Hacker News new | past | comments | ask | show | jobs | submit login

Encryption is nice, but does it have to be the overhead of HTTP? What would be a sensible alternative protocol?



DNSCrypt or RFC7858 (dprive) are probably closest equivalents.


I suppose it could also be implemented with DTLS [0] over UDP [1]. (Checking Wikipedia...) A 2013 paper [2] published some vulnerabilities; mostly implementation flaws, but it raised some questions about the core spec as well.

However you implement it, encrypting DNS probably has it's place, but it doesn't make a whole lot of sense for most applications.

[0] https://en.wikipedia.org/wiki/Datagram_Transport_Layer_Secur...

[1] https://tools.ietf.org/html/rfc6347

[2] http://www.isg.rhul.ac.uk/~kp/dtls.pdf





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: