{"id":38121,"date":"2019-10-31T22:21:46","date_gmt":"2019-10-31T19:21:46","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https\/"},"modified":"2019-10-31T22:21:46","modified_gmt":"2019-10-31T19:21:46","slug":"v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https","title":{"rendered":"Experiments will begin in Chrome 78 to enable DNS-over-HTTPS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Following <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51439\">Mozilla<\/a><\/noindex> Google company <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.chromium.org\/2019\/09\/experimenting-with-same-provider-dns.html\">has announced<\/a><\/noindex> about the intention to conduct an experiment to test the implementation of 'DNS over HTTPS' (DoH) being developed for the Chrome browser. In the upcoming release of Chrome 78, scheduled for October 22, some user categories will have this enabled by default. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.chromium.org\/developers\/dns-over-https\">translated<\/a><\/noindex> In the experiment to enable DoH, only users whose current system settings specify certain DNS providers recognized as compatible with DoH will participate. <\/p>\n<p>The whitelist of DNS providers includes <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/tips\/info\/3087.shtml\">services<\/a><\/noindex> Google (8.8.8.8, 8.8.4.4), Cloudflare (1.1.1.1, 1.0.0.1), OpenDNS (208.67.222.222, 208.67.220.220), Quad9 (9.9.9.9, 149.112.112.112), Cleanbrowsing (185.228.168.168, 185.228.169.168), and DNS.SB (185.222.222.222, 185.184.222.222). If a user has one of the aforementioned DNS servers in their DNS settings, DoH will be activated by default in Chrome. For those using DNS servers provided by their local internet service provider, everything will remain unchanged, and system resolver will continue to be used for DNS queries. <\/p>\n<p>An important difference from the implementation of DoH in Firefox, where the phased enabling of DoH by default <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51439\">will begin<\/a><\/noindex> already at the end of September, is the lack of binding to a single DoH service. While in Firefox the default <noindex><a rel=\"nofollow\" href=\"https:\/\/support.mozilla.org\/en-US\/kb\/firefox-dns-over-https\">a layer<\/a><\/noindex> DNS server is CloudFlare, in Chrome only the method of working with DNS will be updated to an equivalent service without changing the DNS provider. For example, if a user has the DNS 8.8.8.8 specified in system settings, then Chrome will <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.google.com\/document\/d\/15Ss0OaJeb-T3g2RMwgikHvsC0CPKd-MLeGeetv1wYY4\/edit#\">activated<\/a><\/noindex> Google's DoH service ('https:\/\/dns.google.com\/dns-query'), and if the DNS is 1.1.1.1, then the DoH service from Cloudflare ('https:\/\/cloudflare-dns.com\/dns-query'). <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/curl\/curl\/wiki\/DNS-over-HTTPS#publicly-available-servers\">etc.<\/a><\/noindex><\/p>\n<p>Users will have the option to enable or disable DoH using the setting 'chrome:\/\/flags\/#dns-over-https'. Three operational modes are supported: 'secure', 'automatic', and 'off'. In 'secure' mode, hosts are resolved solely based on previously cached secure values (obtained via a secure connection) and queries made through DoH, with no fallback to regular DNS. In 'automatic' mode, if DoH and secure cache are unavailable, data may be retrieved from an insecure cache and requests made through traditional DNS. In 'off' mode, the default cache is checked first, and if no data is found, the request is sent via system DNS. The mode is set through <noindex><a rel=\"nofollow\" href=\"https:\/\/cs.chromium.org\/chromium\/src\/net\/dns\/dns_config.h?l=27&#038;rcl=3cf5b735fc8dcce6d9d8a5a9591d2a3700dceca4\">the setting<\/a><\/noindex> kDnsOverHttpsMode, and the server matching template through kDnsOverHttpsTemplates.<\/p>\n<p>The experiment to enable DoH will be conducted on all platforms supported in Chrome, except for Linux and iOS due to the complexity of parsing resolver settings and limitations in accessing system DNS settings. In the event that issues arise after enabling DoH with requests to the DoH server (e.g., due to its blockage, network connectivity disruptions, or outages), the browser will automatically revert to the system DNS settings. <\/p>\n<p>The aim of the experiment is to conduct a final verification of the DoH implementation and to study its impact on performance. It is worth noting that support for DoH was actually added <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=799753\">has added<\/a><\/noindex> to the Chrome codebase back in February, but enabling and configuring DoH <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/tips\/3120_chrome_firefox_dns_doh_https_crypt_privacy.shtml\">required<\/a><\/noindex> launching Chrome with a special flag and a non-obvious set of options.<\/p>\n<p>It is important to remember that DoH can be beneficial in preventing leaks of information about requested hostnames through provider DNS servers, combating MITM attacks, and DNS traffic spoofing (for instance, when connecting to public Wi-Fi), resisting DNS-level blocks (DoH cannot replace VPNs when it comes to bypassing restrictions implemented at the DPI level), or for enabling functionality in situations where direct access to DNS servers is not possible (e.g., when working through a proxy). While in a regular situation, DNS requests are sent directly to the DNS servers specified in the system configuration, with DoH, the request to determine the host's IP address is encapsulated in HTTPS traffic and sent to an HTTP server, where the resolver processes the requests through a Web API. The existing DNSSEC standard only uses encryption for client and server authentication, but does not protect traffic from interception and does not guarantee the confidentiality of requests. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51488\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Mozilla \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e \u043d\u0430\u043c\u0435\u0440\u0435\u043d\u0438\u0438 \u043f\u0440\u043e\u0432\u0435\u0441\u0442\u0438 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430 Chrome \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 &#171;DNS \u043f\u043e\u0432\u0435\u0440\u0445 HTTPS&#187; (DoH, DNS over HTTPS). \u0412 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Chrome 78, \u043d\u0430\u043c\u0435\u0447\u0435\u043d\u043d\u043e\u043c \u043d\u0430 22 \u043e\u043a\u0442\u044f\u0431\u0440\u044f, \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0431\u0443\u0434\u0443\u0442 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0435\u0440\u0435\u0432\u0435\u0434\u0435\u043d\u044b \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 DoH. \u0412 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0435 \u043f\u043e \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044e DoH \u043f\u0440\u0438\u043c\u0443\u0442 \u0443\u0447\u0430\u0441\u0442\u0438\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438, \u0432 \u0442\u0435\u043a\u0443\u0449\u0438\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u043d\u0430\u0441\u0442\u043e\u0439\u043a\u0430\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38121","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Mozilla \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Chrome 78 \u043d\u0430\u0447\u043d\u0443\u0442\u0441\u044f \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u044b \u0441 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435\u043c DNS-over-HTTPS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Mozilla \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:21:46+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:21:46+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Experiments with enabling DNS-over-HTTPS will begin in Chrome 78 | ProHoster","description":"Following Mozilla, Google","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Chrome 78 \u043d\u0430\u0447\u043d\u0443\u0442\u0441\u044f \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u044b \u0441 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435\u043c DNS-over-HTTPS | ProHoster","og:description":"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Mozilla \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-chrome-78-nachnutsya-eksperimenty-s-vklyucheniem-dns-over-https","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:21:46+00:00","article:modified_time":"2019-10-31T19:21:46+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38121","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 20:32:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:14:23","updated":"2026-01-23 20:32:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38121"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38121\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}