• 0 Posts
  • 20 Comments
Joined 2 years ago
cake
Cake day: June 4th, 2023

help-circle





  • DNS over HTTPS (DoH), which is Domain Name Service over Secure HyperText Transfer Protocol. HTTP is the technology the Web runs on. The S in HTTPS is the secured version of HTTP, it’s encrypted using TLS (originally was SSL, Secure Sockets Layer), Transport Layer Security. DNS translates site names (e.g., www.google.com) into an IP (Internet Protocol) address (e.g., 8.8.8.8). DNS is an unencrypted protocol like HTTP. Adding in the Security component is somewhat tricky, but DoH is one of the ways, it just piggy backs on a tried and true secure transport technology that powers the web today.

    The reason you would want to use DoH is to secure the domains you are accessing from (1) being intercepted and/or altered, e.g., someone poisoning the response and giving you a bad IP address for any number of reasons, and (2) snoops such as the WiFi provider you’re connected to or the Internet Service Provider (ISP) or cellular provider, or anyone else watching the unencrypted traffic.









  • I’m really not sure. I’ve heard of people using Ceph across datacenters. Presumably that’s with a fast-ish connection, and it’s like joining separate clusters, so you’d likely need local ceph cluster at each site then replicate between datacenters. Probably not what you’re looking for.

    I’ve heard good things about Garbage S3 and that it’s usable across the internet on slow-ish connections. Combined with JuiceFS is what I was looking at using before I landed on Ceph.