-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 2011-07-28 23:57, intrigeri wrote:
> Anders wrote (28 Jul 2011 21:02:24 GMT) :
>> Another option, one that I'm considering for the Haven OS, is to use
>> the unbound dns server with a patch that forces it to only send tcp
>> traffic. That way all dns requests are sent over tor and since we
>> are doing the name resolution our selves, there is no need to rely
>> on any one open dns server. This way we can also resolve every type
>> of query (even DNSSEC stuff).
> 
> It means doing the recursive resolution process ourselves (I mean,
> from inside the Live system itself), right?

Yes, that's the plan. I've tested it and performance isn't really all
that bad. About 2sec for root, tld, and a subdomain (in a completely
unscientific test).

One possible concern is that the tld owners could use statistical
methods to track a user across different exits if she performs lookups
for many related and uncommon domains.

Regards,
Anders
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJOMmpeAAoJEKM+ps8RdIYNhVIIAKV1k1v+969ZLlwNr5TJXBA4
mghJOPn0DCYdE/FqaHtujkFAIb0WZLc9RVWCB3HfndOYEiyItEXD21RH8UCdG4jL
70ZA0vy/MtYw+aSIS0S3Cl8AWi9R+iKczY9CgsTKlEbm/NV7fPW0CIBXbzz4DA8q
LZ7KIFGTsXm8m/fGiIdQ5GUfM9iWMz2FaKmf5w8v+UAPxURelID2lmKc73yxXB+s
gQlVAhqkrR9jc8QCOCyD7hSlBkF825LhCwiJAz44dooLy8sAS7UnCTEWEJ3+aHLT
jUZgUtH9zwpsv3sKBXKjZUkqvKP6ZplcL7q7H3Lk74cg4itUV4FllBJCV4EhlRQ=
=7TXU
-----END PGP SIGNATURE-----
_______________________________________________
tails-dev mailing list
[email protected]
https://boum.org/mailman/listinfo/tails-dev

Reply via email to