Chrome for Android has enabled DNS-over-HTTPS support

Google Inc. announced the beginning of phased activation of the 'DNS over HTTPS' mode for Chrome 85 users on the Android platform. The mode will be gradually enabled, reaching more and more users. Previously, in Chrome 83 activation of DNS-over-HTTPS has begun for desktop system users.

DNS-over-HTTPS will be automatically activated for users whose settings specify DNS providers that support this technology (the same provider used for DNS will be utilized for DNS-over-HTTPS). For instance, if a user has 8.8.8.8 set in their system settings, Chrome will activate Google's DNS-over-HTTPS service ("https://dns.google.com/dns-query"); if the DNS is 1.1.1.1, then Cloudflare's DNS-over-HTTPS service ("https://cloudflare-dns.com/dns-query") will be used, and so on.

To avoid issues with the resolution of corporate intranet networks, DNS-over-HTTPS is not applied when determining the use of the browser in centrally managed systems. DNS-over-HTTPS is also disabled when parental control systems are present. In the event of failures in the operation of DNS-over-HTTPS, there is an option to revert settings to regular DNS. Special options have been added to the browser settings to manage the operation of DNS-over-HTTPS, allowing users to disable DNS-over-HTTPS or select a different provider.

It is worth noting that DNS-over-HTTPS can be useful for preventing leaks of requested hostnames through provider DNS servers, combating MITM attacks and DNS traffic spoofing (for example, when connecting to public Wi-Fi), countering DNS-level blocks (DNS-over-HTTPS cannot replace a VPN for bypassing blocks implemented at the DPI level), or for facilitating operation when direct access to DNS servers is impossible (for instance, when working through a proxy). While standard DNS queries are typically sent directly to the DNS servers specified in the system configuration, with DNS-over-HTTPS, the request to determine a host's IP address is encapsulated in HTTPS traffic and sent to an HTTP server, where the resolver processes requests via the Web API. The existing DNSSEC standard uses encryption only for client and server authentication but does not protect traffic from interception and does not guarantee confidentiality of requests.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster