- Apr 07, 2017
-
-
Libor Peltan authored
-
- Apr 05, 2017
-
-
At NDSS 2017's DNS privacy workshop, I presented an empirical study of DNS padding policies: https://www.internetsociety.org/events/ndss-symposium/ndss-symposium-2017/dns-privacy-workshop-2017-programme#session3 The slide deck is here: https://dns.cmrg.net/ndss2017-dprive-empirical-DNS-traffic-size.pdf The resulting recommendation from the research is that a simple padding policy is relatively cheap and still protective of metadata when DNS traffic is encrypted: * queries should be padded to a multiple of 128 octets * responses should be padded to a multiple of 468 octets Since future research could propose even better policies, and future DNS traffic characteristics might evolve, I've implemented this recommendation as a new function in libknot: knot_edns_default_padding_size() This changeset also modifies kdig to use this padding policy by default when doing queries over TLS, and defines +padding (with no argument) as a kdig option that forces the use of the default padding policy. With this changeset, any libknot user who wants to use "a sensible DNS padding policy" can just rely on the library; this means that if a better padding policy is determined in the future, it can be distributed to all users by upgrading libknot.
-
- Mar 20, 2017
-
-
- Jan 04, 2017
-
-
Libor Peltan authored
-
- Dec 06, 2016
-
-
Daniel Salzman authored
-
- Sep 15, 2016
-
-
Daniel Salzman authored
-
- Aug 06, 2016
-
-
Daniel Salzman authored
-
- Aug 01, 2016
-
-
Daniel Salzman authored
-
- Jul 31, 2016
-
-
Daniel Salzman authored
-
- Jul 19, 2016
-
-
Daniel Salzman authored
-
- Feb 03, 2016
-
-
Dominik Taborsky authored
-
- Jan 08, 2016
-
-
Jan Včelák authored
-
- Dec 31, 2015
-
-
Daniel Salzman authored
-
- Sep 14, 2015
-
-
Daniel Salzman authored
-
- Jul 07, 2015
-
-
Jan Včelák authored
-
Jan Včelák authored
-
- Jun 03, 2015
-
-
Daniel Salzman authored
-
- May 26, 2015
-
-
Daniel Salzman authored
-
- May 06, 2015
-
-
Ondřej Surý authored
-
Ondřej Surý authored
-
- Apr 28, 2015
-
-
Ondřej Surý authored
-