Firefox éçºè
幎éãéããŠå®æœããããã¹ãã§ã¯ããµãŒãã¹ã®ä¿¡é Œæ§ãšè¯å¥œãªããã©ãŒãã³ã¹ã瀺ãããã»ããDoH ãåé¡ãåŒãèµ·ããå¯èœæ§ã®ããããã€ãã®ç¶æ³ãç¹å®ããããããåé¿ãããœãªã¥ãŒã·ã§ã³ãéçºããããšãå¯èœã«ãªããŸãã (äŸ: éã¢ã»ã³ãã«)
DNS ãã©ãã£ãã¯ã®æå·åã®éèŠæ§ã¯ããŠãŒã¶ãŒãä¿è·ããäžã§åºæ¬çã«éèŠãªèŠçŽ ãšããŠè©äŸ¡ãããŠãããããããã©ã«ã㧠DoH ãæå¹ã«ããããšã決å®ãããŸããããæåã®æ®µéã§ã¯ç±³åœã®ãŠãŒã¶ãŒã®ã¿ã察象ã§ããã DoH ãã¢ã¯ãã£ãåãããšããŠãŒã¶ãŒã¯ãå¿ èŠã«å¿ããŠãéäžå DoH DNS ãµãŒããŒãžã®æ¥ç¶ãæåŠããæå·åãããŠããªããªã¯ãšã¹ãããããã€ããŒã® DNS ãµãŒããŒã«éä¿¡ããåŸæ¥ã®ã¹ããŒã (DNS ãªãŸã«ããŒã®åæ£ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä»£ããã«) ã«æ»ãããšãã§ããèŠåãåãåããŸãã DoH ã¯ç¹å®ã® DoH ãµãŒãã¹ãžã®ãã€ã³ãã£ã³ã°ã䜿çšããŸããããã¯åäžé害ç¹ãšã¿ãªãããå¯èœæ§ããããŸã)ã
DoH ãã¢ã¯ãã£ãã«ãªããšãã€ã³ãã©ããã ã¢ãã¬ã¹ãšäŒæ¥ãã¹ãã解決ããããã«å éšãããã¯ãŒã¯å°çšã® DNS åæ§é ã䜿çšãããã¢ã¬ã³ã¿ã« ã³ã³ãããŒã« ã·ã¹ãã ãšäŒæ¥ãããã¯ãŒã¯ãäžæãããå¯èœæ§ããããŸãã ãã®ãããªã·ã¹ãã ã®åé¡ã解決ããããã«ãDoH ãèªåçã«ç¡å¹ã«ãããã§ã㯠ã·ã¹ãã ãè¿œå ãããŸããã ãã§ãã¯ã¯ããã©ãŠã¶ãèµ·åããããã³ããŸãã¯ãµããããã®å€æŽãæ€åºããããã³ã«å®è¡ãããŸãã
DoH çµç±ã®è§£æ±ºäžã«é害ãçºçããå Žå (ããšãã°ãDoH ãããã€ããŒãšã®ãããã¯ãŒã¯å¯çšæ§ãäžæãããå ŽåããŸãã¯ãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§é害ãçºçããå Žå)ãæšæºã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãªãŸã«ããŒã®äœ¿çšã«èªåçã«æ»ãããšãã§ããŸãã ãªãŸã«ããŒã®åäœãå¶åŸ¡ããæ»æè ããã©ãã£ãã¯ã«å¹²æžã§ããæ»æè ãåæ§ã®åäœãã·ãã¥ã¬ãŒãã㊠DNS ãã©ãã£ãã¯ã®æå·åãç¡å¹ã«ããããšã誰ãé»æ¢ã§ããªãããããã®ãããªãã§ãã¯ã®æå³ã«ã¯çåããããŸãã ãã®åé¡ã¯ããåžžã« DoHãé ç®ãèšå®ã«è¿œå ããããšã§è§£æ±ºãããŸãã (ãµã€ã¬ã³ãã«éã¢ã¯ãã£ãã«ãªããŸã)ãèšå®ãããšãèªåã·ã£ããããŠã³ã¯é©çšãããŸãããããã¯åççãªåŠ¥åçã§ãã
ãšã³ã¿ãŒãã©ã€ãº ãªãŸã«ããŒãèå¥ããããã«ãéå
žåçãªãã¡ãŒã¹ãã¬ãã« ãã¡ã€ã³ (TLD) ããã§ãã¯ãããã·ã¹ãã ãªãŸã«ããŒã¯ã€ã³ãã©ããã ã¢ãã¬ã¹ãè¿ããŸãã ä¿è·è
ã«ããå¶éãæå¹ãã©ãããå€æããããã«ãexample Adultsite.com ãšããååã®è§£æ±ºãè©Šè¡ããããã®çµæãå®éã® IP ãšäžèŽããªãå Žåã¯ãDNS ã¬ãã«ã§ã¢ãã«ã ã³ã³ãã³ãã®ãããã¯ãã¢ã¯ãã£ãã§ãããšèŠãªãããŸãã Google ãš YouTube ã® IP ã¢ãã¬ã¹ãå
åãšããŠãã§ãã¯ãããrestrict.youtube.comãforcesafesearch.google.comãrestrictmoderate.youtube.com ã«çœ®ãæããããŠããªããã©ããã確èªãããŸãã è¿œå ã® Mozilla
ãŸããåäžã® DoH ãµãŒãã¹ãä»ããŠåäœãããšãDNS ã䜿çšããŠãã©ãã£ãã¯ã®ãã©ã³ã¹ãåãã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ã®ãã©ãã£ãã¯æé©åã§åé¡ãçºçããå¯èœæ§ããããŸã (CDN ãããã¯ãŒã¯ã® DNS ãµãŒããŒã¯ããªãŸã«ã㌠ã¢ãã¬ã¹ãèæ ®ããŠå¿çãçæããã³ã³ãã³ããåä¿¡ããããã«æãè¿ããã¹ããæäŸããŸã)ã ãã®ãã㪠CDN ã§ãŠãŒã¶ãŒã«æãè¿ããªãŸã«ããŒãã DNS ã¯ãšãªãéä¿¡ãããšããŠãŒã¶ãŒã«æãè¿ããã¹ãã®ã¢ãã¬ã¹ãè¿ãããŸãããéäžãªãŸã«ããŒãã DNS ã¯ãšãªãéä¿¡ãããšãDNS-over-HTTPS ãµãŒããŒã«æãè¿ããã¹ã ã¢ãã¬ã¹ãè¿ãããŸãã ã å®éã®ãã¹ãã§ã¯ãCDN 䜿çšæã« DNS-over-HTTP ã䜿çšãããšãã³ã³ãã³ã転éã®éå§åã«å®è³ªçã«é 延ãçºçããªãããšãããããŸãã (é«éæ¥ç¶ã®å Žåãé 延㯠10 ããªç§ãè¶ ãããäœééä¿¡ãã£ãã«ã§ã¯ããã«é«éãªããã©ãŒãã³ã¹ã芳å¯ãããŸãã) ïŒã ã¯ã©ã€ã¢ã³ãã®äœçœ®æ å ±ã CDN ãªãŸã«ããŒã«æäŸããããã«ãEDNS ã¯ã©ã€ã¢ã³ã ãµããããæ¡åŒµæ©èœã®äœ¿çšãæ€èšãããŸããã
DoH ã¯ããããã€ããŒã® DNS ãµãŒããŒãä»ããèŠæ±ããããã¹ãåã«é¢ããæ å ±ã®æŒæŽ©ã®é²æ¢ãMITM æ»æã DNS ãã©ãã£ãã¯ã®ã¹ããŒãã£ã³ã°ãžã®å¯ŸåŠãDNS ã¬ãã«ã§ã®ãããã¯ãžã®å¯Ÿæããããã¯ãDNS ã¬ãã«ã§ã®ããããã³ã°ãžã®å¯ŸåŠããŸãã¯ãDNS ãã©ãã£ãã¯ãçºçããå Žåã®äœæ¥ã®æŽçã«åœ¹ç«ã€ããšãæãåºããŠãã ããã DNS ãµãŒããŒã«çŽæ¥ã¢ã¯ã»ã¹ããããšã¯ã§ããŸãã (ããšãã°ããããã·ãä»ããŠäœæ¥ããŠããå Žå)ã éåžžã®ç¶æ³ã§ã¯ãDNS ãªã¯ãšã¹ããã·ã¹ãã æ§æã§å®çŸ©ããã DNS ãµãŒããŒã«çŽæ¥éä¿¡ãããå ŽåãDoH ã®å Žåããã¹ãã® IP ã¢ãã¬ã¹ã決å®ãããªã¯ãšã¹ã㯠HTTPS ãã©ãã£ãã¯ã«ã«ãã»ã«åãã㊠HTTP ãµãŒããŒã«éä¿¡ãããããã§ãªãŸã«ããŒãåŠçããŸãã Web APIçµç±ã§ã®ãªã¯ãšã¹ãã æ¢åã® DNSSEC æšæºã§ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã®èªèšŒã«ã®ã¿æå·åã䜿çšãããŸããããã©ãã£ãã¯ãååããä¿è·ãããããªã¯ãšã¹ãã®æ©å¯æ§ãä¿èšŒãããããããšã¯ãããŸããã
about:config 㧠DoH ãæå¹ã«ããã«ã¯ãnetwork.trr.mode å€æ°ã®å€ãå€æŽããå¿ èŠããããŸãããã®å€æ°ã¯ Firefox 60 以éã§ãµããŒããããŠããŸããå€ 0 㯠DoH ãå®å šã«ç¡å¹ã«ããŸãã 1 - DNS ãŸã㯠DoH ã®ã©ã¡ããéãæ¹ã䜿çšãããŸãã 2 - DoH ãããã©ã«ãã§äœ¿çšãããDNS ããã©ãŒã«ãã㯠ãªãã·ã§ã³ãšããŠäœ¿çšãããŸãã 3 - DoH ã®ã¿ã䜿çšãããŸãã 4 - DoH ãš DNS ã䞊è¡ããŠäœ¿çšããããã©ãŒãªã³ã° ã¢ãŒãã ããã©ã«ãã§ã¯ãCloudFlare DNS ãµãŒããŒã䜿çšãããŸãããnetwork.trr.uri ãã©ã¡ãŒã¿ãŒã䜿çšããŠå€æŽã§ããŸããããšãã°ããhttps://dns.google.com/experimentalããŸãã¯ãhttps://9.9.9.9ããèšå®ã§ããŸãã .XNUMX/dns-query "
åºæïŒ ãªãŒãã³ããã.ru