-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi,
On 2011-07-26 23:47, intrigeri wrote: > [...] > What we really want instead is: query Tor resolver first, fallback to > ttdnsd if the former fails. This is possible using Tor 0.2.2.x. That sounds like a reasonable solution. But there is probably no harm in waiting and sticking with DNSPort until the 0.2.2 stable is out. The only reason I even consider it worth while using some thing other than DNSPort in the long run is to get DNSSEC working. Using ttdnsd won't solve this though. Getting MX and SRV (for XMPP) is nice, and ttdnsd fixes this, but it's not really an instant must have. Another option, one that I'm considering for the Haven OS, is to use the unbound dns server with a patch that forces it to only send tcp traffic. That way all dns requests are sent over tor and since we are doing the name resolution our selves, there is no need to rely on any one open dns server. This way we can also resolve every type of query (even DNSSEC stuff). I'm not quite sure what the anonymity implications are of doing it like this, so it will need some more thought. But this might be something to consider for the future. Best regards, Anders -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJOMc5YAAoJEKM+ps8RdIYNgJwH/1sccSf6H8XOSh2Kf9qHGEgT EJ9AnoDRNiVHGgNoe58Z61JyH8z/sb9YGAEsQ7YW7WRFiOoiIyRefFt60esEzOR4 CWxkFCJY9AdWfNdxPjMcMHjkAT2lRYwTmn4uXV5dTJPxRw4pm18y0n8Ly5cI3soO onMYHCI6i3YU0A4H8LDCKpcZ/4eWVWjt6f6TIUtrE2AKVEU6IASCbSVLDnTB/Epb uvcNcffXOgEvhvhQawNZsLIBb9MW9km8rHMJF9kYIPt9mbZSvcTUwx8Mn4pRArun eThSKN4YHwL2myp1aeFhJHerqgoKPSxj+Ld9fh6jTWbIIpyETtTMgUsIRkXroH4= =iqxu -----END PGP SIGNATURE----- _______________________________________________ tails-dev mailing list [email protected] https://boum.org/mailman/listinfo/tails-dev
