|
|
Log in / Subscribe / Register

Ever-growing CRL?

Ever-growing CRL?

Posted Dec 6, 2024 16:59 UTC (Fri) by paulj (subscriber, #341)
In reply to: Ever-growing CRL? by dskoll
Parent article: Let's Encrypt sets date for ending OCSP support

> You're leaking that info to your name servers, your ISP's name servers maybe, and all the servers along the chain up to the root of the domain you're looking up.

No, no I'm not. Whether it's address lookups or cert lookups, that's hugely sensitive information, and I am amazed that in this day and age we're still by default sending that information in the clear to some random local device (AP, router, whatever) managed by someone we may not trust much if at all with our sensitive data (cafe, airport, school, employer, some giant incumbent former-state-monopoly national telco, etc.), using IPs that are very likely tied to us.

I am especially amazed that technical people, such as those here, are still doing that. ;)

We should be using anonymised name lookup systems *BY DEFAULT* here in the 21st Century.

My machines are setup to resolve using a local dnscrypto, making queries over Tor, to public DoH servers. The DoH servers might see the queries, but they can't relate them back to me. My local and access networks handle packets, but they have no clue about what queries I'm making. If you don't like Tor, do something similar with a VPN provider. Not quite as good, but probably sufficient for most privacy needs.

(And yes, the Five Sisters and some other SIGINTs might have enough nodes to do correlation analysis to some degree, but that's not a concern to me).


to post comments

Ever-growing CRL?

Posted Dec 6, 2024 18:10 UTC (Fri) by dskoll (subscriber, #1630) [Link]

Good for you. But you are clearly not in the target audience that Lets Encrypt believes it's protecting by deprecating OCSP. I'd say no more than 0.2% of all the people on the Internet have your level of privacy WRT DNS, and that's unlikely to change in the forseeable future.

Ever-growing CRL?

Posted Dec 19, 2024 12:17 UTC (Thu) by Lennie (subscriber, #49641) [Link] (1 responses)

I had found using Tor to connect to public DoH servers was pretty darn slow, what is your experience ?

Ever-growing CRL?

Posted Jan 2, 2025 15:28 UTC (Thu) by paulj (subscriber, #341) [Link]

dnscrypt-proxy can setup connections to a wide-range of public DoH servers (it can download lists of them) and then sort them by RTT. Chances are good that over all those different Tor circuits, to different DoH servers, you'll get at least a few that are fast.

Tor is pretty fast these days. A good few years ago Tor was indeed often noticeably slower than going direct. Today I browse the web via Tor by default, and I don't ever notice a downside when it comes to speed. You can pretty much reliably watch YouTube (or whatever) over Tor these days.

The one thing you do notice with Tor is that you regularly get the "Are you a human" interstitial checks. Cloudflare seem to be clever enough to just want you to click a check-box with your mouse and not check you again for quite a while, but some others will put you through a Captcha type puzzle. Thankfully, the majority of cases are Cloudflare, so it's not really a bother. Though, Google make you do a Captcha thing. There are a small handful of sites that outright block you when they detect Tor.

At some point, I think Tor (or similar onion routing) should become the default way for end-users to interact with the Web. Privacy should be a fundamental component of the Internet.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds