6 ms·
My ISP (Entel Chile) started blocking DNS requests to non-Entel servers in July. DoT would not give me a way around this, because they can still see that it is
by oskapt 7y ago
My ISP (Entel Chile) started blocking DNS requests to non-Entel servers in July. DoT would not give me a way around this, because they can still see that it is DNS traffic by the port. DoH mixes DNS traffic in with the noise of HTTPS traffic, allowing me to run my own DoH resolvers and bypass their restrictions.
- teddyh 7y agoOnce your ISP starts mucking with and blocking your traffic, what you need is a VPN and/or Tor – DoH is a very partial solution at best. What DoH gives you is merely a correct answer to a DNS lookup of an IP address. But if your ISP blocks traffic to that IP address, which they could, you’re still blocked; DoH did not help you.
- judge2020 7y agoThe ISP is trying to block other DNS traffic, they're not necessarily trying to block certain websites (or if they are, they wouldn't want to block [for example] all of Cloudflare or the GCP load balancers to block porn hosted on either of those services). DoH solves that problem as directly as possible without going to solutions that have other side-effects.
- teddyh 7y agoThe ISP do most certainly want to block web sites. The currently most common method is to block DNS, but they could, and will, switch to IP blocking in a heartbeat if they have to. > they wouldn't want to block [for example] all of Cloudflare or the GCP load balancers If your only defense against blocking by your ISP is to centralize web server hosting, then you’re just moving the problem to there instead. Cloudflare also blocks, or “deplatforms”, those they deem unseemly. And once someone is taken off the centralized web server hosts, they can be blocked by your ISP again. You’re not solving the problem in the long term. DoH is fighting yesterday’s war.
- oskapt 7y agoTor has limited value. Lots of things are blocked (search, for example), and it's slower than dialup. The security of the exit points is also questionable, and this is about trust. Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy. I don't want my traffic to bounce from Chile to Norway and then back to Chile when I do online banking. I run a VPN endpoint in Chile for my own traffic, but I don't need to push all of my home traffic through it....yet. All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites, but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries.
- teddyh 7y ago> Tor [is] slower than dialup. That was true years ago, but nowadays I rarely percieve any speed difference at all when comparing browsing using Tor and non-Tor. > Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy. But, and here’s the crucial difference: with VPNs you have a choice. A wide variety of choice. With ISPs, especially in the US, not so much. > All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites, That’s due to be fixed with ESNI. Just wait for a technical fix. > but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries. That is true today, but when DoH and/or DoT happens, the ISPs will certainly switch to doing whatever still works. They are merely sniffing and proxying DNS traffic today because it still works, but the second it no longer works, they will switch to whatever does work. You can’t just work around the current mechanisms, you have to look a few more moves ahead.
- ga-vu 7y agoMozilla has deployed a canary domain with Firefox. Your ISP can block that canary domain and they'll automatically disable DoH for you... ooops!
- throw0101a 7y ago> DoH mixes DNS traffic in with the noise of HTTPS traffic, allowing me to run my own DoH resolvers and bypass their restrictions. And when malware gets on your network and starts using DoH to get around your home resolvers, what will you do? * https://www.zdnet.com/article/first-ever-malware-strain-spotted-abusing-new-doh-dns-over-https-protocol/ https://www.zdnet.com/article/first-ever-malware-strain-spot... * https://www.zdnet.com/article/psixbot-malware-upgraded-with-google-dns-over-https-sexploitation-kit/ https://www.zdnet.com/article/psixbot-malware-upgraded-with-... As someone who works in IT, this is my problem with DoH.
- KyleJ61782 7y agoThat was already a possibility even before all of this DoH publicity. Mozilla, etc. pushing DoH publicizes it's availability, but there was nothing in the past preventing malware from tunneling all sorts of traffic over HTTPS. DNS inspection isn't an end all, be all for malware security. It just gets the low hanging fruit.
- throw0101a 7y agoThere was a lot of low-hanging fruit given that most malware writers aren't going to set up all of this infrastructure for custom protocols. And even when they did, creating various C&C servers, the lack of ESNI would allow for detecting activity once the daily domain creation algorithm was reverse-engineered: * https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/ https://blog.malwarebytes.com/security-world/2016/12/explain...
- akerl_ 7y agoThis is possible regardless of whether Chrome/Firefox/etc deploy DoH support. In fact, it was possible before DoH at all: nothing mandated that malware use standard DNS requests on port 53.
- throw0101a 7y ago> ... nothing mandated that malware use standard DNS requests on port 53. Except using other ports would cause network monitoring software to throw red flags because of the "strange" traffic on non-standard ports.