DNS-over-HTTPS ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘-Firefox ืขื‘ื•ืจ ืžืฉืชืžืฉื™ ืืจื”"ื‘

ืžืคืชื—ื™ ืคื™ื™ืจืคื•ืงืก ื”ื•ื›ืจื– ืขืœ ื”ืคืขืœืช ืžืฆื‘ DNS over HTTPS (DoH, DNS over HTTPS) ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ื‘ืืจื”"ื‘. ื”ืฆืคื ื” ืฉืœ ืชืขื‘ื•ืจืช DNS ื ื—ืฉื‘ืช ืœื’ื•ืจื ื—ืฉื•ื‘ ื‘ื™ืกื•ื“ื• ื‘ื”ื’ื ื” ืขืœ ื”ืžืฉืชืžืฉื™ื. ื”ื—ืœ ืžื”ื™ื•ื, ื›ืœ ื”ื”ืชืงื ื•ืช ื”ื—ื“ืฉื•ืช ืฉืœ ืžืฉืชืžืฉื™ ืืจื”"ื‘ ื™ื•ืคืขืœื• DoH ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืžืฉืชืžืฉื™ื ืงื™ื™ืžื™ื ื‘ืืจื”"ื‘ ืืžื•ืจื™ื ืœืขื‘ื•ืจ ืœ-DoH ืชื•ืš ืžืกืคืจ ืฉื‘ื•ืขื•ืช. ื‘ืื™ื—ื•ื“ ื”ืื™ืจื•ืคื™ ื•ื‘ืžื“ื™ื ื•ืช ืื—ืจื•ืช, ื”ืคืขืœ ืืช DoH ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœืขืช ืขืชื” ืœื ืœืชื›ื ืŸ.

ืœืื—ืจ ื”ืคืขืœืช DoH, ืžื•ืฆื’ืช ืื–ื”ืจื” ืœืžืฉืชืžืฉ, ื”ืžืืคืฉืจืช, ืื ืชืจืฆื”, ืœืกืจื‘ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืชื™ DoH DNS ืžืจื›ื–ื™ื™ื ื•ืœื—ื–ื•ืจ ืœืกื›ื™ืžื” ื”ืžืกื•ืจืชื™ืช ืฉืœ ืฉืœื™ื—ืช ืฉืื™ืœืชื•ืช ืœื ืžื•ืฆืคื ื•ืช ืœืฉืจืช ื”-DNS ืฉืœ ื”ืกืคืง. ื‘ืžืงื•ื ืชืฉืชื™ืช ืžื‘ื•ื–ืจืช ืฉืœ ืคื•ืชืจื™ DNS, DoH ืžืฉืชืžืฉ ื‘ืงื™ืฉื•ืจ ืœืฉื™ืจื•ืช DoH ืกืคืฆื™ืคื™, ืฉื™ื›ื•ืœ ืœื”ื™ื—ืฉื‘ ื›ื ืงื•ื“ืช ื›ืฉืœ ื‘ื•ื“ื“ืช. ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ื”ืขื‘ื•ื“ื” ืžื•ืฆืขืช ื“ืจืš ืฉื ื™ ืกืคืงื™ DNS - CloudFlare (ื‘ืจื™ืจืช ืžื—ื“ืœ) ื• NextDNS.

DNS-over-HTTPS ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘-Firefox ืขื‘ื•ืจ ืžืฉืชืžืฉื™ ืืจื”"ื‘

ืฉื ื” ืกืคืง ืื• ื”ืฉื‘ืช ืืช DoH ืื—ื“ ื™ื›ื•ืœ ื‘ื”ื’ื“ืจื•ืช ื”ื—ื™ื‘ื•ืจ ืœืจืฉืช. ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ืฉืจืช DoH ื—ืœื•ืคื™ "https://dns.google/dns-query" ื›ื“ื™ ืœื’ืฉืช ืœืฉืจืชื™ Google, "https://dns.quad9.net/dns-query" - Quad9 ื•-"https:/ /doh .opendns.com/dns-query" - OpenDNS. About:config ืžืกืคืงืช ื’ื ืืช ื”ื’ื“ืจืช network.trr.mode, ืฉื“ืจื›ื” ื ื™ืชืŸ ืœืฉื ื•ืช ืืช ืžืฆื‘ ื”ื”ืคืขืœื” ืฉืœ DoH: ืขืจืš ืฉืœ 0 ืžืฉื‘ื™ืช ืœื—ืœื•ื˜ื™ืŸ ืืช DoH; 1 - ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-DNS ืื• DoH, ื”ืžื”ื™ืจ ืžื‘ื™ื ื™ื”ื; 2 - DoH ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื•-DNS ืžืฉืžืฉ ื›ืืคืฉืจื•ืช ื—ื–ืจื”; 3 - ืจืง DoH ืžืฉืžืฉ; 4 - ืžืฆื‘ ืฉื™ืงื•ืฃ ื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-DoH ื•-DNS ื‘ืžืงื‘ื™ืœ.

ื ื–ื›ื™ืจ ื›ื™ DoH ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœืžื ื™ืขืช ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื”ืžื‘ื•ืงืฉื™ื ื“ืจืš ืฉืจืชื™ ื”-DNS ืฉืœ ืกืคืงื™ื, ืžืื‘ืง ื‘ื”ืชืงืคื•ืช MITM ื•ื–ื™ื•ืฃ ืชืขื‘ื•ืจืช DNS (ืœื“ื•ื’ืžื”, ื‘ืขืช ื—ื™ื‘ื•ืจ ืœ-Wi-Fi ืฆื™ื‘ื•ืจื™), ืžื ื™ืขืช ื—ืกื™ืžื” ื‘-DNS ืจืžืช (DoH ืœื ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ VPN ื‘ืชื—ื•ื ืฉืœ ืขืงื™ืคืช ื—ืกื™ืžื” ื”ืžื™ื•ืฉืžืช ื‘ืจืžืช DPI) ืื• ืœืืจื’ื•ืŸ ืขื‘ื•ื“ื” ืื ืื™ ืืคืฉืจ ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS (ืœื“ื•ื’ืžื”, ื‘ืขื‘ื•ื“ื” ื“ืจืš ืคืจื•ืงืกื™). ืื ื‘ืžืฆื‘ ืจื’ื™ืœ ื‘ืงืฉื•ืช DNS ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS ื”ืžื•ื’ื“ืจื™ื ื‘ืชืฆื•ืจืช ื”ืžืขืจื›ืช, ืื– ื‘ืžืงืจื” ืฉืœ DoH, ื”ื‘ืงืฉื” ืœืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืืจื— ืžื•ื‘ืœืขืช ื‘ืชืขื‘ื•ืจืช HTTPS ื•ื ืฉืœื—ืช ืœืฉืจืช ื”-HTTP, ืฉื ื”ืคื•ืชืจ ืžืขื‘ื“ ื‘ืงืฉื•ืช ื“ืจืš ื”-API ืฉืœ ื”ืื™ื ื˜ืจื ื˜. ืชืงืŸ DNSSEC ื”ืงื™ื™ื ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” ืจืง ื›ื“ื™ ืœืืžืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ืื™ื ื• ืžื’ืŸ ืขืœ ื”ืชืขื‘ื•ืจื” ืžืคื ื™ ื™ื™ืจื•ื˜ ื•ืื™ื ื• ืžื‘ื˜ื™ื— ืืช ืกื•ื“ื™ื•ืช ื”ื‘ืงืฉื•ืช.

ื›ื“ื™ ืœื‘ื—ื•ืจ ืืช ืกืคืงื™ DoH ื”ืžื•ืฆืขื™ื ื‘-Firefox, ื“ืจื™ืฉื•ืช ืœืคื•ืชืจื™ DNS ืžื”ื™ืžื ื™ื, ืœืคื™ื”ื ืžืคืขื™ืœ ื”-DNS ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื ืชื•ื ื™ื ื”ืžืชืงื‘ืœื™ื ืœืคืชืจื•ืŸ ืจืง ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืืช ืคืขื•ืœืช ื”ืฉื™ืจื•ืช, ืืกื•ืจ ืœืื—ืกืŸ ืœื•ื’ื™ื ื‘ืžืฉืš ื™ื•ืชืจ ืž-24 ืฉืขื•ืช, ืื™ื ื• ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ื ืชื•ื ื™ื ืœืฆื“ื“ื™ื ืฉืœื™ืฉื™ื™ื ื•ืžื—ื•ื™ื‘ ืœื—ืฉื•ืฃ ืžื™ื“ืข ืื•ื“ื•ืช ืฉื™ื˜ื•ืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื. ืขืœ ื”ืฉื™ืจื•ืช ื’ื ืœื”ืกื›ื™ื ืฉืœื ืœืฆื ื–ืจ, ืœืกื ืŸ, ืœื”ืคืจื™ืข ืื• ืœื—ืกื•ื ืชืขื‘ื•ืจืช DNS, ืืœื ื‘ืžืฆื‘ื™ื ื”ืงื‘ื•ืขื™ื ื‘ื—ื•ืง.

ื™ืฉ ืœื”ืฉืชืžืฉ ื‘-DoH ื‘ื–ื”ื™ืจื•ืช. ืœื“ื•ื’ืžื”, ื‘ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช, ื›ืชื•ื‘ื•ืช IP 104.16.248.249 ื•-104.16.249.249 ื”ืžืฉื•ื™ื›ื•ืช ืœืฉืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ DoH mozilla.cloudflare-dns.com ื”ืžื•ืฆืข ื‘-Firefox, ื‘ืจืฉื™ืžื” ะฒ ืจืฉื™ืžื•ืช ื—ืกื™ืžื” ืจื•ืกืงื•ืžื ื“ื–ื•ืจ ืœื‘ืงืฉืช ื‘ื™ืช ื”ืžืฉืคื˜ ื‘ืกื˜ื‘ืจื•ืคื•ืœ ืžื™ื•ื 10.06.2013.

DoH ื™ื›ื•ืœ ื’ื ืœื’ืจื•ื ืœื‘ืขื™ื•ืช ื‘ืชื—ื•ืžื™ื ื›ืžื• ืžืขืจื›ื•ืช ื‘ืงืจืช ื”ื•ืจื™ื, ื’ื™ืฉื” ืœืžืจื—ื‘ื™ ืฉืžื•ืช ืคื ื™ืžื™ื™ื ื‘ืžืขืจื›ื•ืช ืืจื’ื•ื ื™ื•ืช, ื‘ื—ื™ืจืช ืžืกืœื•ืœื™ื ื‘ืžืขืจื›ื•ืช ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืฉืœ ืžืกื™ืจืช ืชื•ื›ืŸ ื•ืขืžื™ื“ื” ื‘ืฆื•ื•ื™ ื‘ื™ืช ืžืฉืคื˜ ื‘ืชื—ื•ื ื”ืžืื‘ืง ื‘ื”ืคืฆืช ืชื•ื›ืŸ ื‘ืœืชื™ ื—ื•ืงื™ ื•ื ื™ืฆื•ืœ ืฉืœ ืงื˜ื™ื ื™ื. ื›ื“ื™ ืœืขืงื•ืฃ ื‘ืขื™ื•ืช ื›ืืœื”, ื”ื•ื˜ืžืขื” ื•ื ื‘ื“ืงื” ืžืขืจื›ืช ืฆ'ืงื™ื ื”ืžืฉื‘ื™ืชื” ืื•ื˜ื•ืžื˜ื™ืช ืืช DoH ื‘ืชื ืื™ื ืžืกื•ื™ืžื™ื.

ื›ื“ื™ ืœื–ื”ื•ืช ืคื•ืชืจื™ื ืืจื’ื•ื ื™ื™ื, ื“ื•ืžื™ื™ื ื™ื ืœื ื˜ื™ืคื•ืกื™ื™ื ื‘ืจืžื” ืจืืฉื•ื ื” (TLD) ื ื‘ื“ืงื™ื ื•ืคื•ืชืจ ื”ืžืขืจื›ืช ืžื—ื–ื™ืจ ื›ืชื•ื‘ื•ืช ืื™ื ื˜ืจืื ื˜. ื›ื“ื™ ืœืงื‘ื•ืข ืื ื‘ืงืจืช ื”ื•ืจื™ื ืžื•ืคืขืœืช, ื ืขืฉื” ื ื™ืกื™ื•ืŸ ืœืคืชื•ืจ ืืช ื”ืฉื exampleadultsite.com ื•ืื ื”ืชื•ืฆืื” ืื™ื ื” ืชื•ืืžืช ืืช ื”-IP ื‘ืคื•ืขืœ, ื–ื” ื ื—ืฉื‘ ืฉื—ืกื™ืžืช ืชื•ื›ืŸ ืœืžื‘ื•ื’ืจื™ื ืคืขื™ืœื” ื‘ืจืžืช ื”-DNS. ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœ Google ื•-YouTube ื ื‘ื“ืงื•ืช ื’ื ื›ืกื™ืžื ื™ื ื›ื“ื™ ืœืจืื•ืช ืื ื”ื ื”ื•ื—ืœืคื• ื‘-strict.youtube.com, forcesafesearch.google.com ื•-restrictmoderate.youtube.com. ื‘ื“ื™ืงื•ืช ืืœื• ืžืืคืฉืจื•ืช ืœืชื•ืงืคื™ื ื”ืฉื•ืœื˜ื™ื ื‘ืคืขื•ืœืช ื”ืคื•ืชืจ ืื• ื”ืžืกื•ื’ืœื™ื ืœื”ืคืจื™ืข ืœืชืขื‘ื•ืจื” ืœื“ืžื•ืช ื”ืชื ื”ื’ื•ืช ื›ื–ื• ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ื”ื”ืฆืคื ื” ืฉืœ ืชืขื‘ื•ืจืช DNS.

ืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืฉื™ืจื•ืช DoH ื™ื—ื™ื“ ืขืœื•ืœื” ื’ื ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ื‘ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืฉืœ ืชืขื‘ื•ืจื” ื‘ืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ ืฉืžืื–ื ื•ืช ืชืขื‘ื•ืจื” ื‘ืืžืฆืขื•ืช DNS (ืฉืจืช ื”-DNS ืฉืœ ืจืฉืช CDN ืžื™ื™ืฆืจ ืชื’ื•ื‘ื” ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ื›ืชื•ื‘ืช ื”ืคื•ืชืจ ื•ืžืกืคืง ืืช ื”ืžืืจื— ื”ืงืจื•ื‘ ื‘ื™ื•ืชืจ ืœืงื‘ืœ ืืช ื”ืชื•ื›ืŸ). ืฉืœื™ื—ืช ืฉืื™ืœืชืช DNS ืžื”ืคื•ืจืกื‘ืจ ื”ืงืจื•ื‘ ื‘ื™ื•ืชืจ ืœืžืฉืชืžืฉ ื‘-CDN ืฉื›ืืœื” ืžื‘ื™ืื” ืœื”ื—ื–ืจืช ื”ื›ืชื•ื‘ืช ืฉืœ ื”ืžืืจื— ื”ืงืจื•ื‘ ืœืžืฉืชืžืฉ, ืืš ืฉืœื™ื—ืช ืฉืื™ืœืชืช DNS ืžืคื•ืชืจ ืžืจื›ื–ื™ ืชื—ื–ื™ืจ ืืช ื›ืชื•ื‘ืช ื”ืžืืจื— ื”ืงืจื•ื‘ื” ื‘ื™ื•ืชืจ ืœืฉืจืช DNS-over-HTTPS . ื‘ื“ื™ืงื” ื‘ืคื•ืขืœ ื”ืจืืชื” ืฉื”ืฉื™ืžื•ืฉ ื‘-DNS-over-HTTP ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-CDN ื”ื•ื‘ื™ืœ ืœืžืขืฉื” ืœืœื ืขื™ื›ื•ื‘ื™ื ืœืคื ื™ ืชื—ื™ืœืช ื”ืขื‘ืจืช ื”ืชื•ื›ืŸ (ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ืžื”ื™ืจื™ื, ื”ืขื™ื›ื•ื‘ื™ื ืœื ืขืœื• ืขืœ 10 ืžื™ืœื™ืฉื ื™ื•ืช, ื•ืืฃ ื ืฆืคื• ื‘ื™ืฆื•ืขื™ื ืžื”ื™ืจื™ื ื™ื•ืชืจ ื‘ืขืจื•ืฆื™ ืชืงืฉื•ืจืช ืื™ื˜ื™ื™ื ). ื”ืฉื™ืžื•ืฉ ื‘ืชื•ืกืฃ EDNS Client Subnet ื ื—ืฉื‘ ื’ื ื›ื“ื™ ืœืกืคืง ืžื™ื“ืข ืขืœ ืžื™ืงื•ื ื”ืœืงื•ื— ืœืคื•ืชืจ ื”-CDN.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”