Privacy and DNS Client Subnet episode artwork

EPISODE · Sep 18, 2024 · 49 MIN

Privacy and DNS Client Subnet

from PING · host APNIC

In his regular monthly spot on PING, APNIC’s Chief Scientist, Geoff Huston, discusses another use of DNS Extensions: The EDNS0 Client Subnet option (RFC 7871). This feature, though flagged in its RFC as a security concern, can help route traffic based on the source of a DNS query. Without it, relying only on the IP address of the DNS resolver can lead to incorrect geolocation, especially when the resolver is outside your own ISP’s network. The EDNS Client Subnet (ECS) signal can help by encoding the client’s address through the resolver, improving accuracy in traffic routing. However, this comes at the cost of privacy, raising significant security concerns. This creates tension between two conflicting goals: Improving routing efficiency and protecting user privacy. Through the APNIC Labs measurement system, Geoff can monitor the prevalence of ECS usage in the wild. He also gains insights into how much end-users rely on their ISP’s DNS resolvers versus opting for public DNS resolver systems that are openly available.

Episode metadata supplied by the publisher feed · Published Sep 18, 2024

Embed this episode

NOW PLAYING

Privacy and DNS Client Subnet

0:00 49:11

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of PING?

This episode is 49 minutes long.

When was this PING episode published?

This episode was published on September 18, 2024.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this PING episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!