Now people are focused on encrypting metadata, so things like DNSSEC took off.
There was a recent discussion about how state actors are using push notifications to spy on users. Maybe that is the next area of improvement.
Now people are focused on encrypting metadata, so things like DNSSEC took off.
There was a recent discussion about how state actors are using push notifications to spy on users. Maybe that is the next area of improvement.
DNSSEC doesn't encrypt anything - it's all plaintext on the wire. There are some DNS extensions that encrypt the query/response (DNS over HTTPS does this), but DNSSEC is not that.
DNSSEC is simply a way to verify that the response you get has not been meddled with in transit - it's the domain owner signing the DNS records so that you can verify that your DNS responses aren't being modified by a malicious entity (that may very well be your ISP).
The number of users of recursive resolvers that support DNSSEC vs users of browsers that use DoH? Number of companies that has infrastructure that supporting DoH compared to number of companies that has infrastructure that supporting DNSSEC? Daily users?
Note that this isn't lookups that happen to run through a resolver with DNSSEC enabled; to count, you'd be talking about such a lookup to a zone that had DNSSEC signatures. You can see the advantage DoH has here, since it works with all zones.
It would interesting to see statistics. I wouldn't assume anything in that race. Some TLD's which are signed has quite a lot of traffic going through them on any given day, and most resolvers connecting to those have dnssec enabled by default. There are published statistics for this, but I can't find anything similar from either google or cloudflare.
CloudFlare itself might not even be aware of the taps. Or maybe only a few select employees know about it.
I think the solution to these problems is to reduce dependence on the Internet. It's now possible to torrent an entire library worth of books and have it all on your personal computer at home. 20TB HDDs are readily available, and constantly getting cheaper. Also check out https://reddit.com/r/DataHoarder. And we have local AI models, again these do not need the Internet to function.
Uh, I thought the concern is about communications (email, IM, etc), not about content consumption. Communications can't be replaced with some static archives.
I doubt any TLA cares if I read Python or Rust documentation, or if I watched Oppenheimer, or Barbie, or both. If they do - well, it's their loss, because such data is absolutely worthless at scale, as repeatedly demonstrated by the ad industry failing to extract any meaning from all the Big Data(tm) they hoard. And if they would somehow get interested in me personally - I don't think having an offline Wikipedia copy would help me any much.
The solution is to encrypt and authenticate every single byte transferred, end-to-end, with strongest known algorithms. And, well, some legislative action too.
certificate transparency makes this very risky to pull off, making it all but useless unless you're trying to catch a international terrorist or something.
so, yeah, a gov abusing this is very bad and visible. scammers profiting from the complexity and humans in the machine, is very common.
Source? If true they're grounds for ejection from root certificate programs of various OS/browsers.
1) That would be figuratively, not literally, as there's no literal baby in HTTPS-everywhere that I know of.
2) What is HTTPS-everywhere throwing out? Which part is the baby and which is the bathwater? I don't think this is the right expresion to use here, not even figuratively.
Well not anymore. We threw it out.
A genuine loss, and also the ability to zip imagery.
The worst of it was that internet providers wanted to tamper with data, and insert this or that advert into what they sent. The absence of that is a good thing.