FYI, Chrome DoH has been using DoH/3 since launch, when used with Google Public DNS or Cloudflare

So comparing do DoH/2 is perhaps not the most logical alternative

Please may i have the QR code for the paper

slides are in the proceedings: https://datatracker.ietf.org/meeting/115/materials/slides-115-maprg-dns-privacy-with-speed-evaluating-dns-over-quic-and-its-impact-on-web-performance-00

Link to PDF herein: https://dl.acm.org/doi/10.1145/3517745.3561445

Others have reached similar conclusions about the performance benefits of DoQ to DoH See for example a presentation by Andrey Meshkov, CTO of AdGuard, at https://419.consulting/encrypted-dns/f/doq-in-the-wild

Just to expand on what I said at the mike: encrypted DNS has lots of potential to be highly performant, e.g. using 0-RTT QUIC with session resumption. Further data would be most helpful in understanding this.

DoH3 with 0-RTT should have identical performance to DoQ, modulo a handful of bytes.

It makes sense that from a client perspective, DoH3's ability to fall back to DoH2 is an advantage over DoQ, assuming a non-zero percentage of networks with UDP blocking. From a network's perspective where we have certainty that UDP is allowed, DoQ appears more attractive. Maybe DoH3 is the overall middle ground.

I believe the term would be \"zenith\" for when the satellite is overhead

\"apogee\" means \"furthest from the Earth\"

For me, DoQ makes sense primarily as the \"MTI\" for recursive-to-authoritative. DNS authorities aren't going to want to have to deploy HTTP stacks, and DoQ seems strictly better than DoT for many reasons if we had to pick one between them. DoH3/DoH2 as the primary mechanism clearly makes sense for client to DNS recursive. For OS resolver stub to DNS recursive, I can see more arguments in various directions (primarily to keep HTTP stacks out of the OS stub resolver).

Yes, DoQ for authoritative makes great sense. But client access should be DoH3/DoH2. Our stub resolver has no issue doing HTTP there \u2014 you can have a very minimal HTTP stack for DoH.

No doubt that IoT security is a large and growing problem.

Risky BIZness: Risks Derived from Registrar Name Management
\n Gautam Akiwate

United We Stand: Collaborative Detection and Mitigation of
\n Amplification DDoS Attacks at Scale\u201d
\n Daniel Wagner

", "time": "2022-11-10T14:49:34Z"}]