An experiment related to DNS-over-HTTPS will be conducted in Firefox.

Mozilla developers informed about a new study being conducted in preparation for the implementation of DNS over HTTPS (DoH, DNS over HTTPS). During the experiment, statistics will be collected on the use of parental control systems and corporate resolvers among users of Firefox releases in the USA. Participants can opt out of the experiment via the 'about:studies' page (the study is listed as 'Detection Logic for DNS-over-HTTPS').

The study will collect anonymized data that includes only counters, without specific addresses or domains. To identify parental control systems, a request will be sent to resolve the name exampleadultsite.com, and if it does not match the actual IP, it can be concluded that adult content blocking is active at the DNS level. The results for Google and YouTube will also be evaluated to check for redirection to restrict.youtube.com, forcesafesearch.google.com, and restrictmoderate.youtube.com. an IP address checked for unusual top-level domains (TLDs) and whether intranet addresses are returned for them. The experiment was motivated by concerns that enabling DNS over HTTPS by default might disrupt the functioning of existing parental control systems relying on DNS, and also create issues for users in corporate networks that utilize DNS servers providing information about internal domains not visible on the external network.

The initiative to reduce application sizes in Fedora

It is worth noting that DoH can be useful for preventing the leakage of information about requested hostnames through provider DNS servers, combating MITM attacks and DNS traffic tampering, resisting DNS-level blocking, or for facilitating operation in cases where direct access to DNS servers is not possible (for instance, when working through a proxy). In a normal scenario, DNS queries are sent directly to the DNS servers specified in the system configuration, whereas in the case of DoH, the request to resolve the host's IP address is encapsulated within HTTPS traffic and sent to an HTTP server where the resolver processes requests via a Web API. The existing DNSSEC standard uses encryption only for client and server authentication, but does not protect traffic from interception nor guarantees the confidentiality of requests.

To enable DoH in about:config, you need to change the value of the variable network.trr.mode, which is supported starting from Firefox 60. The value 0 completely disables DoH; 1 uses DNS or DoH, depending on which is faster; 2 uses DoH by default, with DNS as a backup; 3 uses only DoH; 4 is a mirroring mode where DoH and DNS are used in parallel. By default, the CloudFlare DNS server is used, but it can be changed via the parameter network.trr.uri; for example, you can set it to "https://dns.google.com/experimental" or "https://9.9.9.9/dns-query."

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster