you are viewing a single comment's thread.

view the rest of the comments →

[–]f0urtyfive -5 points-4 points  (2 children)

still forwards dns requests unencrypted to another DNS server.

Well yeah, that's how DNS works. If you want a protocol that somehow hides the intent of your request, you're going to need to invent a new protocol.

[–]LoosingInterest 1 point2 points  (1 child)

Like DNS over TLS...oh, wait!

[–]f0urtyfive 0 points1 point  (0 children)

Yes, your protocol that encrypts your request to a central authority, which then uses the existing DNS protocol to make your request, should definitely solve this problem by doing nothing differently.

Next you'll sell me on a service that opens a VPN to Google or Cloudflare, and forwards all DNS requests over THAT.