Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNS will only leak which hostname you visit, not which pages you access on that hostname. You hereby definitely resolve a privacy issue.

Furthermore, the presence of a <form> element also looks like a very bad measure for 'protectworthy' information to me. Websites that require a user session to be established, need users to send a cookie for every request. Those requests need to be secure, or the sessions can be stolen.



Then, if there are sessions too, <form> was just an example.

You're right for the path though, but for a majority of users, this doesn't matter, that is because a website often has a specific subject (porn, warez, etc), so if one DNS lookups the website, then that pretty much gives it all if the middle man is interested.

Read: My opinion is that it's useless for most people, and is problematic for old infrastructures. Therefore there are as much benefit as negative effects, or more negative effects, so it doesn't seem worth it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: