Baetsi ba Firefox
Kamora ho kenya tšebetsong DoH, ho tla bontšoa temoso ho mosebelisi, e lumellang, ha ho hlokahala, ho hana ho ikopanya le li-server tsa DoH DNS tse bohareng le ho khutlela morerong oa khale oa ho romella likopo tse sa ngolisoang ho seva sa DNS ea mofani. Sebakeng sa meralo ea motheo e ajoang ea ba rarollang mathata a DNS, DoH e sebelisa tlamo ho tšebeletso e itseng ea DoH, e ka nkoang e le ntlha e le 'ngoe ea ho hlōleha. Hajoale, e fanoa ho sebetsa ka bafani ba babeli ba DNS - CloudFlare (ka kamehla) le
Fetola mofani oa thepa kapa u koale DoH
Hopola hore DoH e ka thusa ho thibela ho lutla ha tlhahisoleseling mabapi le mabitso a baamoheli a kopiloeng ka li-server tsa DNS tsa bafani, ho loants'a litlhaselo tsa MITM le DNS traffic spoofing (mohlala, ha o hokela ho Wi-Fi ea sechaba), ho thibela ho thibela ho thibela DNS (DoH). e ke ke ea nka sebaka sa VPN sebakeng sa ho thibela thibelo e kentsoeng maemong a DPI) kapa bakeng sa ho hlophisa mosebetsi haeba ho sa khonehe ho fihlella li-server tsa DNS ka kotloloho (mohlala, ha o sebetsa ka proxy). Ha e ntse e le boemong bo tloaelehileng likopo tsa DNS li romelloa ka ho toba ho li-server tsa DNS tse hlalositsoeng tsamaisong ea tsamaiso, tabeng ea DoH, kopo ea ho fumana aterese ea IP ea moeti e kenyelelitsoe ho sephethephethe sa HTTPS 'me e romelloa ho seva sa HTTP, moo mohatelli. e sebetsana le likopo ka Web API. Tekanyetso ea hajoale ea DNSSEC e sebelisa encryption feela ho netefatsa moreki le seva, empa ha e sireletse sephethephethe ho tsoa ho thibelo ebile ha e fane ka tiiso ea lekunutu la likopo.
Bakeng sa khetho ea bafani ba DoH e fanoang ka Firefox, the
DoH e lokela ho sebelisoa ka hloko. Ka mohlala, Russia Federation, liaterese tsa IP 104.16.248.249 le 104.16.249.249 tse amanang le seva sa Mozilla.cloudflare-dns.com DoH tse fanoang ka ho feletseng ho Firefox,
Ts'ebeliso ea DoH e ka boela ea baka mathata libakeng tse kang litsamaiso tsa taolo ea batsoali, phihlello ea libaka tsa mabitso ka har'a litsamaiso tsa likhoebo, khetho ea litsela lits'ebetsong tsa ntlafatso ea phano ea litaba, le ho kenya tšebetsong litaelo tsa lekhotla lepatlelong la ho loants'a ho ajoa ha litaba tse seng molaong, tlhekefetso ya bana ba banyenyane. Ho qoba mathata a joalo, ho kentsoe tšebetsong mokhoa oa ho hlahloba le ho lekoa o koalang DoH ka bo eona tlas'a maemo a itseng.
Ho tseba batharolli ba likhoebo, ho etsoa licheke bakeng sa libaka tsa boemo ba pele ba boemo ba pele (TLDs) 'me sesebelisoa se rarollang se khutlisetsa liaterese tsa intranet. Ho fumana hore na taolo ea batsoali e lumelletsoe, ho etsoa boiteko ba ho rarolla lebitso mohlalaadultsite.com mme haeba sephetho se sa lumellane le IP ea sebele, ho nkoa hore ho thibela litaba tsa batho ba baholo ho sebetsa boemong ba DNS. Liaterese tsa IP tsa Google le YouTube li boetse li hlahlojoa e le matšoao ho bona hore na li senyehile joalo ka restrict.youtube.com, forcesafesearch.google.com, le restrictmoderate.youtube.com. Licheke tsena li lumella bahlaseli ba laolang ts'ebetso ea sebatli kapa ba khonang ho kena-kenana le sephethephethe ho etsisa boitšoaro bo joalo e le hore ba thibele ts'ebetso ea sephethephethe sa DNS.
Ho sebetsa ka ts'ebeletso e le 'ngoe ea DoH le hona ho ka baka mathata ka ntlafatso ea sephethephethe ho marang-rang a phano ea litaba a sebelisang tekano ea sephethephethe a sebelisa DNS (seva ea DNS ea marang-rang ea CDN e hlahisa karabo, ho nahanela aterese ea mohatelli le ho fana ka litaba tsa moamoheli ea haufi. ho amohela dikahare). Ho romella potso ea DNS ho tsoa ho mohlophisi ea haufi haholo le mosebelisi ho li-CDN tse joalo ho khutlisa aterese ea moamoheli ea haufi haholo le mosebelisi, empa ho romella potso ea DNS ho tsoa ho setsi sa setsi ho tla khutlisa aterese ea moamoheli e haufi le seva sa DNS-over-HTTPS. Teko ea ts'ebetso e bonts'itse hore ts'ebeliso ea DNS-over-HTTP ha o sebelisa CDN ha ea ka ea lebisa tieho pele ho phetiso ea litaba (bakeng sa likhokahano tse potlakileng, tieho ha ea ka ea feta li-milliseconds tsa 10, esita le ho potlakisa ho ile ha bonoa mecheng ea puisano e liehang. ). Re boetse re nahanne ka ho sebelisa katoloso ea EDNS Client Subnet ho fetisetsa tlhahisoleseling ea sebaka sa bareki ho CDN solver.
Source: opennet.ru