We analyze opinions regarding the features of DNS over HTTPS, which has recently become a "bone of contention" among internet providers and browser developers.
/ Unsplash /
The Essence of the Disagreements
Recently and (including Habr) frequently write about the DNS over HTTPS (DoH) protocol. It encrypts DNS queries and responses. This approach hides the host names that users are requesting. From the publications, one can conclude that the new protocol (approved by the IETF has divided the IT community into two camps.
Half believe that the new protocol will enhance internet security and are implementing it in their applications and services. The other half is convinced that the technology merely complicates the work of system administrators. Next, we will analyze both sides' arguments.
How DoH Works
Before discussing why internet providers and other market participants are for or against DNS over HTTPS, let's briefly summarize its principles.
In the case of DoH, the request for determining an IP address is encapsulated in HTTPS traffic. It then goes to an HTTP server, where it is processed via an API. Here’s an example request from RFC 8484 ():
:method = GET
:scheme = https
:authority = dnsserver.example.net
:path = /dns-query?
dns=AAABAAABAAAAAAAAAWE-NjJjaGFyYWN0ZXJsYWJl
bC1tYWtlcy1iYXNlNjR1cmwtZGlzdGluY3QtZnJvbS1z
dGFuZGFyZC1iYXNlNjQHZXhhbXBsZQNjb20AAAEAAQ
accept = application/dns-message
Thus, DNS traffic is concealed within HTTPS traffic. The client and server communicate over the standard port 443. As a result, requests to the domain name system remain anonymous.
Why It's Not Welcomed
Opponents of DNS over HTTPS argue that the new protocol will decrease the security of connections. According to Paul Vixie, a member of the DNS development team, it will be more difficult for system administrators to block potentially malicious sites. Regular users will lose the ability to set up conditional parental controls in browsers.
Paul's opinion is shared by UK internet providers. The laws of the country them to block resources with prohibited content. However, support for DoH in browsers complicates the task of traffic filtering. Among the critics of the new protocol are also the UK's Government Communications Headquarters () and the Internet Watch Foundation (), which maintains a registry of blocked resources.
On our blog on Habr:
Experts note that DNS over HTTPS could pose a cybersecurity threat. In early July, cybersecurity specialists from Netlab the first virus that used the new protocol for conducting DDoS attacks — . The malware used DoH to obtain text records (TXT) and extract URLs of control servers.
Encrypted DoH requests were not recognized by antivirus software. Cybersecurity experts , that after Godlua, other malware will come, invisible to passive DNS monitoring.
But not everyone is against it
In defense of DNS over HTTPS, on their blog engineer from APNIC Geoff Houston. According to him, the new protocol will help combat DNS hijacking attacks, which have become increasingly common recently. This fact a January report from cybersecurity company FireEye. The protocol's development was supported by major IT companies.
As early as last year, DoH began testing at Google. And a month ago, the company released the General Availability version of its DoH service. Google , that it will enhance online personal data security and protect against MITM attacks.
Another browser developer — Mozilla — has been using DNS over HTTPS since last summer. The company is actively promoting this new technology in the IT community. Because of this, the Internet Services Providers Association (ISPA) Mozilla for the 'Internet Villain of the Year' award. In response, company representatives , that they are disappointed by the unwillingness of telecom operators to improve outdated internet infrastructure.

/ Unsplash /
In support of Mozilla and some internet providers. In particular, British Telecom mentioned , that the new protocol will not affect content filtering and will enhance security for British users. Under public pressure, ISPA the 'villainous' nomination.
Cloud providers have also advocated for the implementation of DNS over HTTPS, for example . They are already offering DNS services based on the new protocol. A complete list of browsers and clients supporting DoH is available at .
In any case, it's too early to speak about the end of the confrontation between the two camps. IT specialists predict that if DNS over HTTPS is destined to become part of the mass stack of internet technologies, it will take .
What else we write about in our corporate blog:
Source: habr.com
