Design: update wrt. current devel branch state.
@@ -14,6 +14,9 @@ therefore blocked in order to prevent leaks. Another solution may be
to use the Linux network filter to forward outgoing UDP datagrams to
the local DNS proxy.
+T(A)ILS development branch also forbids DNS queries to RFC1918 addresses; those
+might indeed allow the system to learn the local network's public IP address.
[resolvconf]( is used to
configure the system resolver in `/etc/resolv.conf`; it is also setup
to prevent NetworkManager and dhcp-client to modify this file.
@@ -15,6 +15,4 @@ We then need to forbid queries to DNS resolvers on the LAN.
Exceptions: at least the htp user; more?
> This has been implemented, though untested, in devel branch (commit
-> c2ad173) => [[!taglink todo/test]] and write [[!taglink
-> todo/documentation]] about this in the [[design
-> document|contribute/design]].
+> c2ad173) => [[!taglink todo/test]].