13 ms·
A cartoon intro to DNS over HTTPS
- Klathmon 8y agoThere was a good chunk of time where my ISP (Verizon FIOS at the time) was having some kind of DNS hijacking attack happening where many CDN IPs were being replaced with an IP of a server that was adding some ad-injecting javascript into many pages (and god knows what else, I still have the payload laying around somewhere as I saved it for future curiosity). At the time my only real recourse was to pump my whole house through a VPN, as even Google's DNS (8.8.8.8) was being hijacked, but ONLY when it was coming from my home IP. (Full disclosure, i'm not very well versed in the networking stack. I know enough to get myself in trouble, but not much more. This was what I understood to be happening, but I could be way off base. However it was happening on multiple devices, multiple OSs, multiple verizon IPs, multiple DNS servers, both with and without a router, and would stop instantly if any of those machines were pointed at a wireless hotspot, or a VPN was turned on. At one point I even sent my router's WAN connection through my phone's hotspot and the problem went away) After talking with verizon many times and each time having to spend an hour or so trying to get through to someone that knew even remotely what I was talking about, all they were able to do was reset my IP, which fixed nothing. Now that DNS-over-HTTPS is becoming more common, i'm going to use it everywhere I can. Yes, DNSSEC might be a "better" solution, but I can use DoH right now to protect myself on all sites and (hopefully soon) all devices. Just the other day I discovered Intra [0] a (still unreleased) app by Google for android which has your whole android phone use DNS-over-HTTPS. I've been running it the last few days and i'm quite pleased with it. Does anyone know of a way to force all DNS queries in windows to use DoH? [0] https://play.google.com/store/apps/details?id=app.intra&hl=en_US https://play.google.com/store/apps/details?id=app.intra&hl=e...
- Skunkleton 8y agoPersonally, I highjack all DNS requests made on my network at my router, then use a VPN tunnel to resolve them on a server that I control that runs unbound. My guess is that FIOS was doing the same to you, just without your interests in mind. A similar setup to mine could be deployed at your network edge, and it could then force all of your port 53 DNS requests to go over a more secure protocol. Of course you would have to figure out how to set this up, and it wouldn't protect your devices anywhere except your home network.
- Klathmon 8y ago>My guess is that FIOS was doing the same to you, just without your interests in mind. It wasn't FIOS doing it, the IP was in Israel and was known as a malware serving IP.
- mcone 8y ago> Does anyone know of a way to force all DNS queries in windows to use DoH? I think you could use pi-hole to do this. https://docs.pi-hole.net/guides/dns-over-https/ https://docs.pi-hole.net/guides/dns-over-https/
- jchw 8y agoYou could also run your own DNS server as well, like Core DNS, and configure it to resolve through DNS-over-HTTPS. I'm sure this is about the same thing, but it's worth noting that you could possibly use your existing router or NAS to run the software.
- Klathmon 8y agoThanks a ton, this looks fantastic! Do you know if it's possible to setup Pihole to use this (and possibly other features) but not do any adblocking?
- moderation 8y agoI'm using cloudflared [0] for this. Allows me to have system level DoH and everything uses it (unless explicitly configured not to). Working on Linux machines (amd64 and aarch64) and MacOS. The documentation is not great / accurate but with a bit of fiddling I have it running as a systemd service (launchctl on MacOS). I'm using the /metrics endpoint to get details in Prometheus on the stats. 0. https://github.com/cloudflare/cloudflared https://github.com/cloudflare/cloudflared
- PappaPatat 8y agoSure, just deselect the blocklists in the GUI of your pi-hole.
- jedisct1 8y agoUse dnscrypt-proxy https://github.com/jedisct1/dnscrypt-proxy https://github.com/jedisct1/dnscrypt-proxy
- jchw 8y agoI don't think DNS-over-HTTPS precludes the use of DNSSEC - I think the intent is that eventually, you will in fact use both in tandem. DNSSEC alone would only give you the ability to check the integrity of a record, but DNS-over-HTTPS makes the transaction confidential and prevents third parties from censoring the request.
- Klathmon 8y agoI guess I was just heading off the flurry of comments along the lines of "Why use DoH when we have DNSSEC?" that always seem to come up when discussing DoH.
- pornel 8y agoDNSSEC has no encryption. It's not for privacy at all.
- bluejekyll 8y agoRight, DNSSEC is about validating the authenticity of the DNS Record in a DNS Message, whereas DNS-over-TLS/HTTPS is about establishing authenticity and privacy with the upstream resolver. In theory if the upstream resolver is using DNSSEC to validate all the Records, then the client over the TLS session can be fairly confident in the Records it receives.
- moderation 8y agoGreat find with Intra. Installed and working well on Pixel XL 2.
- textmode 8y ago"Threats to users' privacy and security are growing." s/privacy/&, autonomy/' Case in point about autonomy is on HN front page at present: https://news.ycombinator.com/item?id=17196888 https://news.ycombinator.com/item?id=17196888 The author cites a hypothetical example where a user shopping at Megastore is blocked from accessing her preferred source of DNS data in order to prevent her from checking a price. Extending this hypothetical, imagine if in response to her request for an unbiased price quote the user was shown unwanted ads with inflated, customised pricing (informed by data gathered about her through tracking). Choice of DNS data is an effective way for users to block advertising and tracking. The issue with user control over DNS also arises with mobile and other devices (e.g. Chromecast/Google Cast/Google Home) that discourage or prevent a user from using her preferred source of DNS data, forcing her to use a commercially-oriented source which may block certain lookups. This is relevant with any computer that connects to the internet. It is an issue of autonomy. There is a long tradition of HOSTS files and later non-commercial DNS where users can autonomously determine where on the network they want to "go". They have the final control over the source of DNS data the computer will use. They can delegate DNS service to someone else, however, following that long tradition, they still retain the autonomy to choose the source of the DNS data, whether it is another third party, their own DNS servers or perhaps /etc/hosts in place of DNS. When an organization (e.g. running an "app store") seeks to circumvent the ability of the user to choose her own DNS data source on her own computer, that is an attack on autonomy. The author mentions that Firefox will allow users to choose their own "DOH DNS" servers. If so, this respects users' autonomy. (No one seems to be mentioning one obvious advantange of DOH DNS for browsers: bulk DNS "prefetch" lookups. One can use HTTP/1.1 pipelining to retrieve the IP addresses for every hostname contained in an HTML page, with a single HTTP request, instead of numerous, simultaneous DNS requests. As for privacy problems with TLS fingerprints, HTTP requests can be secured by CurveCP as an alternative to TLS - example is in my profile.)
- vetinari 8y agoI see additional problem with this, which actually endangers autonomy. The resolving is not only done for user-initiated action, but is being done by many programs, even which you might not want to do it. For the same reason, many users use a local firewall to block outcoming connections, like Little Snitch. (Sidenote: if you are using MS Office 2016 for Mac, and are not satisfied with the choice of telemetry that Microsoft offered you in the last update, and you are interested in third option, "None", the hostnames to block are nexusrules.officeapps.live.com and nexus.officeapps.live.com) With apps using DoH and ignoring the local resolver, that firewall will now have a problem, especially if multiple, separate hostnames resolve to the same IP. Until now, Little Snitch used a guess (last resolved hostname that matches the IP); now it won't have that chance. That's why, if the user wants to have a chance to who their local processes talk to, they must be forced to use a local resolver under user's control, not implement their private resolver. And of course, on non-public networks, it should be supplie-able by DHCP or RA.
- iampims 8y agoI applaud the efforts to increase privacy,reduce data collection and hardened security. Do we really want a SPOF in Cloudflare for this though? A single outage (or AT&T snafu) and many millions of users would be affected.
- dogecoinbase 8y agoIn fact, it already happened between this Mozilla announcement and now: https://www.cloudflarestatus.com/incidents/2mz3wly2g7dy https://www.cloudflarestatus.com/incidents/2mz3wly2g7dy I think encrypting DNS transport is as important as the next guy (though DoH is bad), but am super unhappy about Mozilla apparently signing on with Cloudflare's ongoing fairly successful attempts to centralize the internet. Sure, they say they'll delete your data "within 24 hours" (they shouldn't be keeping it at all), but pretty soon they'll get a Nat'l Security Letter like everyone else does.
- tracker1 8y agoWhich begs the question, do they have a canary page? In any case, it would be unreasonable to require logging for more than that... even a week would be too much data for many ISPs. Also, they have to have some logging to be able to even try and troubleshoot a problem.
- floatingatoll 8y agoThe article clearly states a desire to ship more providers as soon as more providers exist. If you know of any other providers who meet the declared privacy choices (e.g. deleted after 24 hours) and protocol choices (e.g. DoH, TRR, QNAME min), please do let us know!
- patrickmcmanus 8y agoDefinitely don't want SPOF. Firefox has both soft-fail and hard-fail modes.. for a soft fail it will fallback to traditional port 53 DNS. Its likely that will be the most common deployment - you need it to deal with captive portals and other split horizon issues as well cloud uptime incidents. But there is a hard fail mode if that is suitable for your environment. and of course defaults matter a lot, but you will be able to select your preferred DoH endpoint (or not use it at all). Firefox wouldn't lock something like that down.
- philip1209 8y agoDNS over HTTPS uses DNS in the protocol. Does that make it extra-recursive DNS?
- Klathmon 8y agoIsn't the expectation that the hostname header will be hardcoded for DoH requests?
- jedisct1 8y agoNot necessarily. You can connect using an IP address. At least to bootstrap the process. This is where DNS Stamps come in handy https://github.com/jedisct1/dnscrypt-proxy/wiki/stamps https://github.com/jedisct1/dnscrypt-proxy/wiki/stamps
- bluejekyll 8y agoI am very conflicted about DNS-over-HTTPS vs. DNS-over-TLS. Most of DNS-over-HTTPS' interesting use-cases start coming into play when you're using the same HTTPS session as the one being used to serve the site you're visiting. Otherwise, DNS-over-TLS is sufficient for the same level of privacy. At that point though, DNS-over-HTTPS has a provenance issue that I don't fully grok how we're going to avoid. What I mean by that: if the site you're visiting supports DNS-over-HTTPS, where requests to that site for DNS records are requested, what happens when they decide to issue custom responses to DNS requests that ignore or supplement actual data in a zone? Won't that lead to a bifurcation of the DNS network, where web-sites can start issuing custom response to DNS queries? Cloudflare, and Quad9, both offer DNS-over-TLS, this will be preferable for non-HTTP use-cases. Some of the points in the article imply that DNS when using DNS-over-HTTPS can't be used for tracking you, but really that just means you're passing that trust to Cloudflare, Quad9, or Google. I suppose the choice is open to you at that point.
- jchw 8y agoI'm not sure I understand. I was under the impression that DNS-over-HTTPS was nothing more than just an alternative DNS protocol just like DNS-over-TLS, where you perform an HTTPS request in order to query for a DNS name, and that DNS-over-TLS was just plain old DNS wrapped in TLS. You seem to be implying that DNS-over-HTTPS would enable sites themselves to deliver DNS records. I don't see how that is possible, because connecting to HTTPS with a hostname requires resolving a DNS record. Am I misunderstanding?
- bluejekyll 8y agoYou are correct for the initial request. I've seen many arguing for taking this to another level of actually sending DNS requests over the same HTTPS session being used with a site the browser is currently connected to.
- jchw 8y agoIs this standardized/drafted? I am curious how one might implement this.
- nykolasz 8y agoThere are 3 major protocols available for DNS privacy: * DNSCrypt * DNS over TLS * DNS over HTTPS DNSCrypt is the one with better client support and a long list of providers available. If you pick DNS over TLS or DNS over HTTPS you will be restricted to 3 or 4 major players (google, quad9, cloudflare and cleanbrowsing). If you trust them, you are good. For example, this is the list of providers with DNSCrypt support: https://download.dnscrypt.info/dnscrypt-resolvers/v2/public-resolvers.md https://download.dnscrypt.info/dnscrypt-resolvers/v2/public-... For DNS over (HTTPS|TLS), there is very little client tools available for troubleshooting. The best one I found was these 2 in PHP: https://github.com/dcid/dns-over-tls-php-client https://github.com/dcid/dns-over-tls-php-client https://github.com/dcid/doh-php-client https://github.com/dcid/doh-php-client
- captn3m0 8y agoAre OS implementations planning to switch to DNS over TLS or DNS over HTTPS anytime soon? Because if not, any requests made by non-browsers are still susceptible and will only give users a false sense of security.
- tracker1 8y agoBecause it's better than doing nothing in the short term, and OSes can switch over as time moves on. Browsers have a much faster cadence and automatic updates (mostly).
- jedisct1 8y agoDNSCrypt is also the fastest and most secure. It doesn't require sessions (uses UDP by default, like regular DNS, but prevents amplification), enforces safe cryptography and pinned certificates, is trivial to implement, doesn't need OpenSSL, implements padding without inventing yet another DNS extension, and can use unique keys for each question (so that DNS providers can't fingerprint clients, unlike other options due to TCP sessions and TLS tickets).
- eridius 8y agoIf it's the fastest and most secure, why are people throwing their weight behind DNS-over-HTTPS? There must be a reason for it.
- barbegal 8y agoAs a cynic I would say this is an attempt by Google and Cloudflare to collect DNS data. Why else would they provide this service for free? Both Google's [1] and Cloudflare's [2] DNS privacy policy prohibits them from storing personally identifiable information or from correlating DNS information with other Google data coming from the same IP/account but it does allow them to store information about which domains are popular, from which locations and from which type of device. TLS (and therefore HTTPS) provides a very useful fingerprint based on accepted cipher suites, extensions, compression methods... [1] https://developers.google.com/speed/public-dns/privacy https://developers.google.com/speed/public-dns/privacy [2] https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/firefox/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... [3] https://devcentral.f5.com/articles/tls-fingerprinting-a-method-for-identifying-a-tls-client-without-decrypting-24598 https://devcentral.f5.com/articles/tls-fingerprinting-a-meth...
- cremp 8y agoCloudflare itself never made sense to me. What possible incentive do they have to stop their primary purpose (DDoS protection) - They have value in promoting the behavior. Whats worse, is everyone and their dog is using them. What happens when they push a bad config to their core routers, or foobar their anycast?
- ikeyany 8y agoIt doesn't make sense to you to do the right thing and protect people at the expense of profit?
- giggles_giggles 8y agoIt costs money to do the things they do. If there's no profit, the service has to beg for money, or die for lack of resources. CloudFlare is not a charity, and if it was one, it would be ineffectual because their services are too behind-the-scenes and technical to get a donor base wide enough to support them. Profit is not necessarily an anathema to doing the right thing, and if you can align your interests with your cash flow, you can do the right thing without begging for money, which imho is even better than doing the right thing but having to subsist on the money generated by profitable enterprises that aren't as noble (donated either directly, or by their employees). But of course, aligning those interests is a challenge.
- mike-cardwell 8y agoI kind of hate this. Taking a decentralised service, and replacing it with a service provided by a small handful of tech giants. "But this doesn’t mean you have to use Cloudflare. Users can configure Firefox to use whichever DoH-supporting recursive resolver they want. As more offerings crop up, we plan to make it easy to discover and switch to them." Only defaults matter. Your average web user wont be interested in knowing about or configuring this, no matter how simple the explanation/choice is made.
- inetknght 8y agoThen put it as part of your startup process, whether that's first-time startup or just-upgraded-from-a-previous-version startup. Do not select any default. Randomize the selections.
- dsr_ 8y agoWe have the NTP pool groups as a model for how to organize groups to offer services like DNS-over-HTTPS.
- marzell 8y agoIf only defaults matter, then it's already a dead horse, as the majority of users don't know what DNS even is, and are using their ISP's servers by default.
- gsich 8y agoWhy does the amount of people knowing about DNS matter? Especially in the context of decentralization?
- tracker1 8y agoDepending on your ISP and/or country of origin, it can matter a lot.
- moderation 8y agoThere is no decentralized DNS where the default for most users is their monopoly ISP.
- gsich 8y agoI tried DNS over TLS (somewhat similar) and it has some potential. But not with those strict timeouts. 1.1.1.1 closes the TCP connection almost instantly after the query response, 9.9.9.9 waits a bit longer, about 10 seconds (need to check again). So everytime you want to make a query, you have to wait several RTTs before getting a response. The connection need to be open for as long as possible, at least 5 minutes. I used stubby as forwarder with idle_timeout: 6500000, the idle timeout in ms. The connection gets closed by the remote party, not by stubby.
- jedisct1 8y agoBecause DNS servers were never designed to keep many open TCP connections.
- gsich 8y agoDoesn't matter what they were designed for. With TCP they need to behave that way. Otherwise this is a solution for people with latency <10 ms to the server. So not a whole lot. I'll argue that the TCP and TLS handshake take more processing power then keeping the connection open.
- caf 8y agoThe limiting resource with large numbers of idle sockets on the server side is memory, not processing power.
- gsich 8y agoWhich I doubt is a problem for Cloudflare or Quad9. Anyway, a TCP based DNS service needs to consider those things. Otherwise it is becoming unusable due to very high response times. A standard 8 GB system with Debian 9 gives me 1048576 max file descriptors. I am sure this can be optimized still.
- caf 8y agoThe default socket receive and send buffers are ~200KB, so you would actually need 400 GB of memory in order to have each of those 1048576 file descriptors connected to a unique socket. And if you were keeping them open for 5 minutes as suggested, that would still limit you to only 3400 clients / second. I do actually agree that they need a longer idle timeout on these connections, but I just wanted to point out that comparisons with the processing power required to set up a TLS connection aren't apt.
- bobajeff 8y ago>That means that your ISP can still figure out which sites you’re visiting, because it’s right there in the server name indication. Plus, the routers that pass that initial request from your browser to the web server can see that info too. Well there goes the interest I had in this.
- azdle 8y agoWell, when there's two issues, one needs to be fixed before the other.
- patrickmcmanus 8y agowe're coming after SNI too. One step at a time. (also, 1] dns leaks are worse than sni leaks as typically more people are exposed to the dns query and 2] HTTP/2 can carry more than one hostname on a connection so some hostnames that appear in dns are never leaked through sni.)
- tialaramex 8y agoThe TLS WG currently has only a problem statement for Encrypted SNI. Even the weak selection of two possible ways forward didn't achieve consensus as I understand it. I don't see any way to have encrypted SNI without paying a price of one additional round trip. That's a fair price for something you must have, but for anybody to benefit we must insist everyone use it always, or adversaries will simply block it. And a round trip is a high price for users who don't (believe they) need this.
- Skunkleton 8y agoDoesn't TCP, TLS, HTTP, and finally DNS seem like overkill? Why not DTLS + plain DNS requests?
- gsich 8y agoStandard HN response: Because my corporate firewall does not allow me to use UDP! Which is the nowadays excuse to use 80/443 for everything. Customers at home don't have this problem. But there are alternatives, DNS over TLS (essentially the same without HTTP) and dnscrypt which uses UDP.
- walrus01 8y agoThis is why I run an openvpn server on port 443 in tcp mode, not UDP, for places like shitty airport captive portal wifi.
- mholt 8y agoWas just wondering... what value will DNS over HTTPS provide if/when we all move to IPv6 and presumably everything could potentially be identified by IP address directly? Will datacenters/ISPs be incentivized to do NAT with IPv6 or have some other way of introducing indirection into the routing?
- gsich 8y agoHave fun remembering every IP by heart.
- mholt 8y agoNo, I mean that simply by observing the IP address of packets, you can know which hosts are being requested, since there are enough IP addresses to go around.
- gsnedders 8y agoThat's a reason to get rid of the TLS SNI extension and the HTTP Host header, but it's entirely unrelated to how DNS messages are transmitted.
- zackbloom 8y agoThink about Cloudflare itself. Millions of websites hosted behind a handful of IP addresses.
- mholt 8y agoSo we go back to re-centralizing for privacy? I love Cloudflare, but... if that's really the answer to this... sigh.
- tracker1 8y agoWell, about 8M websites are already behind Cloudflare... if you add the top 50 hosting providers, that's probably 95% of the internet. Traffic is already relatively centralized.
- 64kbisalluneed 8y agoAs a good and responsible parent DNS over HTTPS will never be an option. I run a DNS server on my local network.
- tracker1 8y agoYou could still have that DNS server use an upstream DNS over HTTPS or other encrypted channel that unifies traffic, which has the effect of anonymizing.
- codedokode 8y agoEncrypted DNS is an awesome idea. But routing all of your DNS requests to a private US company should not be enabled by default. And what about SNI that shows domain name in clear text for HTTPS connection? Please do something with it too.
- PappaPatat 8y agoNow just wait for your browser (or any other random application) to stop using your OS's resolve completely (at least Chrome does at times already by simply accessing DNS services via port 53 when it considers the configured OS DNS 'not good'. I have no idea about the exact criteria) by accessing its desired DNS-over-HTTPS server and bypass your carefully setup DNS filtering / monitoring. Notes 1: I have NO idea if Chrome (or any other random application) accesses DNS-over-HTTPS already since I have not paid too much attention to it. 2: At least Chrome (on OSX) likes to access 8.8.8.8 & 8.8.4.4 & your configured DNS server on port 53 (happy eyeball protocol). This might only be on flaky networks like mine, where I tend to make all sorts of configuration experiments.
- herghost 8y ago> "Threats to users’ privacy and security are growing." Website won't load without allowing a call out to googleadapis.l.google.com Yeah, you're right they are growing.
- h1d 8y agoWhy is DNS taking so long to have security patched in as if governments are pressuring to make sure they can snoop on things easily. Same goes for email. Having an opt in security mechanism is easy to deploy as in keeping the http version of a site available while running https on a new port for clients that want to use it.