from Hacker News

DNSChain 0.5 released, brings full HTTPS support, Openname Resolver API and more

by DonPellegrino on 3/7/15, 9:15 PM with 32 comments

  • by e12e on 3/7/15, 11:43 PM

    Is there a clear readme on dnschain somewhere? I looked at the github repo, but still don't quite get what actual benefits it brings over running one's own dns server? Using the public server obviously still leaks metadata (who looks up what when) - not that such metadata isn't rather obvious anyway by observing traffic between ips. How is it any better than cacert? Because you pin the trust to your own ca? What stops you from doing that now (how is the trust different with dnschain?).
  • by higherpurpose on 3/7/15, 10:10 PM

    > Automatically generates 4096-bit HTTPS key/certificate pair for you

    Will this be a problem for low-end phones? Why not ECC certificates?