5 ms·
How well does the redirect scheme work for a device that connects to a central DNS server listening on, say, port 5353 instead? What about 80 or 443?
by chipb 6y ago
How well does the redirect scheme work for a device that connects to a central DNS server listening on, say, port 5353 instead? What about 80 or 443?
- vageli 6y ago> How well does the redirect scheme work for a device that connects to a central DNS server listening on, say, port 5353 instead? How about 80 or 443? Just because it is not a silver bullet doesn't mean it is not effective for a large percentage of users.
- fiddlerwoaroof 6y agoWell, it’s more complicated, but in theory you could do some deep packet inspection that understands the protocols: personally, I’d use this to break DoH connections (for every host name seen in SNI, attempt a DoH query, if it resolves, reset the connection) and attempt to force everything to fall back to plain DNS. Then, whitelist a couple outbound ports (on most networks, maybe just 443 + 53?) and block VPNs.
- judge2020 6y ago> or every host name seen in SNI Not going to be possible in a few years or so: https://news.ycombinator.com/item?id=25344311 https://news.ycombinator.com/item?id=25344311
- dhaavi 6y agomeh. The outer SNI and the IP address still tell a lot about what you are doing online.
- fiddlerwoaroof 6y agoAlso, with things like this, you can just reset connections using HTTPS features you don’t support. It might eventually become painful, but it’ll be fine for the near future. And, if enough enterprise middleboxes do this, the standards will be DOA.
- dhaavi 6y agoWith the Portmaster (https://github.com/safing/portmaster https://github.com/safing/portmaster) we're going in that direction, but it will take a couple more years to be able to go that deep. Have a look!
- jlgaddis 6y agohttps://en.wikipedia.org/wiki/Perfect_is_the_enemy_of_good https://en.wikipedia.org/wiki/Perfect_is_the_enemy_of_good