Kutevera
Iyo chena rondedzero yeDNS vanopa inosanganisira
Musiyano wakakosha kubva mukushandiswa kweDoH muFirefox, iyo yakagonesa DoH zvishoma nezvishoma
Kana zvichidikanwa, mushandisi anogona kugonesa kana kudzima DoH uchishandisa iyo "chrome://flags/#dns-over-https" kuseta. Matatu ekushandisa modes anotsigirwa: akachengeteka, otomatiki uye akadzima. Mune "yakachengeteka" modhi, mauto anotemerwa chete zvichibva pane yaimbove cached yakachengeteka kukosha (yakagashirwa kuburikidza yakachengeteka yekubatanidza) uye zvikumbiro kuburikidza neDoH; yekudzokera kune yakajairwa DNS haishandiswe. Mune "otomatiki" modhi, kana DoH uye cache yakachengeteka zvisipo, data inogona kutorwa kubva kune isina kuchengetedzwa cache uye inowanikwa kuburikidza neyakajairwa DNS. Mu "off" mode, cache yakagovaniswa inotanga kuongororwa uye kana pasina data, chikumbiro chinotumirwa kuburikidza nehurongwa DNS. Iyo modhi inoiswa kuburikidza
Kuedza kugonesa DoH kuchaitwa pamapuratifomu ese anotsigirwa muChrome, kunze kweLinux neIOS nekuda kwechimiro chisiri chidiki chekuparura zvigadziriso zvekugadzirisa uye kurambidza kupinda kune system DNS marongero. Kana, mushure mekugonesa DoH, pane matambudziko ekutumira zvikumbiro kune server yeDoH (semuenzaniso, nekuda kwekuvharika kwayo, network yekubatanidza kana kutadza), bhurawuza inongodzosa iyo DNS marongero.
Chinangwa chekuedza ndechekupedzisira kuyedza kushandiswa kweDoH uye kudzidza mabatiro ekushandisa DoH pakuita. Zvinofanira kucherechedzwa kuti chokwadi tsigiro yeDoH yaive
Ngatiyeukei kuti DoH inogona kubatsira kudzivirira kubuda kweruzivo nezve akakumbirwa mazita ekugamuchira kuburikidza nemaseva eDNS evanopa, kurwisa MITM kurwiswa uye DNS traffic spoofing (semuenzaniso, kana uchibatanidza kune yeruzhinji Wi-Fi), kuverengera kuvharira paDNS. nhanho (DoH haigone kutsiva VPN munzvimbo yekupfuura nekuvharira kunoitwa padanho reDPI) kana kuronga basa kana zvisingaite kuwana zvakananga DNS maseva (semuenzaniso, paunenge uchishanda kuburikidza neproxy). Kana zviri zvakajairika zvikumbiro zveDNS zvakatumirwa zvakananga kumaseva eDNS anotsanangurwa mukugadziriswa kwehurongwa, saka mune yeDoH, chikumbiro chekuona iyo IP kero yakavharirwa muHTTPS traffic uye inotumirwa kuHTTP server, uko kunogadzirisa maitiro. zvikumbiro kuburikidza neWebhu API. Iyo iripo DNSSEC chiyero inoshandisa encryption chete kuratidza mutengi uye server, asi haidzivirire traffic kubva pakubata uye haivimbisi kuvanzika kwezvikumbiro.
Source: opennet.ru