Mozilla is moving to enable DNS-over-HTTPS by default in Firefox

Firefox Developers announced about the completion of testing support for DNS over HTTPS (DoH) and the intention to enable this technology by default for users in the U.S. at the end of September. The rollout will be gradual, initially for a small percentage of users, gradually increasing to 100% if no issues arise. After covering the U.S., the possibility of enabling DoH in other countries will be considered.

Tests conducted over the year have shown the reliability and good performance of the service, as well as identified some situations where DoH may cause issues and developed solutions to workaround these (for instance, concerning issues traffic optimization in content delivery networks, parental control, and corporate internal DNS zones).

The importance of encrypting DNS traffic is seen as a fundamental factor in protecting users; therefore, DoH is decided to be enabled by default, but initially only for users in the U.S. After activation of DoH, a warning will be displayed to users, allowing them to opt out of connecting to centralized DoH DNS servers and revert to the traditional method of sending unencrypted requests to the provider's DNS server (as opposed to the distributed infrastructure of DoH resolvers, which ties to a specific DoH service that can be viewed as a single point of failure).

Upon activation of DoH, there may be disruptions in parental control systems and corporate networks that use a DNS naming structure available only within the internal network to resolve intranet addresses and corporate hosts. To address issues with such systems, a system of checks has been added that automatically disables DoH. These checks are performed each time the browser is launched or when a subnet change is detected.

Automatic fallback to the use of the operating system's native resolver is also provided in the event of failures when resolving through DoH (for instance, due to network availability issues with the DoH provider or failures in its infrastructure). The rationale behind such checks is questionable, as attackers controlling the resolver or capable of interfering with traffic can simulate such behavior to disable DNS traffic encryption. The issue has been resolved by adding a 'DoH always' setting (disabled by default), which, when enabled, prevents automatic disabling, providing a reasonable compromise.

To identify corporate resolvers, checks for atypical top-level domains (TLDs) are performed, and system resolvers return intranet addresses. To determine if parental controls are enabled, an attempt to resolve the name exampleadultsite.com is made, and if the result does not match the actual IP, it is considered that adult content blocking is active at the DNS level. Signs also include checking Google's and YouTube's IP addresses for possible substitutions with restrict.youtube.com, forcesafesearch.google.com, and restrictmoderate.youtube.com. Additionally, Mozilla offers implement a unified test host use-application-dns.net, which can be utilized by internet providers and parental control services as a marker to disable DoH (if the host cannot be resolved, Firefox disables DoH).

Working through a single DoH service can potentially lead to traffic optimization issues in content delivery networks that perform load balancing using DNS (the CDN network's DNS server formulates a response based on the resolver's address and issues the nearest host for content retrieval). Sending a DNS query from a resolver closest to the user in such CDNs results in returning the address of the host nearest to the user, but when sending a DNS query from a centralized resolver, the address of the host closest to the DNS-over-HTTPS server will be issued. Practical testing has shown that using DNS-over-HTTP with CDNs practically did not lead to delays before content delivery begins (for fast connections, delays did not exceed 10 milliseconds, and even acceleration was observed on slow channels). The use of the EDNS Client Subnet extension was also considered to convey the client's location to the CDN resolver.

It is worth noting that DoH can be useful for preventing the leakage of information about requested hostnames through provider DNS servers, combating MITM attacks and DNS traffic tampering, resisting DNS-level blocking, or for facilitating operation in cases where direct access to DNS servers is not possible (for instance, when working through a proxy). In a normal scenario, DNS queries are sent directly to the DNS servers specified in the system configuration, whereas in the case of DoH, the request to resolve the host's IP address is encapsulated within HTTPS traffic and sent to an HTTP server where the resolver processes requests via a Web API. The existing DNSSEC standard uses encryption only for client and server authentication, but does not protect traffic from interception nor guarantees the confidentiality of requests.

To enable DoH in about:config, you need to change the value of the variable network.trr.mode, which is supported starting from Firefox 60. The value 0 completely disables DoH; 1 uses DNS or DoH, depending on which is faster; 2 uses DoH by default, with DNS as a backup; 3 uses only DoH; 4 is a mirroring mode where DoH and DNS are used in parallel. By default, the CloudFlare DNS server is used, but it can be changed via the parameter network.trr.uri; for example, you can set it to "https://dns.google.com/experimental" or "https://9.9.9.9/dns-query."

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster