Reply to post:

Mozilla Firefox to begin slow rollout of DNS-over-HTTPS by default at the end of the month

The Mole

Because 123.234.345.456 might be hosting thousands of different websites under lots of different hostnames so just knowing the ip isn't sufficient to target you. Knowing what you've just resolved to get the IP is a cheap and easy way to find out. For HTTP connections they could just look at the Host header, and even HTTPS connections they can look at the SNI header (which isn't encrypted) to find it out but that's more expensive and alternatives to SNI might be widely available at some point.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon