Question and 2026 source
Encrypted DNS still has a recognizable shape. Which visible fields identify DNS traffic after encryption, and what do mitigations cost?
Lenders, Schmidt and Wählisch, Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT, first arXiv submission June 8, 2026, v1 full text; peer-reviewed IEEE EuroS&P 2026, DOI 10.1109/EuroSP68448.2026.00094. An artifact was already public in April 2026. Reviewed September 11, 2026, especially §§III, V–VI and VIII.
The study classifies DNS versus application-data frames, not decrypted domain names. Its DoH comparison uses HTTP/2 and TLS 1.2 PSK for aligned experimental stacks; avoid generalizing to all modern DoH traffic.
This differs from #592's shared-cache question and the DoH deployment post: the subject is visible packet metadata. Coordinate with privacy correction #593.
Proposed bounded analysis, not yet run
The versioned artifact offers a 171.2-MB code/plot-data package separately from its 175.4-GB full dataset. Begin with one published figure and one scenario's header-feature analysis. If a small raw subset is available, compare address-only, length-only and combined features with majority/permuted-label controls and held-out deployments.
Proposed cap: one day, 8-GB RAM, 2-GB downloads, CPU-only. If raw data is unavailable within the cap, publish a clearly labeled analysis of aggregate results, with no new classifier-performance claim. No live traffic collection. Inspect and pin code/license before use; do not run an upstream setup script during discovery.
Question and 2026 source
Encrypted DNS still has a recognizable shape. Which visible fields identify DNS traffic after encryption, and what do mitigations cost?
Lenders, Schmidt and Wählisch, Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT, first arXiv submission June 8, 2026, v1 full text; peer-reviewed IEEE EuroS&P 2026, DOI 10.1109/EuroSP68448.2026.00094. An artifact was already public in April 2026. Reviewed September 11, 2026, especially §§III, V–VI and VIII.
The study classifies DNS versus application-data frames, not decrypted domain names. Its DoH comparison uses HTTP/2 and TLS 1.2 PSK for aligned experimental stacks; avoid generalizing to all modern DoH traffic.
This differs from #592's shared-cache question and the DoH deployment post: the subject is visible packet metadata. Coordinate with privacy correction #593.
Proposed bounded analysis, not yet run
The versioned artifact offers a 171.2-MB code/plot-data package separately from its 175.4-GB full dataset. Begin with one published figure and one scenario's header-feature analysis. If a small raw subset is available, compare address-only, length-only and combined features with majority/permuted-label controls and held-out deployments.
Proposed cap: one day, 8-GB RAM, 2-GB downloads, CPU-only. If raw data is unavailable within the cap, publish a clearly labeled analysis of aggregate results, with no new classifier-performance claim. No live traffic collection. Inspect and pin code/license before use; do not run an upstream setup script during discovery.