Ukulandela
Uhlu olumhlophe lwabahlinzeki be-DNS luhlanganisa
Umehluko obalulekile kusukela ekusetshenzisweni kwe-DoH ku-Firefox, okwenza kancane kancane i-DoH isebenze ngokuzenzakalelayo
Uma ethanda, umsebenzisi anganika amandla noma akhubaze i-DoH esebenzisa isilungiselelo esithi “chrome://flags/#dns-over-https”. Kusekelwa izindlela ezintathu zokusebenza: zivikelekile, ziyazenzakalela futhi zivaliwe. Kumodi "evikelekile", ababungazi banqunywa kuphela ngokusekelwe kumanani avikelekile agcinwe kunqolobane yangaphambilini (atholwe ngoxhumano oluvikelekile) kanye nezicelo nge-DoH; ukubuyela emuva ku-DNS evamile akusetshenziswa. Kumodi "ezenzakalelayo", uma i-DoH nenqolobane evikelekile ingatholakali, idatha ingabuyiswa kunqolobane engavikelekile futhi ifinyelelwe nge-DNS evamile. Kumodi "yokucisha", inqolobane eyabiwe iqala ihlolwe futhi uma ingekho idatha, isicelo sithunyelwa ngohlelo lwe-DNS. Imodi isethwe nge
Ukuhlolwa kokunika amandla i-DoH kuzokwenziwa kuzo zonke izinkundla ezisekelwa ku-Chrome, ngaphandle kwe-Linux ne-iOS ngenxa yokungeyona into encane yokuhlukanisa izilungiselelo zesixazululi kanye nokukhawulela ukufinyelela kuzilungiselelo zesistimu ye-DNS. Uma, ngemva kokunika i-DoH amandla, kunezinkinga zokuthumela izicelo kuseva ye-DoH (isibonelo, ngenxa yokuvinjwa kwayo, ukuxhumeka kwenethiwekhi noma ukwehluleka), isiphequluli sizobuyisela ngokuzenzakalelayo izilungiselelo zesistimu ye-DNS.
Inhloso yocwaningo ukuhlola okokugcina ukuqaliswa kwe-DoH nokutadisha umthelela wokusebenzisa i-DoH ekusebenzeni. Kufanele kuqashelwe ukuthi empeleni kwaba ukwesekwa kwe-DoH
Masikhumbule ukuthi i-DoH ingaba wusizo ekuvimbeleni ukuvuza kolwazi mayelana namagama aceliwe osokhaya ngokusebenzisa iziphakeli ze-DNS zabahlinzeki, ukulwa nokuhlaselwa kwe-MITM kanye nokukhwabanisa kwethrafikhi ye-DNS (isibonelo, lapho uxhuma ku-Wi-Fi yomphakathi), ukuphikisana nokuvinjwa ku-DNS. ileveli (i-DoH ayikwazi ukufaka esikhundleni i-VPN endaweni yokuvimbela ukudlula okwenziwa ezingeni le-DPI) noma yokuhlela umsebenzi uma kungenakwenzeka ukufinyelela ngokuqondile amaseva e-DNS (isibonelo, uma usebenza ngommeleli). Uma esimweni esivamile izicelo ze-DNS zithunyelwa ngokuqondile kumaseva e-DNS achazwe ekucushweni kwesistimu, khona-ke esimweni se-DoH, isicelo sokunquma ikheli le-IP lomsingathi sihlanganiswa kuthrafikhi ye-HTTPS futhi sithunyelwe kuseva ye-HTTP, lapho isixazululi sicubungula khona. izicelo nge-Web API. Izinga elikhona le-DNSSEC lisebenzisa ukubethela kuphela ukuze uqinisekise iklayenti neseva, kodwa alivikeli ithrafikhi ekungeneni futhi aliqinisekisi ukugcinwa kuyimfihlo kwezicelo.
Source: opennet.ru