Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The privacy benefit is there's no centralized logs. If you're using your ISP's / CF's / Google's resolvers[1], there's a single place the bad guys have to log to get all of your DNS requests. Locally, your resolver talks to each authoritative server in the chain independently.. to find out who you're talking to, it's not a matter of just requesting logs anymore, they'd have to actively tap your connection and sniff traffic on DNS ports.

[1]Someone will start shouting about how 8.8.8.8/1.1.1.1 doesn't store logs. Yes they do[2][3]. They store full logs for "24 to 48 hours", so the bad guys can happily request your DNS logs (without a warrant now), as long as they request them once a day for the previous day.

[2]https://developers.google.com/speed/public-dns/privacy

[3]https://www.cloudflare.com/learning/dns/what-is-1.1.1.1/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: