Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What exactly do you use DNS for? If it's to subsequently make a HTTP and/or HTTPS request, then your full IP address (and not just a /24 subnet) will be leaked to the very same parties anyways.

Even if they eventually make DNS encrypted, even if encrypting TLSv1.3 SNI work properly (and both of these are pretty big ifs, BTW), the IP addresses will still leak, always, and with a much higher precision anyways. So, this we-don't-do-ECS-because-privacy is hardly a rational statement on Cloudflare's part in the end — it merely breaks the performance of their competitor CDNs without any real privacy angle.



DNS isn't always run by the place the site is hosted and until the other 2 are implemented everyone along the lookup path can also see where you are going. Increasingly a destination IP is becoming less of a hint of what you are browsing to.

Whether you think that's enough to care about or not it's very different than the picture you painted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: