If you like BoxMatrix then please contribute Supportdata, Supportdata2, Firmware and/or Hardware (get in touch).
My metamonk@yahoo.com is not reachable by me since years. Please use hippie2000@webnmail.de instead.
Property:ECID
BoxMatrix >> Lexicon >> Network-Protocols >> ECID | @ BoxMatrix - IRC-Chat - Translate: de es fr it nl pl |
News | Selectors | Models | Accessories | Components | Environment | Config | Commands | System | Webif | Software | Develop | Lexicon | Community | Project | Media |
Computer | FRITZ | I18N | Telephony | Smarthome | Internet | Protocols | Multimedia | Formats | Hardware | Software | Research |
Protocol
Protocol: | ECID | Wiki | Freetz | IPPF | whmf | AVM | Web |
Short for: | EDNS0 Client ID | ||||||
Location: | Lexicon >> Network-Protocols | ||||||
Weblinks: | draft-tale-dnsop-edns0-clientid | ||||||
Description: | Send client identifiation in extended DNS requests |
Goto: FRITZ!OS - SMW-Browser
Details
ECID (EDNS0 Client ID
) uses EDNS0 packets to send client identifiation to the upstream DNS server in requests.
This identifiation typically consists of MAC address and hostname of the caller.
ECID never got an own RFC. It is only definied in an expired IETF draft from 2017, see the Weblink above.
The draft states that implementations of ECID MUST BE explicit opt-in by an administrator on the LAN.
It also warns about privacy and security dangers and even about possibly being illegal in some countries.
FRITZ!OS
Since FRITZ!OS 7.59 ECID is supported as an explicit opt-in feature.
See the Upstream-DNS section of the DNS article how it's enabled.
The option is called (own translation from german text - not translated yet in english language db):
Send information about the network device to the DNS server of your ISP (EDNS0). [ ] The MAC address and hostname will be transmitted. Enable this if your ISP provides EDNS0 services like client specific filtering, and you want to use them.
The reason for this option and the ISP requesting it is unknown so far, there's no word on the AVM website or in their help.
Let's hope it's not a new dimension of opt-in DNS-Hijacking with tracking or even surveillance of hosts behind NAT.