[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-relays] Reminder: exit nodes probably shouldn't be using Google's DNS servers



On Thu, 08 Jan 2015 08:38:35 -0800, Paul Syverson <paul.syverson@xxxxxxxxxxxx> wrote:
The flip side is that, against such an adversary, using a DNS server that supports encryption of
queries and responses is probably more important than it being local.

I like to chain unbound up to dnscrypt-proxy in order to encrypt DNS traffic for this very reason.

dnscrypt-proxy frequently is unable to keep up however, so I currently have unbound configured to make queries directly if dnscrypt-proxy is not responding.
_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays