Assessing DNS privacy under partial deployment of special-use Domain Names

Ah Reum Kang, Aziz Mohaisen · 2016

Domain Name System (DNS) leakage occurs when queries for names within a private namespace are propagated in the public DNS infrastructure, which has various privacy implications. To reduce this leakage and improve Tor's privacy, Appelbaum and Muffet suggested in RFC 7686 the special-use of .onion domain name. They recommended how stub, recursive, and authority name servers should behave when encountering .onion domains: they should not attempt to resolve such domains and return NXDOMAIN responses (i.e., blocking the query from propagating in the public DNS). Without any form of analysis of those recommendations in practice, it is hard to tell how much privacy is provided by following such recommendations. We initiate for the study of those recommendations by analyzing them under different contexts and conclude that while the unlikely universal implementation will certainly improve privacy by preventing leakage, partial deployment, which is the likely case with early adoption, will degrade the privacy of individuals not adopting the recommendations.

Read the paper · More papers on PaperTik