DNS-over-HTTPS ื™ื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืคื™ื™ืจืคื•ืงืก ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืงื ื“ื™ื™ื

ืžืคืชื—ื™ ืคื™ื™ืจืคื•ืงืก ื”ื›ืจื™ื–ื• ืขืœ ื”ืจื—ื‘ืช ืžืฆื‘ DNS over HTTPS (DoH), ืืฉืจ ื™ื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ื‘ืงื ื“ื” (ื‘ืขื‘ืจ, DoH ื”ื™ื” ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืขื‘ื•ืจ ืืจื”"ื‘ ื‘ืœื‘ื“). ื”ืคืขืœืช DoH ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืงื ื“ื™ื™ื ืžื—ื•ืœืงืช ืœืžืกืคืจ ืฉืœื‘ื™ื: ื‘-20 ื‘ื™ื•ืœื™, DoH ื™ื•ืคืขืœ ืขื‘ื•ืจ 1% ืžื”ืžืฉืชืžืฉื™ื ื”ืงื ื“ื™ื™ื, ื•ืœืžืขื˜ ื‘ืขื™ื•ืช ื‘ืœืชื™ ืฆืคื•ื™ื•ืช, ื”ื›ื™ืกื•ื™ ื™ื•ื’ื“ืœ ืœ-100% ืขื“ ืกื•ืฃ ืกืคื˜ืžื‘ืจ.

ื”ืžืขื‘ืจ ืฉืœ ืžืฉืชืžืฉื™ ืคื™ื™ืจืคื•ืงืก ืงื ื“ื™ื™ื ืœ-DoH ืžืชื‘ืฆืข ื‘ื”ืฉืชืชืคื•ืช CIRA (Canadian Internet Registration Authority), ื”ืžืกื“ื™ืจื” ืืช ื”ืชืคืชื—ื•ืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืงื ื“ื” ื•ืื—ืจืื™ืช ืขืœ ื”ืชื—ื•ื ื‘ืจืžื” ื”ืขืœื™ื•ื ื” "ca". CIRA ื’ื ื ืจืฉืžื” ืœ-TRR (Recursive Resolver ืžื”ื™ืžืŸ) ื•ื”ื™ื ืื—ืช ืžืกืคืงื™ื•ืช ื”-DNS-over-HTTPS ื”ื–ืžื™ื ื•ืช ื‘ืคื™ื™ืจืคื•ืงืก.

ืœืื—ืจ ื”ืคืขืœืช DoH, ืชื•ืฆื’ ืื–ื”ืจื” ื‘ืžืขืจื›ืช ื”ืžืฉืชืžืฉ, ื”ืžืืคืฉืจืช, ืื ืชืจืฆื”, ืœืกืจื‘ ืœืžืขื‘ืจ ืœ-DoH ื•ืœื”ืžืฉื™ืš ืœื”ืฉืชืžืฉ ื‘ืกื›ื™ืžื” ื”ืžืกื•ืจืชื™ืช ืฉืœ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืœื ืžื•ืฆืคื ื•ืช ืœืฉืจืช ื”-DNS ืฉืœ ื”ืกืคืง. ืืชื” ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ื”ืกืคืง ืื• ืœื”ืฉื‘ื™ืช ืืช DoH ื‘ื”ื’ื“ืจื•ืช ื”ื—ื™ื‘ื•ืจ ืœืจืฉืช. ื‘ื ื•ืกืฃ ืœืฉืจืชื™ CIRA DoH, ืืชื” ื™ื›ื•ืœ ืœื‘ื—ื•ืจ ื‘ืฉื™ืจื•ืชื™ Cloudflare ื•-NextDNS.

DNS-over-HTTPS ื™ื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืคื™ื™ืจืคื•ืงืก ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืงื ื“ื™ื™ื

ืกืคืงื™ DoH ื”ืžื•ืฆืขื™ื ื‘ืคื™ื™ืจืคื•ืงืก ื ื‘ื—ืจื™ื ื‘ื”ืชืื ืœื“ืจื™ืฉื•ืช ืœืคื•ืชืจื™ DNS ืžื”ื™ืžื ื™ื, ืœืคื™ื”ื ืžืคืขื™ืœ ื”-DNS ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื ืชื•ื ื™ื ื”ืžืชืงื‘ืœื™ื ืœืคืชืจื•ืŸ ืจืง ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืืช ืคืขื•ืœืช ื”ืฉื™ืจื•ืช, ืืกื•ืจ ืœืื—ืกืŸ ืœื•ื’ื™ื ื™ื•ืชืจ ืž-24 ืฉืขื•ืช, ื•ืื™ื ื• ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ื ืชื•ื ื™ื ืœืฆื“ื“ื™ื ืฉืœื™ืฉื™ื™ื ื•ื ื“ืจืฉ ืœื—ืฉื•ืฃ ืžื™ื“ืข ืขืœ ืฉื™ื˜ื•ืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื. ืขืœ ื”ืฉื™ืจื•ืช ื’ื ืœื”ืกื›ื™ื ืฉืœื ืœืฆื ื–ืจ, ืœืกื ืŸ, ืœื”ืคืจื™ืข ืื• ืœื—ืกื•ื ืชืขื‘ื•ืจืช DNS, ืืœื ื‘ืžืฆื‘ื™ื ื”ืงื‘ื•ืขื™ื ื‘ื—ื•ืง.

ื ื–ื›ื™ืจ ื›ื™ DoH ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœืžื ื™ืขืช ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื”ืžื‘ื•ืงืฉื™ื ื“ืจืš ืฉืจืชื™ ื”-DNS ืฉืœ ืกืคืงื™ื, ืžืื‘ืง ื‘ื”ืชืงืคื•ืช MITM ื•ื–ื™ื•ืฃ ืชืขื‘ื•ืจืช DNS (ืœื“ื•ื’ืžื”, ื‘ืขืช ื—ื™ื‘ื•ืจ ืœ-Wi-Fi ืฆื™ื‘ื•ืจื™), ืžื ื™ืขืช ื—ืกื™ืžื” ื‘-DNS ืจืžืช (DoH ืœื ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ VPN ื‘ืชื—ื•ื ืฉืœ ืขืงื™ืคืช ื—ืกื™ืžื” ื”ืžื™ื•ืฉืžืช ื‘ืจืžืช DPI) ืื• ืœืืจื’ื•ืŸ ืขื‘ื•ื“ื” ืื ืื™ ืืคืฉืจ ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS (ืœื“ื•ื’ืžื”, ื‘ืขื‘ื•ื“ื” ื“ืจืš ืคืจื•ืงืกื™). ืื ื‘ืžืฆื‘ ืจื’ื™ืœ ื‘ืงืฉื•ืช DNS ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS ื”ืžื•ื’ื“ืจื™ื ื‘ืชืฆื•ืจืช ื”ืžืขืจื›ืช, ืื– ื‘ืžืงืจื” ืฉืœ DoH, ื”ื‘ืงืฉื” ืœืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืืจื— ืžื•ื‘ืœืขืช ื‘ืชืขื‘ื•ืจืช HTTPS ื•ื ืฉืœื—ืช ืœืฉืจืช ื”-HTTP, ืฉื ื”ืคื•ืชืจ ืžืขื‘ื“ ื‘ืงืฉื•ืช ื“ืจืš ื”-API ืฉืœ ื”ืื™ื ื˜ืจื ื˜. ืชืงืŸ DNSSEC ื”ืงื™ื™ื ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” ืจืง ื›ื“ื™ ืœืืžืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ืื™ื ื• ืžื’ืŸ ืขืœ ื”ืชืขื‘ื•ืจื” ืžืคื ื™ ื™ื™ืจื•ื˜ ื•ืื™ื ื• ืžื‘ื˜ื™ื— ืืช ืกื•ื“ื™ื•ืช ื”ื‘ืงืฉื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”