3 ms·
> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Not in applications!
by isostatic 7y ago
> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Not in applications!
You're right. But so are Mozilla.
Here we are 30 years into the web, and we're still using plain old DNS. DNS over TLS should have caught on, but it didn't. Apple and Microsoft had years to ensure it's implemented as standard, but they didn't.
The points this article makes - about DHCP options, about multiple providers, are very valid.
But they're also just talking shops.
The biggest problems here seems to be
1) DHCP can't give internal DOH servers. When I'm at home I want it landing on my own DOH server, but when I'm away I want to use a different one.
2) Internal DNS resolving falls to bits
- throw0101a 7y ago> DNS over TLS should have caught on, but it didn't. So enable DoT instead.
- m-p-3 7y agoAgreed, I'd prefer setting up the DNS-over-HTTPS config at the gateway level (and either push the config over DHCP, or have the gateway act as a local resolver, which forwards the new requests over DoH), but we're not there yet.
- isostatic 7y agoIn theory isn't it "just" a matter of agreeing a DHCP option number, then having the DHCP client (or vpn client or whatever) be responsible for passing it to applications that want it (including the system resolver, be that mDNSResponder, systemd, glibc, whatever windows uses) Anyone who wants to can configure their dhcp client to ignore it, or use a different service, you could even have applications doing that too, but this would allow a network operator to tell people where the recommended resource is. Likewise if you want to change your DNS provider yourself you would have a single location on your machine to do it for the entire OS, rather than having to change 50 different applications.
- bscphil 7y ago> have the gateway act as a local resolver, which forwards the new requests over DoH This is what I would like to see as a default (and included in routers). In fact, it's what I already do myself. I think (as others here have said) that the privacy concerns the article raises are mostly FUD. But I do agree with the article when it says handling DNS at the application level is kind of a terrible idea (even though it might seem justified in this case). If the end result is that every application has its own built in network stack, that's going to be terrible for security, usability, and make it much harder to debug third-party apps.
- ripdog 7y agoI use my pfsense router as a DoH recursive resolver, so while DNS is unencrypted inside my local network, all requests are protected when the enter the internet.