logoalt Hacker News

abcdefg12today at 1:22 AM2 repliesview on HN

Or you could use dnscrypt so ISP doesn’t see your lookups at all


Replies

aand16today at 1:20 PM

During the TLS handshake, you send the domain name in clear text (Server Name Indication - SNI extension) so that the hoster can present the correct certificate for that domain.

Nothing prevents the ISP from collecting that.

show 1 reply
Bendertoday at 1:28 AM

When all the authoritative servers support TLS I can enable TLS outbound but very few of them do at the moment. At some point someone is decrypting, turtles all the way down. I could of course just do DoT to another instance of Unbound somewhere else but I do not need to do that as my ISP does not care about my queries. I used to keep standby DoT Unbound servers around but I have never once seen a US ISP tinker with my traffic. If they did I would put up billboards saying they what they are doing.

show 2 replies