On 20 Jan 2016, at 11:51, Marek Isalski <[email protected]> wrote:
>> On 20 Jan 2016, at 11:45, Simon Lockhart <[email protected]> wrote:
>> How would you, as a service provider, capture this information, assuming you
>> have no DPI capability at the moment?
>
> Log all the queries to provider's recursive DNS resolvers.
>
> Then customers switch to using 8.8.8.8, OpenDNS, etc, instead of the ISP's
> own. So Google has to do the logging, but also providers are compelled to
> trivially DPI all UDP/TCP port 53 and log that.
>
> Then every customer deploys DNSCrypt and providers' DPI becomes expensive,
> and a battle of costs begins between ISPs and the Home Office.
Any middle box is expensive and I love how people think encryption solves these
problems! But in this scenario I'd wager "ISPs lose battle on costs with the
home office" would be the outcome.
Neil
>
> Marek Isalski
> AS41495
>
>