Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Sen. Wyden Requests Probe into Sale of DNS Query Data [pdf] (senate.gov)
79 points by barathr on Dec 15, 2022 | hide | past | favorite | 6 comments


With my colleagues I've been advocating for a decoupled approach to achieve security/privacy for network services like DNS, which we built a demo of earlier this week and wrote about a bit here -- the gist is that there's no reason to hand over your personal stream of DNS queries to a DNS resolver because you can divide the information across multiple parties:

https://invisv.com/articles/dns.html

(The timing is coincidental -- we didn't realize Wyden was looking into this very issue and was going to issue a request for a probe into it.)


Reading this link...wouldnt this break EDNS client subnet then by design, or am I misunderstanding?


Yes and no; while the second hop (recursive resolver) won't know the client's IP/geo, we've chosen to locate the first and second hops very near each other in terms of network latency and, eventually, to roll out enough first hops so that there won't be much (region-scale) geographic distance between the client, the first hop, and the second hop. This would require a slight modification to the existing mechanism. (A client could include ECS as is, but it'd be bad for their privacy.)


US Senator outlines the allegedly misuse of US government funds and where the contracted academic obtained their funds for the actual purchase of DNS tracking dataset from,

in which to (allegedly?) enable US government performing these acts of circumventing the various intra-US surveillance laws that are in place to protect US person (citizens, US-based corporations, naturalized citizens), or something to that gist of it.

Probably a focus on whether academic is violating contracts and depending on that, whether a federal agency is lacking oversight mechanism of these alleged transgression(s), or both.

Should be interesting to shine a light on this allegedly roundabout ways, given that DoT and DoH are the "rage".



Worked for me (both original and archive).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: