The solution
Ars Technica's Dan Goodin reported that Cloudflare, Apple and content-delivery network Fastly introduced Oblivious DNS over HTTPS (ODoH), a change to the domain name system meant to stop providers and snoops from seeing which addresses users visit. DNS over HTTPS and DNS over TLS already encrypt lookups, but a small pool of providers can still log the Internet usage of potentially billions of people. Because the provider sees both the query and the IP address of the computer making it, it can still build comprehensive profiles.
ODoH places a network proxy between users and the DNS resolver. The client encrypts its query for the target resolver using HPKE, with the target's public key obtained through DNS. The proxy forwards the encrypted query and cannot read it. The target decrypts it, answers and encrypts the response, which returns through the proxy. Only the user has access to both the request and the IP address that sent it.
Cloudflare reported that in one study the extra overhead of ODoH over a proxied DoH query was less than 1 millisecond at the 99th percentile. The companies worked with the Internet Engineering Task Force toward an industry standard.
Why it worked
DoH and DoT protect against network snoops but not against the resolver itself.
Few providers offer encrypted DNS, which concentrates the privacy risk in them.
A proxy that cannot decrypt and a resolver that cannot see the client address keep the two facts apart.
Messages stay end-to-end encrypted even though they cross two separate HTTPS connections.
What can be applied
If one party cannot be trusted with two linked facts, split the facts across two parties so neither can join them.
Aftermath
Ars described ODoH as a work in progress in late 2020: performance costs of the proxy and encryption were still being measured, Firefox and others had shown interest, and Google and Microsoft were absent. It said the absence of these players suggested the protocol had a long way to go.
FOLLOW THE EVIDENCE