3 ms·
They can't, because that's handled at the OS level, not the application level. If a browser starts (purposefully) subverting the hosts file or not adhering to
by cremp 8y ago
They can't, because that's handled at the OS level, not the application level.
If a browser starts (purposefully) subverting the hosts file or not adhering to resolv addresses, then we've got a bigger problem.
Think, a fat client resolving an address differently than a browser; then that's all sort of Pandora's Box.
- drb91 8y agoDNS over HTTPS is still handled at the OS level? Related, it should be possible to have “correct” dns in userland that behaves as you describe sans falling back to the system resolver. In my understanding the whole point of DNS over https is to avoid the DHCP assigned DNS address (and of course encrypt) Finally, I’m pretty sure Firefox at least does its own dns caching. I’ve had to force reload to pick up dns changes already visible to the system resolver.
- cremp 8y agoDoH isn't done by the OS. But that's my point. In order to use DoH, you have to (purposefully) use an extension/browser addon/browser setting. As a system admin myself; if user applications started overriding the DHCP DNS that I give them, not only could intranet sites be broken, but I'd start having fights with users about it. Edit: Rather, not overriding but querying the DoH instead of the provisioned DHCP DNS. I'm no expert in DoH, or how any of that works under the hood. Further, when/if browsers turn on DoH by default, then I can't really fight users, because they did nothing wrong but use a browser. Suddenly, I can't support a browser or two because of it. DNS caching by the application is fine, because they made the request to the OS, and got the response. That being said, TTL might be violated by that, since the record has a TTL, and whatever the application cache TTL is.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- Brybry 8y agoI think the typical way to do DNS over HTTPS is to run a DoH client/DNS proxy and then point your nameservers at localhost. I'm not really sure what benefit there is to doing this compared to DNS over TLS with a resolver like Unbound but I suppose that's a different discussion. What Firefox seems to be doing, unless I'm mistaken, is running their own resolver that implements DoH/connects to Cloudflare and bypasses OS settings.[1][2] I haven't dug into the details yet to see how it interacts with the hosts file. It does sound like it falls back to the OS if it fails to resolve with DoH but this solution at first glance appears unideal. Wouldn't it be best if Microsoft/Apple/*nix distros/ISPs/third party nameservers used resolvers and nameservers that support DNS over TLS? Then end users/administrators could choose who they trust and everything would still be encrypted. [1] https://wiki.mozilla.org/Trusted_Recursive_Resolver https://wiki.mozilla.org/Trusted_Recursive_Resolver [2] https://bugzilla.mozilla.org/show_bug.cgi?id=1434852 https://bugzilla.mozilla.org/show_bug.cgi?id=1434852
- snvzz 8y agoSee dnscrypt-proxy. That's what I use on my network. It's the default DNS in the network. Computers do not need to know the detail it gets encrypted past that point.