Ever-growing CRL?
Ever-growing CRL?
Posted Dec 6, 2024 16:59 UTC (Fri) by paulj (subscriber, #341)In reply to: Ever-growing CRL? by dskoll
Parent article: Let's Encrypt sets date for ending OCSP support
No, no I'm not. Whether it's address lookups or cert lookups, that's hugely sensitive information, and I am amazed that in this day and age we're still by default sending that information in the clear to some random local device (AP, router, whatever) managed by someone we may not trust much if at all with our sensitive data (cafe, airport, school, employer, some giant incumbent former-state-monopoly national telco, etc.), using IPs that are very likely tied to us.
I am especially amazed that technical people, such as those here, are still doing that. ;)
We should be using anonymised name lookup systems *BY DEFAULT* here in the 21st Century.
My machines are setup to resolve using a local dnscrypto, making queries over Tor, to public DoH servers. The DoH servers might see the queries, but they can't relate them back to me. My local and access networks handle packets, but they have no clue about what queries I'm making. If you don't like Tor, do something similar with a VPN provider. Not quite as good, but probably sufficient for most privacy needs.
(And yes, the Five Sisters and some other SIGINTs might have enough nodes to do correlation analysis to some degree, but that's not a concern to me).
