13 ms·
A safer and more private browsing experience with Secure DNS
- TheChaplain 6y agoSigh, the two words Google and Privacy are like oil and water, but I digress... It will be interesting to see what reception this will get in some countries where all ISP's are legally bound to modify DNS-requests to prevent users connecting to sites with content such as child pornography.
- deleted 6y ago[deleted]
- buro9 6y agoEncrypted DNS is great, so long as the end user retains control over which DNS servers provide the answers. This does appear to be the case here, and so it is still possible to disable it (use a local stubby instance to do encrypted DNS) or to use a custom setting (your nextdns.io config for example).
- politelemon 6y agoFrom what I have seen Firefox has already been taking a similar approach for the past year. In enterprise environments, there's the ability to disable DoH. And for general audiences, the ability to fall back to normal DNS if necessary.
- badRNG 6y agoThe significant difference here is that Firefox has made it possible to maintain Split DNS without managing and reconfiguring every device via a network signal to continue to use split DNS (e.g. PiHole)
- tialaramex 6y agoThe upside of the "same provider" approach in Chromium is that it defuses a bunch of the complaints you get with Mozilla's approach about how they're picking winners (with the inevitable side dish of conspiracy theories). The downside is that it's opportunistic encryption which means it fails open. If you're actively targeted this won't protect you. You'll need to explicitly configure a DoH server to be protected.
- zrm 6y agoWhat's really needed is to add support for DoH or similar to internet gateways. Attacks are nearly always between the gateway and the internet and not between the client and the gateway on the same LAN, and then the gateway can safely require DoH by default because it isn't a significant administrative burden to change it in one place for the whole network if that isn't what you want. They could even default to something like trying DoH to the DNS server configured via upstream DHCP with fallback to DoH to Cloudflare or similar if that fails, but no default fallback to unencrypted DNS. Meanwhile if the administrator of the endpoint device knows their DNS server supports DoH, they could still manually enable it as required even if that isn't suitable as a default there, and the default Chromium is using still protects against passive attacks when your DNS server supports DoH.
- dmayle 6y agoForget the encryption; alter the protocol to support overfetching. (Instead of fetching a specific site, you fetch blocks of sites). In a naive version, you'd ask for every site from goodreads.com through to google.com, and then the client would actually visit the site it wanted. In a hardened protocol, I'd imagine you'd use hashing, along with a random salt so that there are many different ways to query the same site. Right now, your DNS provider has a list of every website you visit (just not how many times you visited it). The shorter the DNS cache, the more closely this list matches your browsing behavior. This definitely complicates the protocol, whether you put the burden at the resolver layer (needs larger cached) or at the level of authoritative servers (where'd they be effectively cooperating with root servers), but it's the only way to truly safeguard browsing data.
- textmode 6y ago"Instead of fetching a specific site, you fetch blocks of sites." I have been doing this for many years, putting bulk DNS data in HOSTS and personal use zone files served from loopback addresses. It is easier than ever today with so many sources of bulk DNS data. DOH now lets users retrieve DNS data from recursive DNS servers (caches) in bulk, using HTTP/1.1 pipelining. Here is a working example: https://news.ycombinator.com/item?id=23242389 https://news.ycombinator.com/item?id=23242389 Many years ago, I started doing non-recursive (no caches used) bulk DNS data retrieval for speed and also for resiliency in the event of outages. However the privacy gains are obvious. A rough analogy is downloading all of Wikipedia in bulk and browsing articles offline as opposed to making separate requests online for each article and generating all the requisite DNS and TCP/HTTP traffic. Openmoko's Wikireader experimented with the idea of offline Wikipedia. Not only does the DOH provider get a record of all the user's DNS lookups, she can now associate each request with the particular user program/device that made it.
- eatbitseveryday 6y agoWhy has the world gone towards DNS over HTTPS as opposed to adding TLS itself to the DNS protocol?
- cosmojg 6y agoDNS over TLS (DoT) already exists, and it's apparently both faster and more efficient. The argument I've heard for preferring DoH is the fact that it disguises DNS traffic, making it indistinguishable from other HTTPS traffic.
- deleted 6y ago[deleted]
- egyptiankarim 6y agoI think the arguments are that there's a degree of security through obfuscation by forcing everything over a single common port (443), the transmission integrity benefits of TCP versus UDP protocols, and maybe just the overall simplicity of HTTPS as a protocol.
- AnonC 6y agoThere’s DoT (DNS Over TLS), which operates on port 853, uses TCP and provides encryption. But it’s also something network operators can easily block since it runs on a specific, separate port. DNS over HTTPS (DoH), on the other hand, rides on HTTPS/port 443, which cannot be blocked in networks without causing major disruptions to the rest of the web traffic. A more detailed comparison is here: https://www.thesslstore.com/blog/dns-over-tls-vs-dns-over-https/ https://www.thesslstore.com/blog/dns-over-tls-vs-dns-over-ht...
- dsl 6y agoYou can run DoT on 443 as well. Providers that want to block DoH or DoT are going to block providers based on destination IP or certificate fingerprints, not port numbers.
- 6y ago
- tialaramex 6y agoAn interesting detail: How does their upgrade work if you're using a customised DNS service where the customisation is detected differently in DoH compared to plain DNS? For example NextDNS customers using DoH put a customisation parameter in the DNS URL paths (and so it's opaque to an adversary on the network) but obviously there's no URL path in conventional DNS, so does Chromium spot your NextDNS configuration and figure out the right URL path?
- staticassertion 6y agoDNS logs are important in an enterprise. But I'm sure many would want to also use DoH. Does Chrome provide any audit logging for DNS while in DoH mode?
- cosmojg 6y ago> DNS logs are important in an enterprise. But I'm sure many would want to also use DoH. Really? Why? As someone who works in academia, I don't see why anyone would need access to my or my colleagues' DNS logs, but I understand things might be different in industry.
- egyptiankarim 6y ago"Important" in the sense that many IT organizations have predicated their data forensics and incident response capabilities on being able to intercept and analyze traffic at arbitrary points within their corporate networks. That's not to say that those choices reflect good architectural design, to be sure quite the opposite. But like many things in enterprise IT risk management, it comes down to where you spent your money, and things like DoH/DoT force will force certain organizations to admit "a lot in the wrong place".
- dsl 6y agoMuch of this comes from regulatory oversight of specific industries. DoH isn't going to fly in the banking sector for example.
- staticassertion 6y agoTo be clear, I'm not asking for the ability to intercept DNS requests, or encrypted traffic, at all. I'm fine (and encourage) encryption on the wire. I'm just as happy to get the logs on the local system, and ship them off.
- m3047 6y ago> As someone who works in academia I wouldn't blame or ride on academia. If you have no data worth exfiltration, experiments worth sabotaging or industry affiliations you might be right.
- johnklos 6y agoOh, get the heck out of here with "Secure DNS". Allowing Google to snoop on all DNS is the opposite of safer and more private.
- jefftk 6y agoChrome maintains a list of DNS providers known to support DNS-over-HTTPS. Chrome uses this list to match the user’s current DNS service provider with that provider’s DNS-over-HTTPS service, if the provider offers one. By keeping the user’s chosen provider, we can preserve any extra services offered by the DNS service provider, such as family-safe filtering, and therefore avoid breaking user expectations. Secure DNS is a "same-provider DNS-over-HTTPS upgrade" approach, and it sounds like you're conflating it with a different design, where Chrome would talk to Google-run DNS servers? (Disclosure: I work at Google, speaking only for myself)
- ve55 6y agoAs far as I have noticed, only time Google makes something 'more private for everyone' historically, has been when they themselves have found a superior way to get around it. Whether this is because the entire Internet uses Google Analytics, Gmail, etc, or because they have a different more effective way of tracking DNS queries is irrelevant, since they always manage to find a way due to being omnipresent.
- krn 6y ago> As far as I have noticed, only time Google makes something 'more private for everyone' historically, has been when they themselves have found a superior way to get around it. In theory, DNS-over-HTTPS in Chrome allows Google to bypass OS-level ad blockers. Just like Manifest v3 limits the capabilities of in-browser ad blocking.
- tptacek 6y agoYes, Google is pushing DoH because, internally, in the AdWords division, they've broken elliptic curve DSA.
- kagenouta 6y agoAm I the only one thinking it's weird that this rolls out on ChromeOS first but other Linux platforms (including Android) last?
- deleted 6y ago[deleted]
- RandomBacon 6y agoI don't think it's weird. If there's a problem, it limits who is affected or allows them to fix it while the problem is small.
- Gaelan 6y ago> Furthermore, if there’s any hiccup with the DNS-over-HTTPS connection, Chrome will fall back to the regular DNS service of the user’s current provider by default, in order to avoid any disruption, while periodically retrying to secure the DNS communication Doesn't that make this pretty trivial to defeat? Just drop the DoH packets and boom, you've got unencrypted DNS again.
- jefftk 6y agoIt means you need an active attacker instead of a passive one, so it still does improve security in practice.
- corford 6y agoPretty marginal gains at the expense of eventually centralising most of the world's DNS lookups through a handful of FAANGs.
- peterwwillis 6y agoI think this is phase 1, where phase 2 or 3 is "enabled by default and don't fall back to plain DNS". So it's trivial to defeat until they change a setting. But that's not even the big problem here. The big problem is how big an impact this will be on less-than-perfect networks. The internet feels "snappy" because of DNS's speed and connectionless nature (and a buttload of DNS caching). Once it relies on a connection-oriented protocol, a lot of people's internet experience is going to start sucking badly, and they'll have to modify more of the common internet protocols to make it suck less again.
- badRNG 6y agoWhat is the impact for an organization utilizing a BYOD policy that performs DNS filtering? What about home users filtering via PiHole or pfSense or parents that use local DNS filtering? Will every device's browser need to be changed? Will Chrome revert in the presence of a network signal to use local DNS (as is the case with FF)?
- StreamBright 6y agoDNA crapware filtering was the most effective way of not having ads in every possible place on the web and also stop mass surveillance conducted by facebook and google. Now they want to know every last bit of information about you, the domains you interact with. Private mode wont work anymore.
- tptacek 6y agoYour local DNS filtering device can simply speak DoH; Pi-holes already do. That's a non-problem.
- Areading314 6y agoI can see this leading to frustrating issues where your browser works fine but every other native app on your system can't resolve hostnames because your regular DNS isn't working. Would be nice to have all hostname resolution dealt with at the OS level rather than special-cased within the browser. Is that something that modern OS's are planning to support?
- ComputerGuru 6y agoWindows 10 May 2020 update brings DoH support but chrome and Firefox are not using the Api for it to the best of my knowledge.
- bzb3 6y agoWhat do you mean "the API"? Shouldn't Windows just pass all requests to resolve domains through doh or dot? Have they really added an opt-in API instead of making it the default?
- ComputerGuru 6y agoFirefox assumes the OS does not use DoH and implements its own DoH lookup client with its own settings and its own list of servers. It's a huge mess.
- londons_explore 6y agoJust like it does for the certificate store.... And not using proper UI toolkits...
- WhitneyLand 6y agoSo why is this better when people could still take the raw IP addresses and do reverse look ups? If I recall looking into the spec before there is a reason it’s an improvement but I can’t recall what it was. I know there are tons of servers behind proxies and so forth but still it seems like over time databases could be built up to give some decent success with this countermeasure.
- vbezhenar 6y agorocketspark.com -> 104.22.34.138 104.22.34.138 is one of the cloudflare servers, it does not have reverse dns record and you can't associate it with any specific website. If you're monitoring traffic, you would have no idea what website user is visiting unless you can intercept his unencrypted DNS queries as well. So CDNs increase user security a little bit.
- mappu 6y agoIf you're monitoring traffic you can see the SNI header in plaintext. ESNI is not deployed yet (and is only as secure as DNS; that is maybe why browsers are implementing DoH themselves instead of waiting for the OS).
- an_opabinia 6y agoFor narrow cases like Cloudflare load balancing traffic, it would be difficult to reverse lookup without other compromises. It always depends on who your adversary is. Chrome is a controlled, auto-updating application. Your Cloudflare traffic is going to a central authority, Cloudflare. They could decide to sell traffic information. Or the government where Google or Cloudflare main line employees eat and sleep could ask or order those working stiffs to do something secretly in spite of company policy or promises. This does protect against a very narrow adversary, which is your ISP or router manufacturer monetizing your aggregated traffic statistics. It remains to be seen if there was ever harm there to the user in the first place. The government, as an adversary, generally wants to put you in jail. Google working stiffs generally don't want to go to jail, so they'll comply with requests; or Google will want the government's business and just do the thing they ask for. Google already gives you the thing for free. Your ISP and router manufacturer just want to offer you lower prices. Corporate and closed source or remotely managed software promises are just that.
- StreamBright 6y agoBye bye DNS based ad blocking, hello malwares straight out of Google ads.
- donmcronald 6y agoYeah. I'm sure that's the eventual goal for regular end users. We'll all be fast-ring beta testers with unblock-able ads. On the enterprise side it's probably a play to shift the market away from on-premise DNS based filtering and logging devices to SaaS based DoH filtering services. Tacit collusion will ensure no one builds a perpetually licensed device that does DoH and filtering.
- mceachen 6y agoYou can run a pihole that delegates to a local cloudflared service.
- TrueDuality 6y agoI don't see any mentions of it, so I'm assuming Google isn't using a canary domain to see if they should enable DoH or not. Can anyone else confirm?
- LeoPanthera 6y agoSo both Firefox and now Chrome will ignore DNS-level malware blockers, such as Pi-Hole. Malware/Adware will inevitably start using the same tricks, if they haven't already. And of course DoH is impossible to block without also blocking all of HTTPS. That's the point of it. A case study in unintended consequences.
- middleclick 6y agoYou can turn it off?
- corford 6y agoFor how long?
- LeoPanthera 6y agoIn these two examples, yes. In more malicious future software? Certainly not.
- yegle 6y agoRun your own DoH/DoT server that forward to PiHole? It works well and with the added benefit of bring PiHole with you (on Android P and above, via DoT) http://github.com/yegle/your-dns http://github.com/yegle/your-dns
- skybrian 6y agoI'm not a Pi-Hole user but it looks like they already support this protocol? https://docs.pi-hole.net/guides/dns-over-https/ https://docs.pi-hole.net/guides/dns-over-https/
- goatsi 6y agoThat's for making upstream DNS over HTTPS requests, not how they serve clients on the local network.
- goatsi 6y agoAs of Pi-Hole release 4.4 it will automatically disable DoH for all Firefox browsers it serves by sinkholing the canary domain [0]. For Chrome it appears that they are just upgrading to DoH for the existing DNS servers if it is possible. Since a local Pi-Hole server wouldn't be in their possible upgrade list it would be left untouched. [0] https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
- garganzol 6y agoThe relation between DNS and internet is the same as between a boot protocol and computer. By taking a control over DNS, Google usurps the power and makes the open web a walled corporate franchise of its own. In other words, Google steals the open web from the world. It injects a proprietary Trojan horse in disguise of security and established a total dictating power, deciding on what can be published on the web and what cannot. The choice of timing speaks by itself as well. A pandemic is a great mud water to pull the trick like that. Didn't you get enough stories about unwarranted pullouts of apps from Google Store? Website pullouts are the subject of the nearest future if we allow that to happen. The community should boycott centralized DNS-over-HTTPS (DoH) approach as it clearly stays in the way of Open Internet was originally designed. DoH leads to a totally centralized, usurped, greed-driven future controlled by a single corporate entity. This should also bring the closest attention of anti-monopoly committees around the world. I know that not all people can grasp the danger DoH brings today, but this is a very dangerous development that may lead to disastrous consequences for communities around the world. Internet as we know it may just die.
- techntoke 6y agoGoogle isn't taking control of DNS. That will still be up to the user, and like Firefox, I expect it to be configurable too. Mozilla already implemented and is using DNS-over-HTTPS. That is why I find the Google hate to be semi-manufactured. Cases like this, it makes no sense to argue against something like this. Even if I was running my own DNS server, I would still want to use DNS-over-HTTPS in my own setup. I'm all for decentralizing DNS and the web as a whole, but does that mean that I am going to advocate against better centralized security because of it? Absolutely not, especially when a majority of users don't have access to decentralized DNS today.
- bzb3 6y agoThis is literally what Firefox did and it was widely applauded.
- garganzol 6y agoAnother thing that Firefox (Mozilla) does is absorbing millions of bucks from Google on yearly basis. Oh well, that's not a cartel. Mind you.
- kamyarg 6y agoHad a discussion just today with some colleagues because of internal company network(VPN) hijacking every port 53 request and responding in 2s(!). I sure do hope this becomes a visible and flexible feature and not a google-only-dnses or "Oh, you have to run it with this special flag --use-dns-over-tls) kind of feature. I think DNS topic has been underrepresented in the privacy-aware community. Hope this changes both for OSes and also apps people use regularly.
- corford 6y agoWhat irritates me about DoH is it's lazy. I get the impression Google, Mozilla etc. are genuinely irritated with crappy networks and invasive ISPs meddling with DNS traffic. What I don't accept is their decision to abuse their market positions to impose a quick, unilateral solution that comes with a range of unfortunate long term implications and secondary effects vis a vis centralization. Imho, it would have been much, much better if they had used their resources and clout to help fund & advocate for a general, independent transition over to DoT for last mile and increased adoption of DNSSEC and DNSCurve upstream. The world manged to move to encrypted email and www. Surely it could move to encrypted DNS without browser vendors forcing us to split name resolution and send half of it over HTTP?
- comex 6y agoThe problem isn't just ISPs meddling with DNS traffic, but ISPs passively collecting DNS traffic and using it to track users, something which is believed to have happened in the US on at least one occasion. [1] DoT to your ISP doesn't help if you don't trust your ISP. There is also the risk of collection by intelligence agencies. [1] https://gigaom.com/2014/05/13/atts-gigapower-plans-turn-privacy-into-a-luxury-that-few-would-choose/ https://gigaom.com/2014/05/13/atts-gigapower-plans-turn-priv...
- corford 6y agoIf you don't trust your ISP, you are savvy enough to use a). a different resolver or b). a VPN. In both cases, the decision is opt-in (which is what it should be). Edit: or option c). apply pressure to your government representatives to update their privacy laws so ISP snooping doesn't happen in the first place. It's a sad state of affairs when the ISP market has failed so badly that you can't find an ISP you can trust.
- comex 6y ago> If you don't trust your ISP, you are savvy enough to use a). a different resolver or b). a VPN. In both cases, the decision is opt-in (which is what it should be). So you think that non-savvy users don't deserve privacy? > Edit: or option c). apply pressure to your government representatives to update their privacy laws so ISP snooping doesn't happen in the first place. That's definitely desirable. Heck, the snooping in question might already be illegal in California under the new CCPA. But I don't see federal legislation happening anytime soon, and the US is not the only jurisdiction lacking privacy protections. And while privacy laws can prevent snooping for advertising purposes, good luck convincing the government to outlaw snooping by intelligence agencies. Ultimately, legal and technical measures are not mutually exclusive, and we should use both.