Now on stage Sara Dickinson, about #DNS #privacy (in english, too). https://dnsprivacy.org/ #RMLL2017
Several technical solutions were considered at the #IETF. The choice was DNS-over-TLS-over-new-port. #teamPort853 #privacy #TLS Does not solve everything: timing and sizes are still there. #RMLL2017
As my grand-mother used to say, "encrypting is easy, authenticating is difficult". Sara Dickinson now explains the possible choices for DNS-over-TLS auth. Strict or opportunistic? #Mallory #ManInTheMiddle #privacy #RMLL2017
And for the cases where port 853 is blocked, I want you to meet DNS-over-HTTP(S)… #everythingOverPort443 #privacy
There is also a DNS-over-#QUIC project. (QUIC can encrypt, and validate the source IP address.)
Monitoring of the public #DNS-over-#TLS servers https://dnsprivacy.org/jenkins/job/dnsprivacy-monitoring/
There is also a cool stub resolver performing encryption, Stubby https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Daemon+-+Stubby
State of the implementation https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Implementation+Status #DNS #privacy #RMLL2017