-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

On 2011-07-26 23:47, intrigeri wrote:
> [...]
> What we really want instead is: query Tor resolver first, fallback to
> ttdnsd if the former fails. This is possible using Tor 0.2.2.x.

That sounds like a reasonable solution. But there is probably no harm in
waiting and sticking with DNSPort until the 0.2.2 stable is out.

The only reason I even consider it worth while using some thing other
than DNSPort in the long run is to get DNSSEC working. Using ttdnsd
won't solve this though. Getting MX and SRV (for XMPP) is nice, and
ttdnsd fixes this, but it's not really an instant must have.

Another option, one that I'm considering for the Haven OS, is to use the
unbound dns server with a patch that forces it to only send tcp traffic.
That way all dns requests are sent over tor and since we are doing the
name resolution our selves, there is no need to rely on any one open dns
server. This way we can also resolve every type of query (even DNSSEC
stuff).

I'm not quite sure what the anonymity implications are of doing it like
this, so it will need some more thought. But this might be something to
consider for the future.

Best regards,
Anders
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJOMc5YAAoJEKM+ps8RdIYNgJwH/1sccSf6H8XOSh2Kf9qHGEgT
EJ9AnoDRNiVHGgNoe58Z61JyH8z/sb9YGAEsQ7YW7WRFiOoiIyRefFt60esEzOR4
CWxkFCJY9AdWfNdxPjMcMHjkAT2lRYwTmn4uXV5dTJPxRw4pm18y0n8Ly5cI3soO
onMYHCI6i3YU0A4H8LDCKpcZ/4eWVWjt6f6TIUtrE2AKVEU6IASCbSVLDnTB/Epb
uvcNcffXOgEvhvhQawNZsLIBb9MW9km8rHMJF9kYIPt9mbZSvcTUwx8Mn4pRArun
eThSKN4YHwL2myp1aeFhJHerqgoKPSxj+Ld9fh6jTWbIIpyETtTMgUsIRkXroH4=
=iqxu
-----END PGP SIGNATURE-----
_______________________________________________
tails-dev mailing list
[email protected]
https://boum.org/mailman/listinfo/tails-dev

Reply via email to