Imibutho yorhwebo
Ukuqonda isibonelelo esipheleleyo sokusebenzisa uguqulelo oluntsonkothileyo lwetrafikhi ye-DNS, imibutho ikubona kungamkelekanga ukugxila kulawulo lwesisombululo samagama ngakwisandla esinye kunye nokudibanisa le ndlela ngokungagqibekanga kwiinkonzo ze-DNS ezisembindini. Ngokukodwa, kuxoxwa ukuba uGoogle ujonge ukwazisa i-DoH ngokungagqibekanga kwi-Android kunye neChrome, ethi, ukuba ibotshelelwe kwiiseva zikaGoogle, iya kwaphula ubume besiseko se-DNS kwaye yenze inqaku elinye lokusilela.
Ekubeni iChrome kunye ne-Android zilawula imarike, ukuba zinyanzelisa iiseva zabo ze-DoH, uGoogle uya kuba nakho ukulawula uninzi lwabasebenzisi be-DNS query query. Ukongeza ekunciphiseni ukuthembeka kweziseko ezingundoqo, inyathelo elinjalo liya kunika iGoogle inzuzo engafanelekanga ngaphezu kwabakhuphisana nabo, ekubeni inkampani iya kufumana ulwazi olongezelelweyo malunga nezenzo zabasebenzisi, ezinokuthi zisetyenziswe ukulandelela umsebenzi wabasebenzisi kunye nokukhetha intengiso efanelekileyo.
I-DoH inokuphazamisana nemimandla efana neenkqubo zolawulo lwabazali, ukufikelela kwizithuba zamagama zangaphakathi kwiinkqubo zamashishini, iindlela kwiisistim zokuphucula ukuhanjiswa kwesiqulatho, kunye nokuthotyelwa kwemiyalelo yenkundla echasene nokusasazwa komxholo ongekho mthethweni kunye noxhatshazo lwabantwana. I-DNS spoofing ikwasetyenziswa rhoqo ukuqondisa abasebenzisi kwiphepha elinolwazi malunga nokuphela kwemali kumbhalisi okanye ukungena kwinethiwekhi engenazingcingo.
uphando
Masikhumbule ukuba i-DoH inokuba luncedo ekuthinteleni ukuvuza kolwazi malunga namagama aceliwe abamba umkhosi ngokusebenzisa iiseva ze-DNS zababoneleli, ukulwa nokuhlaselwa kwe-MITM kunye ne-DNS ye-traffic spoofing (umzekelo, xa uqhagamshela kwi-Wi-Fi yoluntu), ukubala ukuthintela kwi-DNS. inqanaba (i-DoH ayinakuthatha indawo ye-VPN kwindawo yokudlula ibhlokhi ephunyezwe kwinqanaba le-DPI) okanye ukulungelelanisa umsebenzi ukuba akunakwenzeka ukufikelela ngokuthe ngqo kwiiseva ze-DNS (umzekelo, xa usebenza nge-proxy).
Ukuba kwimeko eqhelekileyo izicelo ze-DNS zithunyelwa ngokuthe ngqo kwiiseva ze-DNS ezichazwe kuqwalaselo lwenkqubo, ngoko kwimeko ye-DoH, isicelo sokugqiba idilesi ye-IP yomninimzi sifakwe kwi-traffic ye-HTTPS kwaye sithunyelwe kumncedisi we-HTTP, apho inkqubo yokusombulula. izicelo ngeWeb API. Umgangatho okhoyo we-DNSSEC usebenzisa i-encryption kuphela ukuqinisekisa umxhasi kunye neseva, kodwa ayikhuseli i-traffic kwi-interception kwaye ayiqinisekisi ubumfihlo bezicelo. Okwangoku malunga
umthombo: opennet.ru