Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



To quote the relevant section:

“ODoH sends DNS queries through the first internet relay, so the DNS server cannot identify the user issuing a query. Each query itself is padded and encrypted using Hybrid Public Key Encryption (HPKE) to help ensure that the first internet relay cannot tell the domain name a user is looking up.”

Apple is the “first internet relay” and they seem to explicitly state that they don’t see the DNS queries themselves.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: