Two wins for Internet Privacy on the same day

Today, the 17th of May 2016, the IETF Editor published RFC 7844, an Anonymity Profile for DHCPv4 and DHCPv6 clients, and RFC 7858, transmission of DNS requests over TLS. These two RFC can close two important avenues for leaking metadata over the Internet.

I started working on what became RFC 7844 in November 2014. The work on MAC Address Randomization was progressing swiftly, and the corresponding feature would ship in Windows 10 the next year. MAC Address Randomization ensures that your laptop or your smartphone cannot be tracked by its Wi-Fi MAC Address, but we quickly observed that doing that was not sufficient. When your computer joins a network, it executes a series of low level protocol to “get configured.” One of this protocol is DHCP, which is used to obtain an Internet Protocol Address. The problem is that DHCP is very chatty, and by default provides all kind of information about your computer name, software version, model, etc. I worked with the members of the DHCP working group in the IETF to remedy that, and their response was great. They produced thorough analyses of privacy issues in DHCPv4 and in DHCPv6, which have just been published as RFC 7819 and RFC 7824. RFC 7844 patches all these issues. And the best part is that an implementation already shipped in the November 2015 update of Windows 10.

The work on DNS Privacy is just as important. By default, your computer issues “name resolution” requests in clear text for each web site and each Internet service that it uses. This stream of requests is a rich set of metadata, rich enough to allow for identification of the computer’s user, and then to track its activities. It is here for the taking, by shady hot spot providers, spies, or maybe criminals. RFC 7858 defines how to send these requests in a secure fashion to a trusted DNS server, effectively closing that source of metadata leakage.

Of course, there is more work to do. But the 17th of May 2016 was a great day for Internet Privacy.


About Christian Huitema

I have been developing Internet protocols and applications for about 30 years. I love to see how the Internet has grown and the applications it enabled. Let's keep it open!
This entry was posted in Uncategorized. Bookmark the permalink.

3 Responses to Two wins for Internet Privacy on the same day

  1. Your work in the area is invaluable and much appreciated; however, it really bothers me that DNS Privacy is largely undermined by

    • Encrypting DNS traffic with TLS prevents observation by anyone but the chosen DNS service provider, but it does not of course prevent observation by that provider. So if people chose Google DNS as their provider, that means they trust Google. That may or may not be a great idea, but at least having standards allows competition. If you trust Cisco more than Google, use Open DNS. Or another competitor. Or set up your own.

      Big services actually have a positive effect on privacy, because they provide “strength in numbers.” Your traffic to the server is encrypted, but the requests out of the server are not. If the server had just one customer, it is very easy to correlate incoming and outgoing requests, and the privacy effect is lost. But if the service has thousands of customers, that’s much more difficult.

  2. blipblip says:
    there is an excellent open non-commercial dns service here being ran for many years by an independent person interested in DNS privacy .

    Theres even a talk with him on youtube from some hack camp.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s