-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 2011-07-28 23:57, intrigeri wrote: > Anders wrote (28 Jul 2011 21:02:24 GMT) : >> Another option, one that I'm considering for the Haven OS, is to use >> the unbound dns server with a patch that forces it to only send tcp >> traffic. That way all dns requests are sent over tor and since we >> are doing the name resolution our selves, there is no need to rely >> on any one open dns server. This way we can also resolve every type >> of query (even DNSSEC stuff). > > It means doing the recursive resolution process ourselves (I mean, > from inside the Live system itself), right?
Yes, that's the plan. I've tested it and performance isn't really all that bad. About 2sec for root, tld, and a subdomain (in a completely unscientific test). One possible concern is that the tld owners could use statistical methods to track a user across different exits if she performs lookups for many related and uncommon domains. Regards, Anders -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJOMmpeAAoJEKM+ps8RdIYNhVIIAKV1k1v+969ZLlwNr5TJXBA4 mghJOPn0DCYdE/FqaHtujkFAIb0WZLc9RVWCB3HfndOYEiyItEXD21RH8UCdG4jL 70ZA0vy/MtYw+aSIS0S3Cl8AWi9R+iKczY9CgsTKlEbm/NV7fPW0CIBXbzz4DA8q LZ7KIFGTsXm8m/fGiIdQ5GUfM9iWMz2FaKmf5w8v+UAPxURelID2lmKc73yxXB+s gQlVAhqkrR9jc8QCOCyD7hSlBkF825LhCwiJAz44dooLy8sAS7UnCTEWEJ3+aHLT jUZgUtH9zwpsv3sKBXKjZUkqvKP6ZplcL7q7H3Lk74cg4itUV4FllBJCV4EhlRQ= =7TXU -----END PGP SIGNATURE----- _______________________________________________ tails-dev mailing list [email protected] https://boum.org/mailman/listinfo/tails-dev
