4 comments

[ 0.24 ms ] story [ 15.5 ms ] thread
running my own resolver as system DNS i can confirm apple devices fire _dns.resolver.arpa on every network join, but since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only, so for a LAN resolver the right move is just answering NODATA instead of leaking the query upstream.
> since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only

Why would you think this? It's trivial to get certs for internal services that mainstream devices trust, they just have to use names from a portion of the public DNS space that you can demonstrate control over. It doesn't actually have to be publicly exposed.

a lookup for _dns.resolver.arpa, a name reserved for ... asking whether an encrypted version exists, and where it can be reached

Neat! Let's try: nslookup _dns.resolver.arpa

    [mine] unblound.lan can't find _dns.resolver.arpa: Non-existent domain 

    [1.1.1.1] can't find _dns.resolver.arpa: Non-existent domain

    [8.8.8.8] No internal type for both IPv4 and IPv6 Addresses (A+AAAA) 
    records available for _dns.resolver.arpa

    [9.9.9.9] Name:  _dns.resolver.arpa
A device that only exposes an IP field can use DDR without extra user configuration, but it still has to implement DDR and an encrypted DNS protocol in the first place...