PING

Privacy and DNS Client Subnet


Listen Later

In his regular monthly spot on PING, APNIC’s Chief Scientist, Geoff Huston, discusses another use of DNS Extensions: The EDNS0 Client Subnet option (RFC 7871). This feature, though flagged in its RFC as a security concern, can help route traffic based on the source of a DNS query. Without it, relying only on the IP address of the DNS resolver can lead to incorrect geolocation, especially when the resolver is outside your own ISP’s network.


The EDNS Client Subnet (ECS) signal can help by encoding the client’s address through the resolver, improving accuracy in traffic routing. However, this comes at the cost of privacy, raising significant security concerns. This creates tension between two conflicting goals: Improving routing efficiency and protecting user privacy.


Through the APNIC Labs measurement system, Geoff can monitor the prevalence of ECS usage in the wild. He also gains insights into how much end-users rely on their ISP’s DNS resolvers versus opting for public DNS resolver systems that are openly available.


Read more about EDNS0 and UDP on the APNIC Blog and at APNIC Labs:

  • Privacy and DNS Client Subnet (Geoff Huston, APNIC Blog July 2024)
  • The use of ECS as measured by APNIC Labs
...more
View all episodesView all episodes
Download on the App Store

PINGBy APNIC

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like PING

View all
This American Life by This American Life

This American Life

90,932 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

290 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

The Everything Feed - All Packet Pushers Pods by Packet Pushers

The Everything Feed - All Packet Pushers Pods

195 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

268 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

215 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,056 Listeners

The Hedge by Russ White

The Hedge

16 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

N Is For Networking by Packet Pushers

N Is For Networking

21 Listeners