) >as default behavior? > > > > >- &

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-18 Thread Matt Corallo
Because getting each ISP in the world to comply with NSA monitoring requests was too hard, instead they get to centralize the full list of every website the everyone in the world visits on a single fleet of servers in Cloudflare's datacenters. This means we only need to compromise one person to

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-18 Thread Mike Hammett
Why on Earth would anyone want that (Firefox deciding to do it's own DNS) as default behavior? - Mike Hammett Intelligent Computing Solutions Midwest Internet Exchange The Brothers WISP - Original Message - From: "Jeroen Massar" To: "NANOG" Sent: Wednesday, September

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-18 Thread Jeroen Massar
On 2019-09-18 12:24, Brian J. Murrell wrote: > On Wed, 2019-09-18 at 09:15 +0200, Jeroen Massar wrote: >> Hi Folks, > > Hi. > >> While in the US soon all Firefox users will *NOT* use your DNS >> Recursives configured using DHCP anymore >> (NXDOMAIN use-application-dns.net to avoid that[1]). > >

Re: DNS Recursive Operators: Please enable QNAME minimization (RFC7816) for the enhanced privacy of your users

2019-09-18 Thread Brian J. Murrell
On Wed, 2019-09-18 at 09:15 +0200, Jeroen Massar wrote: > Hi Folks, Hi. > While in the US soon all Firefox users will *NOT* use your DNS > Recursives configured using DHCP anymore > (NXDOMAIN use-application-dns.net to avoid that[1]). What am I misunderstanding? Isn't use-application-dns.net