6 ms·
Encrypted DNS is a good idea, I just wish all of the basic protocols were getting encryption in-place, instead of being reinvented over HTTPS. First HTTP/3 (ne
by 60654 7y ago
Encrypted DNS is a good idea, I just wish all of the basic protocols were getting encryption in-place, instead of being reinvented over HTTPS.
First HTTP/3 (nee QUIC) reinvented TCP and ports over HTTPS, now DOH is reinventing DNS over HTTPS... Sigh. Both of these would be better off by evolving and modernizing their respective existing protocols. And HTTP is a client/server protocol with a _heavy_ handshake cost, why are we using it for a quick one-off request like DNS.
- iampims 7y agoin my experience, it's not about the protocols, it's about all existing middleboxes blocking/intercepting all traffic on non 443 ports. UDP traffic is notoriously blocked by routers. The only viable option being: HTTPS.
- sundbry 7y agoProbably because in your corporate/controlled environment you're supposed to use the company DNS for a good reason.
- bluejekyll 7y agoIf you're not using a VPN, DNS is actually pretty easily spoofed. DoH and DoT make that much harder.
- defanor 7y ago> The only viable option being: HTTPS. But why not DoT on port 443? The story about office workers, sysadmins, and service providers trying to make life harder for each other and complicating things for everyone seems unfortunate, but makes sense, yet I don't quite see why HTTP has to be involved.
- bluejekyll 7y agoHTTP2 isn't significantly more overhead than TLS in my experience. Also, using DoT over 443 would mean that you have an issue with traffic not being distinguishable for routing purposes at the edge. By making DNS on 443 DoH, it means that all HTTP2 routers/loadbalancers/etc. can work the same regardless of it being a Web request or a DNS request, because then they are both Web, i.e. HTTP, requests.
- cmroanirgo 7y agoI don't disagree. But the problem began decades ago when sysadmins started using firewalls to control what employees could access. During early 2000's I was involved in moving a lot of apps that used a bespoke port to port 80/443 just to make sure our apps and services didn't have any client hiccups due to (rightly so?) belligerent sysadmins. All this has really done has made sysadmins lives harder bc of packet inspection. So, all app developers and now infrastructure solution devs must run thru 443, otherwise the take up wouldn't happen. The internet is effectively running on one port nowadays.
- throw0101a 7y ago> But the problem began decades ago when sysadmins started using firewalls to control what employees could access. If the sysadmins were told "We don't want people doing X on company time: stop it.", that is hardly the sysadmins' fault. Do you think IT / Helpdesk wants the drama of extra calls because certain things are blocked? That they're sitting in their cubicles twirling their sinister mustaches thinking of ways to make people's lives more difficult?
- aduitsis 7y agoThe Bastard Operator From Hell! :-)
- mrfredward 7y agoHonestly, I've met a handful of IT bureaucrats who enjoyed the power trip of holding up dozens of people on a multimillion dollar project over an outdated policy. These people are the exception, not the norm, but it only takes one.
- pdkl95 7y ago> holding up ... over an outdated policy https://en.wikipedia.org/wiki/Slowdown#Rule-book_slowdown https://en.wikipedia.org/wiki/Slowdown#Rule-book_slowdown When used carefully, it can be a very effective tactic.
- 7y ago
- tamrix 7y agoThere's DOT aswell. Http over tls which doesn't use http. It's on your andriod phone now!
- bluejekyll 7y agoThe big concern with DoT is that firewalls are more likely to block the new port on outbound requests than DoH requests over 443. I think the main concern here is that it would slow uptake of the new protocol similar to how long IPv6 has taken to get fully supported.
- jedisct1 7y agoDNSCrypt uses the standard DNS mechanism, and just encrypts the content beforehand. Quick one-off requests. No handshake cost. It uses UDP, or TCP for large responses, exactly like standard DNS. In fact, it can even share port 53 with standard DNS. But can be configured to use TCP/443 if you're on a network where this is the only port that works.
- tveita 7y ago> First HTTP/3 (nee QUIC) reinvented TCP and ports over HTTPS This doesn't sound right. QUIC is built on UDP and TLS 1.3, not HTTPS. HTTP/3 doesn't go over itself. TLS 1.3 also makes the handshake significantly cheaper with the option for 0-RTT resumptions. DNS isn't really being reinvented either - it's the old wire format with a different framing.
- baltbalt 7y agoI feel that this everything over HTTPS trend is a scam, I don't know how or why yet, I just feel it. Perhaps it makes the surveillance tooling more uniform and easier to develop/maintain. The argument that HTTPS is always available and not filtered is just wrong, anyone who has experience working with large corporations knows that clients use local * certificates and everything is decrypted by the firewall and then re-encrypted. Making HTTPS slow af and sometimes plain broken. I guess someone will implement a full HTTPS stack in js and announce HTTPS over HTTP to go around this "problem".
- mukti 7y ago> The argument that HTTPS is always available and not filtered is just wrong, anyone who has experience working with large corporations knows that clients use local * certificates and everything is decrypted by the firewall and then re-encrypted. Making HTTPS slow af and sometimes plain broken. Yeah, and implementing everything over https is just going to make things harder or impossible to filter. There's a reason that large corporations block certain things, so if they get reimplemented over http, that will just be a security hole. It would be nice if an actual encrypted DNS protocol was created.
- throw0101a 7y ago> First HTTP/3 (nee QUIC) reinvented TCP and ports over HTTPS, Well, multi-streaming and multi-homing is part of SCTP, but no one seems to have bothered implementing it. > now DOH is reinventing DNS over HTTPS... Sigh. DoT was already invented when the Web folks decided to go and invent DoH: * https://en.wikipedia.org/wiki/DNS_over_TLS https://en.wikipedia.org/wiki/DNS_over_TLS
- deleted 7y ago[deleted]
- codewiz 7y agoHTTP had persistent connections ever since HTTP/1.1, and HTTP/2 supports parallel streams within the same persistent connection. HTTP/3 is still a IETF draft, but is already being deployed pretty much by all big sites. It supports zero-round-trip (0RTT) requests even after the IP of the client has changed. DoH can essentially match the latency of traditional UDP queries, while also encrypting the channel and traversing any gateways that let HTTPS through.
- zrm 7y agoYou can't get 0-RTT with TCP because the TCP handshake itself isn't 0-RTT. HTTP/3 accomplishes it by switching to UDP -- but then you can't get through the legacy middleboxes that only allow HTTPS over TCP port 443.