How does this not just move the trust problem to the ODNS server? Doesn't it now know both the requesting IP and the requested domain?
How does this not just move the trust problem to the ODNS server? Doesn't it now know both the requesting IP and the requested domain?
All seems to hinge on the recursive resolver acting as a proxy, so a direct response from ODNS server to the client stub doesn't seem safe.
[1] https://s3.amazonaws.com/ftt-uploads/wp-content/uploads/2018...
The ODNS resolver then sends the encrypted request to the DNS resolver on your behalf, and the DNS resolver decrypts the request and services it. This meanst that the DNS resolver knows what website you are looking for, but doesn't know that it is you that is looking for it.
The DNS resolver then encrypts the result and returns it to the ODNS, which then returns it to you.
It is basically decoupling the identity of the requester from the domain being requested.
How is the middle path between current DNS and Tor-level anonymity defined, exactly?
That's how I read this as well. It does appear that a simple DNS proxy would accomplish the same goal without all the encryption. Are we missing something?