{"id":38615,"date":"2019-10-31T22:24:52","date_gmt":"2019-10-31T19:24:52","guid":{"rendered":"https:\/\/prohoster.info\/blog\/assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https\/"},"modified":"2019-10-31T22:24:52","modified_gmt":"2019-10-31T19:24:52","slug":"assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https","title":{"rendered":"U.S. provider associations opposed the centralization in implementing DNS-over-HTTPS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Trade Associations <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/NCTA_(association)\">NCTA<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/CTIA_(organization)\">CTIA<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/United_States_Telecom_Association\">USTelecom<\/a><\/noindex>, advocating for the interests of internet providers,  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ncta.com\/sites\/default\/files\/2019-09\/Final%20DOH%20LETTER%209-19-19.pdf\">have appealed<\/a><\/noindex> to the US Congress requesting attention to the issue of implementing \"DNS over HTTPS\" (DoH) and to ask Google for detailed information about the current and future plans to include DoH in its products, as well as to obtain a commitment not to enable centralized DNS query processing in Chrome and Android by default without prior comprehensive discussion with other ecosystem representatives and consideration of potential negative consequences.<\/p>\n<p>Understanding the overall benefits of encryption for DNS traffic, the associations consider it unacceptable to concentrate control over name resolution in a single hand and to tie this mechanism by default to centralized DNS services. In particular, it is claimed that Google is moving towards implementing DoH by default in Android and Chrome, which, if tied to Google's servers, will violate the decentralized nature of the DNS infrastructure and create a single point of failure.<\/p>\n<p>Since Chrome and Android dominate the market, if Google enforces its DoH servers, it will gain the ability to control a large portion of users' DNS request flows. Besides reducing the reliability of the infrastructure, such a move will also give Google unjust advantages over competitors, as the company will gain additional insights into user actions that can be used for tracking user activities and targeting relevant advertising. <\/p>\n<p>The implementation of DoH may also disrupt operations in areas such as parental control systems, access to internal namespaces in corporate systems, route selection in content delivery optimization systems, and the execution of court orders in combating the spread of illegal content and the exploitation of minors. DNS spoofing is also often used to redirect users to a page with information about the subscriber's funds running out or to log into a wireless network.<\/p>\n<p>Google Inc. <noindex><a rel=\"nofollow\" href=\"https:\/\/arstechnica.com\/tech-policy\/2019\/09\/isps-worry-a-new-chrome-feature-will-stop-them-from-spying-on-you\/\">declared<\/a><\/noindex>, that the concerns are unfounded, as it does not intend to enable DoH in Chrome and Android by default. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51488\">Planned<\/a><\/noindex> In Chrome 78, the experimental default enabling of DoH will only cover users whose settings specify DNS providers that offer DoH as an alternative to traditional DNS. For those using DNS servers provided by their local internet service providers, DNS requests will continue to be sent through the system resolver. In other words, Google's actions amount to merely replacing the current provider's service with an equivalent one to transition to a secured method of working with DNS. The experimental enabling of DoH is also planned in Firefox, but unlike Google, Mozilla's approach differs. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51439\">intended<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/support.mozilla.org\/en-US\/kb\/firefox-dns-over-https\">to use<\/a><\/noindex> CloudFlare's DNS server by default. This approach has already sparked <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51471\">criticism<\/a><\/noindex> from the OpenBSD project.<\/p>\n<p>It is worth noting that DoH can be useful to prevent leaks of information about queried hostnames through providers' DNS servers, combat MITM attacks and DNS traffic spoofing (for example, when connecting to public Wi-Fi), counter DNS-level blocking (DoH cannot replace VPNs in bypassing blocks implemented at the DPI level), or for enabling functionality when direct access to DNS servers is not possible (for example, when working through a proxy). <\/p>\n<p>While typically DNS requests are sent directly to the DNS servers specified in the system configuration, in the case of DoH, the request to resolve the host's IP address is encapsulated in HTTPS traffic and sent to an HTTP server, where the resolver processes requests via a Web API. The existing DNSSEC standard uses encryption only for authenticating the client and server but does not protect traffic from interception and does not guarantee the confidentiality of requests. Currently, around <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/curl\/curl\/wiki\/DNS-over-HTTPS#publicly-available-servers\">30 public DNS servers<\/a><\/noindex> support DoH.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51602\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0422\u043e\u0440\u0433\u043e\u0432\u044b\u0435 \u0430\u0441\u0441\u043e\u0446\u0438\u0430\u0446\u0438\u0438 NCTA, CTIA \u0438 USTelecom, \u043e\u0442\u0441\u0442\u0430\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u044b \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432, \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438\u0441\u044c \u0432 \u041a\u043e\u043d\u0433\u0440\u0435\u0441\u0441 \u0421\u0428\u0410 \u0441 \u043f\u0440\u043e\u0441\u044c\u0431\u043e\u0439 \u043e\u0431\u0440\u0430\u0442\u0438\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0441 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0435\u043c &#171;DNS \u043f\u043e\u0432\u0435\u0440\u0445 HTTPS&#187; (DoH, DNS over HTTPS) \u0438 \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u0442\u044c \u0443 Google \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u0443\u044e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0442\u0435\u043a\u0443\u0449\u0438\u0445 \u0438 \u0431\u0443\u0434\u0443\u0449\u0438\u0445 \u043f\u043b\u0430\u043d\u0430\u0445 \u043f\u043e \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044e DoH \u0432 \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u0430\u0445, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u0441\u0442\u0432\u043e \u043d\u0435 \u0432\u043a\u043b\u044e\u0447\u0430\u0442\u044c \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u0443\u044e \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38615","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0422\u043e\u0440\u0433\u043e\u0432\u044b\u0435 \u0430\u0441\u0441\u043e\u0446\u0438\u0430\u0446\u0438\u0438 NCTA,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0441\u0441\u043e\u0446\u0438\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432 \u0421\u0428\u0410 \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b\u0438 \u043f\u0440\u043e\u0442\u0438\u0432 \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u0438 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0438 DNS-over-HTTPS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0422\u043e\u0440\u0433\u043e\u0432\u044b\u0435 \u0430\u0441\u0441\u043e\u0446\u0438\u0430\u0446\u0438\u0438 NCTA,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:52+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:52+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47US Providers Association has opposed centralization in the implementation of DNS-over-HTTPS | ProHoster","description":"Trade associations NCTA,","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0441\u0441\u043e\u0446\u0438\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432 \u0421\u0428\u0410 \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b\u0438 \u043f\u0440\u043e\u0442\u0438\u0432 \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u0438 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0438 DNS-over-HTTPS | ProHoster","og:description":"\u0422\u043e\u0440\u0433\u043e\u0432\u044b\u0435 \u0430\u0441\u0441\u043e\u0446\u0438\u0430\u0446\u0438\u0438 NCTA,","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/assotsiatsii-provajderov-ssha-vystupili-protiv-tsentralizatsii-pri-vnedrenii-dns-over-https","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:52+00:00","article:modified_time":"2019-10-31T19:24:52+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38615","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:45:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:06:24","updated":"2026-01-23 22:45:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38615"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38615\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}