I love this. It doesn’t need a reason to exist. It’s interesting on its own.
That being said, can anyone think of additional interesting reasons for why this would be useful rather than the same toys over HTTP?
I love this. It doesn’t need a reason to exist. It’s interesting on its own.
That being said, can anyone think of additional interesting reasons for why this would be useful rather than the same toys over HTTP?
Anyway if you're using a 14.4 modem in a rusty bunker at the bottom of the sea you'll notice a substantial improvement :)
I measured the difference using `tcpdump`, and this was my conclusion:
> A big advantage of using DNS queries instead of HTTP queries is bandwidth: querying ns-aws.sslip.io requires a mere 592 bytes spread over 2 packets; Querying https://icanhazip.com/ requires 8692 bytes spread out over 34 packets—over 14 times as much! Admittedly bandwidth usage is a bigger concern for the one hosting the service than the one using the service.
(I had set up a service to determine your IP address via DNS, i.e. `dig @ns.sslip.io txt ip.sslip.io +short`, and measured why it was (marginally) better than using HTTP)
On a TLS1.3 QUIC connection with a session supporting 0-rtt would DNS still require less round trips?
How did DNS resolution work? Do they force you to use their proxy server?
Just setup openvpn with port 53 UDP with cheap vps, then connect it, and get unlimited internet access
Internet connection in my country is very limited and expensive in that day
I never thought to use DNS as a tunnel, but I have seen some pretty interesting loopholes that I was trying to find. Some airline's captive portal used to rely on some google service (captcha probs), and for a period of time didn't block any google-owned IP address that wasn't a consumer website (eg search, yt) so GCP and developer docs would load if you had the URL. I couldn't reliably get to user-generated content through it though.
Most firewalls drop or hijack packets on port 53.
Add a bonus withering stare for assuming JSON is the only data serialization/interchange format.
https://resources.infosecinstitute.com/topic/bypassing-secur...
That availability can also be used for good.