DNS隐私

DNS隐私涵盖旨在保护用户浏览意图免遭DNS层被动监视的技术、协议和策略。由于传统[[dns|DNS]]查询以明文形式发送,ISP、网络管理员和被动窃听者均可见。[[dns-over-https|DNS-over-HTTPS(DoH)]]、[[dns-over-tls|DNS-over-TLS(DoT)]]和[[encrypted-sni|加密客户端Hello(ECH)]]等协议对DNS流量进行加密。其他隐私措施包括:限制与各解析层共享信息的查询名称最小化(RFC 7816),以及使用遵循严格无日志政策的注重隐私的解析器。

示例

An activist uses a combination of DoH and ECH so that their ISP sees encrypted HTTPS traffic but cannot determine which news sites, forums, or advocacy pages they visit.