ืžื•ื–ื™ืœื” ืขื•ื‘ืจืช ืœืืคืฉืจ DNS-over-HTTPS ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘-Firefox

ืžืคืชื—ื™ ืคื™ื™ืจืคื•ืงืก ื”ื•ื›ืจื– ืขืœ ื”ืฉืœืžืช ื‘ื“ื™ืงืช ื”ืชืžื™ื›ื” ื‘-DNS ืขืœ HTTPS (DoH, DNS over HTTPS) ื•ืขืœ ื”ื›ื•ื•ื ื” ืœืืคืฉืจ ื˜ื›ื ื•ืœื•ื’ื™ื” ื–ื• ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœืžืฉืชืžืฉื™ื ื‘ืืจื”"ื‘ ื‘ืกื•ืฃ ืกืคื˜ืžื‘ืจ. ื”ื”ืคืขืœื” ืชืชื‘ืฆืข ื‘ื”ื“ืจื’ื”, ืชื—ื™ืœื” ืขื‘ื•ืจ ื›ืžื” ืื—ื•ื–ื™ื ืžื”ืžืฉืชืžืฉื™ื, ื•ืื ืื™ืŸ ื‘ืขื™ื•ืช, ืขืœื™ื™ื” ื”ื“ืจื’ืชื™ืช ืœ-100%. ืœืื—ืจ ื›ื™ืกื•ื™ ืืจื”"ื‘, DoH ื™ื™ื—ืฉื‘ ืœื”ื›ืœืœื” ื‘ืžื“ื™ื ื•ืช ืื—ืจื•ืช.

ื‘ื“ื™ืงื•ืช ืฉื‘ื•ืฆืขื• ื‘ืžื”ืœืš ื”ืฉื ื” ื”ืจืื• ืืช ืืžื™ื ื•ืช ื”ืฉื™ืจื•ืช ื•ื”ื‘ื™ืฆื•ืขื™ื ื”ื˜ื•ื‘ื™ื, ื•ื›ืŸ ืืคืฉืจื• ืœื–ื”ื•ืช ื›ืžื” ืžืฆื‘ื™ื ืฉื‘ื”ื DoH ื™ื›ื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ื•ืœืคืชื— ืคืชืจื•ื ื•ืช ืœืขืงื•ืฃ ืื•ืชืŸ (ืœืžืฉืœ, ืคื™ืจื•ืง ื‘ืขื™ื•ืช ืขื ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืฉืœ ืชื ื•ืขื” ื‘ืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ, ื‘ืงืจืช ื”ื•ืจื™ื ื•ืื–ื•ืจื™ DNS ืคื ื™ืžื™ื™ื ืืจื’ื•ื ื™ื™ื).

ื”ื—ืฉื™ื‘ื•ืช ืฉืœ ื”ืฆืคื ืช ืชืขื‘ื•ืจืช DNS ืžื•ืขืจื›ืช ื›ื’ื•ืจื ื—ืฉื•ื‘ ื‘ื™ืกื•ื“ื• ื‘ื”ื’ื ื” ืขืœ ื”ืžืฉืชืžืฉื™ื, ื•ืœื›ืŸ ื”ื•ื—ืœื˜ ืœืืคืฉืจ ืืช DoH ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืืš ื‘ืฉืœื‘ ื”ืจืืฉื•ืŸ ืจืง ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืžืืจืฆื•ืช ื”ื‘ืจื™ืช. ืœืื—ืจ ื”ืคืขืœืช DoH, ื”ืžืฉืชืžืฉ ื™ืงื‘ืœ ืื–ื”ืจื” ืฉืชืืคืฉืจ, ืื ืชืจืฆื”, ืœืกืจื‘ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืชื™ DNS ืžืจื›ื–ื™ื™ื ืฉืœ DoH ื•ืœื—ื–ื•ืจ ืœืกื›ื™ืžื” ื”ืžืกื•ืจืชื™ืช ืฉืœ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืœื ืžื•ืฆืคื ื•ืช ืœืฉืจืช ื”-DNS ืฉืœ ื”ืกืคืง (ื‘ืžืงื•ื ืชืฉืชื™ืช ืžื‘ื•ื–ืจืช ืฉืœ ืคื•ืชืจื™ DNS, DoH ืžืฉืชืžืฉ ื‘ืงื™ืฉื•ืจ ืœืฉื™ืจื•ืช DoH ืกืคืฆื™ืคื™, ืฉื™ื›ื•ืœ ืœื”ื™ื—ืฉื‘ ื›ื ืงื•ื“ืช ื›ืฉืœ ื‘ื•ื“ื“ืช).

ืื DoH ืžื•ืคืขืœ, ืžืขืจื›ื•ืช ื‘ืงืจืช ื”ื•ืจื™ื ื•ืจืฉืชื•ืช ืืจื’ื•ื ื™ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ืžื‘ื ื” ืฉืžื•ืช ื”-DNS ื”ืคื ื™ืžื™ ืฉืœ ื”ืจืฉืช ื‘ืœื‘ื“ ื›ื“ื™ ืœืคืชื•ืจ ื›ืชื•ื‘ื•ืช ืื™ื ื˜ืจื-ื ื˜ ื•ืžืืจื—ื™ื ืืจื’ื•ื ื™ื™ื ืขืœื•ืœื•ืช ืœื”ื™ืคื’ืข. ื›ื“ื™ ืœืคืชื•ืจ ื‘ืขื™ื•ืช ื‘ืžืขืจื›ื•ืช ื›ืืœื”, ื ื•ืกืคื” ืžืขืจื›ืช ื‘ื“ื™ืงื•ืช ืฉืžื ื˜ืจืœืช ืื•ื˜ื•ืžื˜ื™ืช ืืช DoH. ื‘ื“ื™ืงื•ืช ืžื‘ื•ืฆืขื•ืช ื‘ื›ืœ ืคืขื ืฉื”ื“ืคื“ืคืŸ ืžื•ืคืขืœ ืื• ื›ืืฉืจ ืžื–ื•ื”ื” ืฉื™ื ื•ื™ ื‘ืจืฉืช ื”ืžืฉื ื”.

ื—ื–ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืœืฉื™ืžื•ืฉ ื‘ืคื•ืชืจ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืกื˜ื ื“ืจื˜ื™ ืžืกื•ืคืงืช ื’ื ืื ืžืชืจื—ืฉื•ืช ื›ืฉืœื™ื ื‘ืžื”ืœืš ื”ืคืชืจื•ืŸ ื‘ืืžืฆืขื•ืช DoH (ืœื“ื•ื’ืžื”, ืื ื–ืžื™ื ื•ืช ื”ืจืฉืช ืืฆืœ ืกืคืง DoH ืžื•ืคืจืขืช ืื• ืžืชืจื—ืฉื•ืช ื›ืฉืœื™ื ื‘ืชืฉืชื™ืช ืฉืœื”). ื”ืžืฉืžืขื•ืช ืฉืœ ื‘ื“ื™ืงื•ืช ื›ืืœื” ืžื•ื˜ืœืช ื‘ืกืคืง, ืฉื›ืŸ ืื™ืฉ ืื™ื ื• ืžื•ื ืข ืžืชื•ืงืคื™ื ื”ืฉื•ืœื˜ื™ื ื‘ืคืขื•ืœืช ื”ืคื•ืชืจ ืื• ื”ืžืกื•ื’ืœื™ื ืœื”ืคืจื™ืข ืœืชืขื‘ื•ืจื” ืœื“ืžื•ืช ื”ืชื ื”ื’ื•ืช ื“ื•ืžื” ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ื”ื”ืฆืคื ื” ืฉืœ ืชืขื‘ื•ืจืช DNS. ื”ื‘ืขื™ื” ื ืคืชืจื” ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืคืจื™ื˜ "DoH always" ืœื”ื’ื“ืจื•ืช (ืœื ืคืขื™ืœ ื‘ืฉืงื˜), ื›ืืฉืจ ืžื•ื’ื“ืจ, ื›ื™ื‘ื•ื™ ืื•ื˜ื•ืžื˜ื™ ืื™ื ื• ืžื•ื—ืœ, ื•ื–ื• ืคืฉืจื” ืกื‘ื™ืจื”.

ื›ื“ื™ ืœื–ื”ื•ืช ืคื•ืชืจื™ื ืืจื’ื•ื ื™ื™ื, ื“ื•ืžื™ื™ื ื™ื ืœื ื˜ื™ืคื•ืกื™ื™ื ื‘ืจืžื” ืจืืฉื•ื ื” (TLD) ื ื‘ื“ืงื™ื ื•ืคื•ืชืจ ื”ืžืขืจื›ืช ืžื—ื–ื™ืจ ื›ืชื•ื‘ื•ืช ืื™ื ื˜ืจืื ื˜. ื›ื“ื™ ืœืงื‘ื•ืข ืื ื‘ืงืจืช ื”ื•ืจื™ื ืžื•ืคืขืœืช, ื ืขืฉื” ื ื™ืกื™ื•ืŸ ืœืคืชื•ืจ ืืช ื”ืฉื exampleadultsite.com ื•ืื ื”ืชื•ืฆืื” ืื™ื ื” ืชื•ืืžืช ืืช ื”-IP ื‘ืคื•ืขืœ, ื–ื” ื ื—ืฉื‘ ืฉื—ืกื™ืžืช ืชื•ื›ืŸ ืœืžื‘ื•ื’ืจื™ื ืคืขื™ืœื” ื‘ืจืžืช ื”-DNS. ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœ Google ื•-YouTube ื ื‘ื“ืงื•ืช ื’ื ื›ืกื™ืžื ื™ื ื›ื“ื™ ืœืจืื•ืช ืื ื”ื ื”ื•ื—ืœืคื• ื‘-strict.youtube.com, forcesafesearch.google.com ื•-restrictmoderate.youtube.com. ืžื•ื–ื™ืœื” ื ื•ืกืคืช ืžืฆื™ืข ืœื™ื™ืฉื ืžืืจื— ื‘ื“ื™ืงื” ื™ื—ื™ื“ use-application-dns.net, ืฉืกืคืงื™ ืฉื™ืจื•ืชื™ ืื™ื ื˜ืจื ื˜ ื•ืฉื™ืจื•ืชื™ ื‘ืงืจืช ื”ื•ืจื™ื ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื’ืœ ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช DoH (ืื ื”ืžืืจื— ืœื ืžื–ื•ื”ื”, Firefox ืžืฉื‘ื™ืช ืืช DoH).

ืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืฉื™ืจื•ืช DoH ื™ื—ื™ื“ ืขืœื•ืœื” ื’ื ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ื‘ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืฉืœ ืชืขื‘ื•ืจื” ื‘ืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ ืฉืžืื–ื ื•ืช ืชืขื‘ื•ืจื” ื‘ืืžืฆืขื•ืช DNS (ืฉืจืช ื”-DNS ืฉืœ ืจืฉืช CDN ืžื™ื™ืฆืจ ืชื’ื•ื‘ื” ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ื›ืชื•ื‘ืช ื”ืคื•ืชืจ ื•ืžืกืคืง ืืช ื”ืžืืจื— ื”ืงืจื•ื‘ ื‘ื™ื•ืชืจ ืœืงื‘ืœ ืืช ื”ืชื•ื›ืŸ). ืฉืœื™ื—ืช ืฉืื™ืœืชืช DNS ืžื”ืคื•ืจืกื‘ืจ ื”ืงืจื•ื‘ ื‘ื™ื•ืชืจ ืœืžืฉืชืžืฉ ื‘-CDN ืฉื›ืืœื” ืžื‘ื™ืื” ืœื”ื—ื–ืจืช ื”ื›ืชื•ื‘ืช ืฉืœ ื”ืžืืจื— ื”ืงืจื•ื‘ ืœืžืฉืชืžืฉ, ืืš ืฉืœื™ื—ืช ืฉืื™ืœืชืช DNS ืžืคื•ืชืจ ืžืจื›ื–ื™ ืชื—ื–ื™ืจ ืืช ื›ืชื•ื‘ืช ื”ืžืืจื— ื”ืงืจื•ื‘ื” ื‘ื™ื•ืชืจ ืœืฉืจืช DNS-over-HTTPS . ื‘ื“ื™ืงื” ื‘ืคื•ืขืœ ื”ืจืืชื” ืฉื”ืฉื™ืžื•ืฉ ื‘-DNS-over-HTTP ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-CDN ื”ื•ื‘ื™ืœ ืœืžืขืฉื” ืœืœื ืขื™ื›ื•ื‘ื™ื ืœืคื ื™ ืชื—ื™ืœืช ื”ืขื‘ืจืช ื”ืชื•ื›ืŸ (ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ืžื”ื™ืจื™ื, ื”ืขื™ื›ื•ื‘ื™ื ืœื ืขืœื• ืขืœ 10 ืžื™ืœื™ืฉื ื™ื•ืช, ื•ืืฃ ื ืฆืคื• ื‘ื™ืฆื•ืขื™ื ืžื”ื™ืจื™ื ื™ื•ืชืจ ื‘ืขืจื•ืฆื™ ืชืงืฉื•ืจืช ืื™ื˜ื™ื™ื ). ื”ืฉื™ืžื•ืฉ ื‘ืชื•ืกืฃ EDNS Client Subnet ื ื—ืฉื‘ ื’ื ื›ื“ื™ ืœืกืคืง ืžื™ื“ืข ืขืœ ืžื™ืงื•ื ื”ืœืงื•ื— ืœืคื•ืชืจ ื”-CDN.

ื ื–ื›ื™ืจ ื›ื™ DoH ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœืžื ื™ืขืช ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื”ืžื‘ื•ืงืฉื™ื ื“ืจืš ืฉืจืชื™ ื”-DNS ืฉืœ ืกืคืงื™ื, ืžืื‘ืง ื‘ื”ืชืงืคื•ืช MITM ื•ื–ื™ื•ืฃ ืฉืœ ืชืขื‘ื•ืจืช DNS, ืžื ื™ืขืช ื—ืกื™ืžื” ื‘ืจืžืช ื”-DNS, ืื• ืœืืจื’ื•ืŸ ืขื‘ื•ื“ื” ื‘ืžืงืจื” ืฉื–ื” ื‘ืœืชื™ ืืคืฉืจื™ ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืขื•ื‘ื“ื™ื ื“ืจืš ืคืจื•ืงืกื™). ืื ื‘ืžืฆื‘ ืจื’ื™ืœ ื‘ืงืฉื•ืช DNS ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS ื”ืžื•ื’ื“ืจื™ื ื‘ืชืฆื•ืจืช ื”ืžืขืจื›ืช, ืื– ื‘ืžืงืจื” ืฉืœ DoH, ื”ื‘ืงืฉื” ืœืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืืจื— ืžื•ื‘ืœืขืช ื‘ืชืขื‘ื•ืจืช HTTPS ื•ื ืฉืœื—ืช ืœืฉืจืช ื”-HTTP, ืฉื ื”ืคื•ืชืจ ืžืขื‘ื“ ื‘ืงืฉื•ืช ื“ืจืš ื”-API ืฉืœ ื”ืื™ื ื˜ืจื ื˜. ืชืงืŸ DNSSEC ื”ืงื™ื™ื ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” ืจืง ื›ื“ื™ ืœืืžืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ืื™ื ื• ืžื’ืŸ ืขืœ ื”ืชืขื‘ื•ืจื” ืžืคื ื™ ื™ื™ืจื•ื˜ ื•ืื™ื ื• ืžื‘ื˜ื™ื— ืืช ืกื•ื“ื™ื•ืช ื”ื‘ืงืฉื•ืช.

ื›ื“ื™ ืœื”ืคืขื™ืœ DoH ื‘- about:config, ืขืœื™ืš ืœืฉื ื•ืช ืืช ื”ืขืจืš ืฉืœ ื”ืžืฉืชื ื” network.trr.mode, ืฉื ืชืžืš ืžืื– Firefox 60. ืขืจืš 0 ืžืฉื‘ื™ืช ืืช DoH ืœื—ืœื•ื˜ื™ืŸ; 1 - ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-DNS ืื• DoH, ื”ืžื”ื™ืจ ืžื‘ื™ื ื™ื”ื; 2 - DoH ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื•-DNS ืžืฉืžืฉ ื›ืืคืฉืจื•ืช ื—ื–ืจื”; 3 - ืจืง DoH ืžืฉืžืฉ; 4 - ืžืฆื‘ ืฉื™ืงื•ืฃ ื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-DoH ื•-DNS ื‘ืžืงื‘ื™ืœ. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืฉืจืช ื”-DNS ืฉืœ CloudFlare, ืืš ื ื™ืชืŸ ืœืฉื ื•ืช ืื•ืชื• ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจ network.trr.uri, ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ "https://dns.google.com/experimental" ืื• "https://9.9.9.9 .XNUMX/dns-query "

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”