"Loves and Doesn't Love": DNS over HTTPS

We analyze opinions regarding the features of DNS over HTTPS, which has recently become a "bone of contention" among internet providers and browser developers.

"Loves and Doesn't Love": DNS over HTTPS
/ Unsplash / Steve Halama

The Essence of the Disagreements

Recently major media outlets and thematic platforms (including Habr) frequently write about the DNS over HTTPS (DoH) protocol. It encrypts DNS queries and responses. This approach hides the host names that users are requesting. From the publications, one can conclude that the new protocol (approved by the IETF in 2018) has divided the IT community into two camps.

Half believe that the new protocol will enhance internet security and are implementing it in their applications and services. The other half is convinced that the technology merely complicates the work of system administrators. Next, we will analyze both sides' arguments.

How DoH Works

Before discussing why internet providers and other market participants are for or against DNS over HTTPS, let's briefly summarize its principles.

In the case of DoH, the request for determining an IP address is encapsulated in HTTPS traffic. It then goes to an HTTP server, where it is processed via an API. Here’s an example request from RFC 8484 (p.6):

   :method = GET
   :scheme = https
   :authority = dnsserver.example.net
   :path = /dns-query?
           dns=AAABAAABAAAAAAAAAWE-NjJjaGFyYWN0ZXJsYWJl
           bC1tYWtlcy1iYXNlNjR1cmwtZGlzdGluY3QtZnJvbS1z
           dGFuZGFyZC1iYXNlNjQHZXhhbXBsZQNjb20AAAEAAQ
   accept = application/dns-message

Thus, DNS traffic is concealed within HTTPS traffic. The client and server communicate over the standard port 443. As a result, requests to the domain name system remain anonymous.

Why It's Not Welcomed

Opponents of DNS over HTTPS sayargue that the new protocol will decrease the security of connections. According to words Paul Vixie, a member of the DNS development team, it will be more difficult for system administrators to block potentially malicious sites. Regular users will lose the ability to set up conditional parental controls in browsers.

Paul's opinion is shared by UK internet providers. The laws of the country require them to block resources with prohibited content. However, support for DoH in browsers complicates the task of traffic filtering. Among the critics of the new protocol are also the UK's Government Communications Headquarters (GCHQ) and the Internet Watch Foundation (IWF), which maintains a registry of blocked resources.

On our blog on Habr:

Experts note that DNS over HTTPS could pose a cybersecurity threat. In early July, cybersecurity specialists from Netlab discovered the first virus that used the new protocol for conducting DDoS attacks — Godlua. The malware used DoH to obtain text records (TXT) and extract URLs of control servers.

Encrypted DoH requests were not recognized by antivirus software. Cybersecurity experts fear, that after Godlua, other malware will come, invisible to passive DNS monitoring.

But not everyone is against it

In defense of DNS over HTTPS, on their blog commented engineer from APNIC Geoff Houston. According to him, the new protocol will help combat DNS hijacking attacks, which have become increasingly common recently. This fact is confirmed by a January report from cybersecurity company FireEye. The protocol's development was supported by major IT companies.

As early as last year, DoH began testing at Google. And a month ago, the company introduced released the General Availability version of its DoH service. Google hopes, that it will enhance online personal data security and protect against MITM attacks.

Another browser developer — Mozilla — has been using the properties DNS over HTTPS since last summer. The company is actively promoting this new technology in the IT community. Because of this, the Internet Services Providers Association (ISPA) even nominated Mozilla for the 'Internet Villain of the Year' award. In response, company representatives noted, that they are disappointed by the unwillingness of telecom operators to improve outdated internet infrastructure.

"Loves and Doesn't Love": DNS over HTTPS
/ Unsplash / TETrebbien

In support of Mozilla expressed major media outlets and some internet providers. In particular, British Telecom mentioned believe, that the new protocol will not affect content filtering and will enhance security for British users. Under public pressure, ISPA had to retract the 'villainous' nomination.

Cloud providers have also advocated for the implementation of DNS over HTTPS, for example Cloudflare. They are already offering DNS services based on the new protocol. A complete list of browsers and clients supporting DoH is available at GitHub.

In any case, it's too early to speak about the end of the confrontation between the two camps. IT specialists predict that if DNS over HTTPS is destined to become part of the mass stack of internet technologies, it will take more than a decade.

What else we write about in our corporate blog:

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster