Mozilla to enable DNS-over-HTTPS support by default for users in the UK due to pressure from the UK Internet Service Providers Association () and the organization (IWF). However, Mozilla is seeking potential partners for broader implementation of DNS-over-HTTPS technology in other European countries. A few days ago, the UK ISPA organization Mozilla for the title of 'Internet Villain' for its work on implementing DNS-over-HTTPS.
Mozilla views DNS-over-HTTPS (DoH) as a tool for ensuring user privacy and security, which eliminates leaks of requested hostnames through provider DNS servers, helps combat MITM attacks and DNS traffic spoofing, counters DNS-level blocking, and allows operation even when direct access to DNS servers is not possible (for example, when working through a proxy). In a normal situation, DNS queries are sent directly to the DNS servers specified in the system configuration, but in the case of DoH, the request to resolve the host's IP address is encapsulated in HTTPS traffic and sent in encrypted form to one of the centralized DoH servers, bypassing the provider's DNS servers.
From the perspective of the UK ISPA, the DNS-over-HTTPS protocol threatens user security and undermines the internet security standards established in the UK, as it simplifies the circumvention of blocks and filters imposed by providers in compliance with regulatory requirements in the UK or when organizing parental control systems. In many cases, such blocks are implemented through DNS request filtering, and the use of DNS-over-HTTP nullifies the effectiveness of these systems.
Source: opennet.ru
