Skip to content

Privacy thoughts on DNS over QUIC ? #49

Discussion options

You must be logged in to vote

DoQ reguires Server Name Indication (SNI) to be encrypted.

Source? SNI has nothing to do with DNS, so I don't see how this could be the case. If you want eSNI, the webserver you connect to must support it, not your DNS resolver. RFC 9250 which you linked to appears to answer your overall question in its introduction, emphasis mine:

The goals of the DoQ mapping are:

  1. Provide the same DNS privacy protection as DoT [RFC7858]. This
    includes an option for the client to authenticate the server by
    means of an authentication domain name as specified in "Usage
    Profiles for DNS over TLS and DNS over DTLS" [RFC8310].

[...]

Replies: 0 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by emikaadeo-git
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
2 participants