Chrome 78 ื™ืชื—ื™ืœ ืœื”ืชื ืกื•ืช ื‘ื”ืคืขืœืช DNS-over-HTTPS

ื”ื‘ื ืžื•ื–ื™ืœื” ื—ื‘ืจืช ื’ื•ื’ืœ ื“ื•ื•ื— ืขืœ ื”ื›ื•ื•ื ื” ืœืขืจื•ืš ื ื™ืกื•ื™ ืœื‘ื“ื™ืงืช ื™ื™ืฉื•ื "DNS over HTTPS" (DoH, DNS over HTTPS) ื”ืžืคื•ืชื— ืขื‘ื•ืจ ื“ืคื“ืคืŸ Chrome. Chrome 78, ื”ืžืชื•ื›ื ืŸ ืœ-22 ื‘ืื•ืงื˜ื•ื‘ืจ, ื™ื›ืœื•ืœ ื›ืžื” ืงื˜ื’ื•ืจื™ื•ืช ืžืฉืชืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืžึฐืชื•ึผืจื’ึธื ืœื”ืฉืชืžืฉ ื‘-DoH. ืจืง ืžืฉืชืžืฉื™ื ืฉื”ื’ื“ืจื•ืช ื”ืžืขืจื›ืช ื”ื ื•ื›ื—ื™ื•ืช ืฉืœื”ื ืžืฆื™ื™ื ื•ืช ืกืคืงื™ DNS ืžืกื•ื™ืžื™ื ื”ืžื•ื›ืจื™ื ื›ืชื•ืืžื™ื ืœ-DoH, ื™ืฉืชืชืคื• ื‘ื ื™ืกื•ื™ ื›ื“ื™ ืœืืคืฉืจ ืืช DoH.

ื”ืจืฉื™ืžื” ื”ืœื‘ื ื” ืฉืœ ืกืคืงื™ DNS ื›ื•ืœืœืช ืฉื™ืจื•ืชื™ื ื’ื•ื’ืœ (8.8.8.8, 8.8.4.4), Cloudflare (1.1.1.1, 1.0.0.1), OpenDns (208.67.222.222, 208.67.220.220), Quad9 (9.9.9.9, 149.112.112.112), Cleanbrowsing (185.228.168.168. 185.228.169.168, 185.222.222.222) ื•-DNS.SB (185.184.222.222, XNUMX). ืื ื”ื’ื“ืจื•ืช ื”-DNS ืฉืœ ื”ืžืฉืชืžืฉ ืžืฆื™ื™ื ื•ืช ืืช ืื—ื“ ืžืฉืจืชื™ ื”-DNS ืฉื”ื•ื–ื›ืจื• ืœืขื™ืœ, DoH ื‘-Chrome ื™ื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืœืžื™ ืฉืžืฉืชืžืฉ ื‘ืฉืจืชื™ DNS ื”ืžืกื•ืคืงื™ื ืขืœ ื™ื“ื™ ืกืคืง ื”ืื™ื ื˜ืจื ื˜ ื”ืžืงื•ืžื™ ืฉืœื”ื, ื”ื›ืœ ื™ื™ืฉืืจ ืœืœื ืฉื™ื ื•ื™ ื•ืคื•ืชืจ ื”ืžืขืจื›ืช ื™ืžืฉื™ืš ืœืฉืžืฉ ืขื‘ื•ืจ ืฉืื™ืœืชื•ืช DNS.

ื”ื‘ื“ืœ ื—ืฉื•ื‘ ืžื”ื˜ืžืขืช DoH ื‘ืคื™ื™ืจืคื•ืงืก, ืฉืื™ืคืฉืจื” ื‘ื”ื“ืจื’ื” ืืช DoH ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื™ืชื—ื™ืœ ื›ื‘ืจ ื‘ืกื•ืฃ ืกืคื˜ืžื‘ืจ, ื”ื™ื ื”ื™ืขื“ืจ ื”ื›ืจื™ื›ื” ืœืฉื™ืจื•ืช ื“ื•ื”"ื— ืื—ื“. ืื ื‘ืคื™ื™ืจืคื•ืงืก ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืžืฉืžืฉ CloudFlare ืฉืจืช DNS, ืื– Chrome ื™ืขื“ื›ืŸ ืจืง ืืช ืฉื™ื˜ืช ื”ืขื‘ื•ื“ื” ืขื DNS ืœืฉื™ืจื•ืช ืฉื•ื•ื” ืขืจืš, ืžื‘ืœื™ ืœืฉื ื•ืช ืืช ืกืคืง ื”-DNS. ืœื“ื•ื’ืžื”, ืื ืœืžืฉืชืžืฉ ื™ืฉ DNS 8.8.8.8 ืฉืฆื•ื™ืŸ ื‘ื”ื’ื“ืจื•ืช ื”ืžืขืจื›ืช, Chrome ื™ืขืฉื” ื–ืืช ืžื•ึผืคืขึธืœ ืฉื™ืจื•ืช Google DoH ("https://dns.google.com/dns-query"), ืื ื”-DNS ื”ื•ื 1.1.1.1, ืื– ืฉื™ืจื•ืช Cloudflare DoH ("https://cloudflare-dns.com/dns-query") ื•ื›ืŸ ื•ื›ื• '

ืื ืชืจืฆื”, ื”ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืื• ืœื”ืฉื‘ื™ืช ืืช DoH ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "chrome://flags/#dns-over-https". ืฉืœื•ืฉื” ืžืฆื‘ื™ ื”ืคืขืœื” ื ืชืžื›ื™ื: ืžืื•ื‘ื˜ื—, ืื•ื˜ื•ืžื˜ื™ ื•ื›ื‘ื•ื™. ื‘ืžืฆื‘ "ืžืื‘ื˜ื—", ื”ืžืืจื—ื™ื ื ืงื‘ืขื™ื ืจืง ืขืœ ืกืžืš ืขืจื›ื™ ืžืื•ื‘ื˜ื—ื™ื ืฉื ืฉืžืจื• ื‘ืขื‘ืจ ื‘ืžื˜ืžื•ืŸ (ื”ืžืชืงื‘ืœื™ื ื‘ืืžืฆืขื•ืช ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื—) ื•ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช DoH; ื—ื–ืจื” ืœ-DNS ืจื’ื™ืœ ืื™ื ื” ืžื•ื—ืœืช. ื‘ืžืฆื‘ "ืื•ื˜ื•ืžื˜ื™", ืื DoH ื•ื”ืžื˜ืžื•ืŸ ื”ืžืื•ื‘ื˜ื— ืื™ื ื ื–ืžื™ื ื™ื, ื ื™ืชืŸ ืœืื—ื–ืจ ื ืชื•ื ื™ื ืžื”ืžื˜ืžื•ืŸ ื”ืœื ืžืื•ื‘ื˜ื— ื•ืœื’ืฉืช ืืœื™ื”ื ื“ืจืš DNS ืžืกื•ืจืชื™. ื‘ืžืฆื‘ "ื›ื‘ื•ื™", ื”ืžื˜ืžื•ืŸ ื”ืžืฉื•ืชืฃ ื ื‘ื“ืง ืชื—ื™ืœื” ื•ืื ืื™ืŸ ื ืชื•ื ื™ื, ื”ื‘ืงืฉื” ื ืฉืœื—ืช ื“ืจืš ื”-DNS ืฉืœ ื”ืžืขืจื›ืช. ื”ืžืฆื‘ ื ืงื‘ืข ื‘ืืžืฆืขื•ืช ื”ืชืืžื” ืื™ืฉื™ืช kDnsOverHttpsMode , ื•ืชื‘ื ื™ืช ืžื™ืคื•ื™ ื”ืฉืจืช ื‘ืืžืฆืขื•ืช kDnsOverHttpsTemplates.

ื”ื ื™ืกื•ื™ ืœื”ืคืขืœืช DoH ื™ืชื‘ืฆืข ื‘ื›ืœ ื”ืคืœื˜ืคื•ืจืžื•ืช ื”ื ืชืžื›ื•ืช ื‘ื›ืจื•ื, ืœืžืขื˜ ืœื™ื ื•ืงืก ื•-iOS ื‘ืฉืœ ื”ืื•ืคื™ ื”ืœื ื˜ืจื™ื•ื•ื™ืืœื™ ืฉืœ ื ื™ืชื•ื— ื”ื’ื“ืจื•ืช ืคื•ืชืจ ื•ื”ื’ื‘ืœืช ื”ื’ื™ืฉื” ืœื”ื’ื“ืจื•ืช ื”-DNS ืฉืœ ื”ืžืขืจื›ืช. ืื ืœืื—ืจ ื”ืคืขืœืช DoH, ื™ืฉ ื‘ืขื™ื•ืช ื‘ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืœืฉืจืช DoH (ืœื“ื•ื’ืžื”, ืขืงื‘ ื—ืกื™ืžืชื•, ืงื™ืฉื•ืจื™ื•ืช ืจืฉืช ืื• ื›ืฉืœ), ื”ื“ืคื“ืคืŸ ื™ื—ื–ื™ืจ ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ื’ื“ืจื•ืช ื”-DNS ืฉืœ ื”ืžืขืจื›ืช.

ืžื˜ืจืช ื”ื ื™ืกื•ื™ ื”ื™ื ืœื‘ื“ื•ืง ืกื•ืคื™ืช ืืช ื”ื™ื™ืฉื•ื ืฉืœ DoH ื•ืœืœืžื•ื“ ืืช ื”ื”ืฉืคืขื” ืฉืœ ื”ืฉื™ืžื•ืฉ ื‘-DoH ืขืœ ื”ื‘ื™ืฆื•ืขื™ื. ื™ืฆื•ื™ืŸ ื›ื™ ืœืžืขืฉื” ืชืžื™ื›ืช DoH ื”ื™ื™ืชื” ื”ื•ืกื™ืฃ ืœืชื•ืš ื‘ืกื™ืก ื”ืงื•ื“ ืฉืœ Chrome ื‘ืคื‘ืจื•ืืจ, ืืœื ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื•ืœื”ืคืขื™ืœ ืืช DoH ื ื“ืจืฉ ืžืฉื™ืง ืืช Chrome ืขื ื“ื’ืœ ืžื™ื•ื—ื“ ื•ืžืขืจื›ืช ืœื ื‘ืจื•ืจื” ืฉืœ ืืคืฉืจื•ื™ื•ืช.

ื ื–ื›ื™ืจ ื›ื™ DoH ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœืžื ื™ืขืช ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื”ืžื‘ื•ืงืฉื™ื ื“ืจืš ืฉืจืชื™ ื”-DNS ืฉืœ ืกืคืงื™ื, ืžืื‘ืง ื‘ื”ืชืงืคื•ืช MITM ื•ื–ื™ื•ืฃ ืชืขื‘ื•ืจืช DNS (ืœื“ื•ื’ืžื”, ื‘ืขืช ื—ื™ื‘ื•ืจ ืœ-Wi-Fi ืฆื™ื‘ื•ืจื™), ืžื ื™ืขืช ื—ืกื™ืžื” ื‘-DNS ืจืžืช (DoH ืœื ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ VPN ื‘ืชื—ื•ื ืฉืœ ืขืงื™ืคืช ื—ืกื™ืžื” ื”ืžื™ื•ืฉืžืช ื‘ืจืžืช DPI) ืื• ืœืืจื’ื•ืŸ ืขื‘ื•ื“ื” ืื ืื™ ืืคืฉืจ ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS (ืœื“ื•ื’ืžื”, ื‘ืขื‘ื•ื“ื” ื“ืจืš ืคืจื•ืงืกื™). ืื ื‘ืžืฆื‘ ืจื’ื™ืœ ื‘ืงืฉื•ืช DNS ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS ื”ืžื•ื’ื“ืจื™ื ื‘ืชืฆื•ืจืช ื”ืžืขืจื›ืช, ืื– ื‘ืžืงืจื” ืฉืœ DoH, ื”ื‘ืงืฉื” ืœืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืืจื— ืžื•ื‘ืœืขืช ื‘ืชืขื‘ื•ืจืช HTTPS ื•ื ืฉืœื—ืช ืœืฉืจืช ื”-HTTP, ืฉื ื”ืคื•ืชืจ ืžืขื‘ื“ ื‘ืงืฉื•ืช ื“ืจืš ื”-API ืฉืœ ื”ืื™ื ื˜ืจื ื˜. ืชืงืŸ DNSSEC ื”ืงื™ื™ื ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” ืจืง ื›ื“ื™ ืœืืžืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ืื™ื ื• ืžื’ืŸ ืขืœ ื”ืชืขื‘ื•ืจื” ืžืคื ื™ ื™ื™ืจื•ื˜ ื•ืื™ื ื• ืžื‘ื˜ื™ื— ืืช ืกื•ื“ื™ื•ืช ื”ื‘ืงืฉื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”