Quick question about DNS and DoH that I thought about after reading this post:

https://packmates.org/@[email protected]/111176886781705659

Wouldn’t it make sense for Firefox or another third party to bundle and transparently forward all DoH requests to cloudflare so that:

A) Cloudflare doesn’t know who made what request due to not knowing the origin

B) Firefox doesn’t know who made what request due to TLS

#Infosec #Privacy
CC: @privacyguides

  • Jørn@ipv6.social
    cake
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    @Wander @privacyguides I think that’s what ODoH is. Apple also does something like that with their private relay service.

    However, it still allows the last DNS provider in the chain to see all queries, even if they don’t know the exact source.