DNS-over-HTTPS za a kunna ta tsohuwa a Firefox don masu amfani da Kanada

Masu haɓaka Firefox sun ba da sanarwar faɗaɗa DNS akan yanayin HTTPS (DoH), wanda za a kunna ta tsohuwa don masu amfani a Kanada (a da, DoH shine kawai tsoho na Amurka). Ba da damar DoH ga masu amfani da Kanada ya kasu kashi da yawa: A ranar 20 ga Yuli, za a kunna DoH don 1% na masu amfani da Kanada kuma, hana matsalolin da ba zato ba tsammani, za a ƙara ɗaukar hoto zuwa 100% a ƙarshen Satumba.

Canjin masu amfani da Firefox na Kanada zuwa DoH ana aiwatar da shi tare da haɗin gwiwar CIRA (Hukumar Rajista ta Intanet ta Kanada), wacce ke tsara haɓaka Intanet a Kanada kuma ke da alhakin babban matakin yanki "ca". CIRA kuma ta yi rajista don TRR (Trusted Recursive Resolver) kuma yana ɗaya daga cikin masu samar da DNS-over-HTTPS da ake samu a Firefox.

Bayan kunna DoH, za a nuna gargadi akan tsarin mai amfani, yana ba da damar, idan ana so, don ƙin canzawa zuwa DoH kuma a ci gaba da amfani da tsarin gargajiya na aika buƙatun da ba a ɓoye ba zuwa uwar garken DNS na mai bayarwa. Kuna iya canza mai badawa ko musaki DoH a cikin saitunan haɗin cibiyar sadarwa. Baya ga sabobin CIRA DoH, zaku iya zaɓar sabis na Cloudflare da NextDNS.

DNS-over-HTTPS za a kunna ta tsohuwa a Firefox don masu amfani da Kanada

Ana zaɓar masu samar da DoH da aka bayar a cikin Firefox daidai da buƙatun don amintattun masu warware DNS, gwargwadon abin da ma'aikacin DNS zai iya amfani da bayanan da aka karɓa don ƙuduri kawai don tabbatar da aikin sabis ɗin, ba dole ba ne a adana rajistan ayyukan fiye da sa'o'i 24, kuma ba zai iya ba. canja wurin bayanai zuwa ɓangare na uku kuma ana buƙatar bayyana bayanai game da hanyoyin sarrafa bayanai. Sabis ɗin kuma dole ne ya yarda ba don tantancewa, tacewa, tsoma baki ko toshe zirga-zirgar DNS ba, sai dai a cikin yanayin da doka ta tanadar.

Bari mu tuna cewa DoH na iya zama da amfani don hana leaks na bayanai game da sunayen rundunar da ake buƙata ta hanyar sabar DNS na masu samarwa, yaƙar hare-haren MITM da ɓarkewar zirga-zirgar ababen hawa na DNS (misali, lokacin haɗawa da Wi-Fi na jama'a), hana toshewa a DNS. matakin (DoH ba zai iya maye gurbin VPN ba a cikin yanki na toshe toshewa wanda aka aiwatar a matakin DPI) ko don tsara aiki idan ba zai yiwu ba kai tsaye zuwa sabar DNS (misali, lokacin aiki ta hanyar wakili). Idan a cikin yanayi na al'ada ana aika buƙatun DNS kai tsaye zuwa sabar DNS da aka ayyana a cikin tsarin tsarin, to, a cikin yanayin DoH, buƙatar tantance adireshin IP ɗin mai watsa shiri yana cikin zirga-zirgar HTTPS kuma a aika zuwa uwar garken HTTP, inda masu warware matsalar ke aiwatarwa. buƙatun ta hanyar API ɗin Yanar Gizo. Ma'auni na DNSSEC na yanzu yana amfani da ɓoyewa kawai don tabbatar da abokin ciniki da uwar garken, amma baya kare zirga-zirga daga shiga tsakani kuma baya bada garantin sirrin buƙatun.

source: budenet.ru

Add a comment