27 ms·
Cloudflare and Apple made a new DNS protocol to protect your data from ISPs
- pbronez 6y agoI wonder if this protocol could provide any relief to network admins trying to protect themselves from aggressive Smart TVs and other IoT devices that use DNS over HTTPS to avoid local DNS blocks. I suspect not, since anything designed to protect against ISP snooping should be available to device manufacturers to protect against local admin snooping.
- skissane 6y agoI guess the only solution is to run your own MITM TLS proxy, and hope that the Smart TV or IoT device lets you install your own root certificate. (Which it quite possibly won't without jailbreaking... and even if it does, it probably isn't documented how to do it)
- unixhero 6y agoThis needs a fix
- michaelmior 6y agoWhy is protection necessary from these devices?
- p00f 6y agoYou can't use a PiHole, for example
- jsjohnst 6y agoDepends on your firewall, but yes you can (assuming your goal is to block those queries)
- eddyg 6y agoWhich firewalls let you block DNS over HTTPS? (Without resorting to blocking random IP addresses from some list that constantly needs updating.)
- jsjohnst 6y agopfSense - it only blocks known DNS over HTTPS servers, but generally all “smart” devices that use it use the publicly available servers. I log and periodically check TCP flow metadata, so I could identify new ones later.
- stephenr 6y agoSeems like a pretty simple solution. Don’t connect the tv to the internet.
- okanesen 6y agoRelated: https://news.ycombinator.com/item?id=25344358 https://news.ycombinator.com/item?id=25344358
- afrcnc 6y agoneeds to be reposted and made a dupe 39 more times, brb
- feroz 6y agoIf you would like to try out an independent ODoH proxy with Cloudflare DNS, I added ODoH proxying to my DoH server last night - instructions on using it are here: https://padlock.argh.in/2020/12/08/odoh.html https://padlock.argh.in/2020/12/08/odoh.html
- INTPenis 6y agoI think this link is relevant to people who want other encrypted DNS alternatives from the big corporate ones. https://www.privacytools.io/providers/dns/ https://www.privacytools.io/providers/dns/
- alexpc201 6y agoBy now I don’t understand why DNS is not a browser functionality. Or an operating system service.
- olliej 6y agoSomeone has to run the DNS servers the browsers talk to - DNS data is big and can change rapidly, especially in the cloudflare and AWS type of cases
- egberts1 6y agoI’m sticking with DNS over dual server/client certificate. My home LAN gateway is blocking DoH because the hassle of issuing enterprise-based intermediate CA is not worth the effort to do a Squid TLS transparent proxy so that one can “Pi-hole” to block stray DNS/domains. This means my own set of authoritative DNS servers.
- nora-puchreiner 6y agoSince 1.1.1.1 introduction, Cloudflare is able to perform HTTPS man-in-the middle attacks even for the websites which do not use Cloudflare CDN: they could forge DNS answer and proxy HTTPS traffic of any website via their CDN, instantaneously issuing a valid HTTPS certificate, as they have root certs and could issue certs for any domain. Since ODoH they could perform such attacks without being spotted by ISPs. Nice.
- crtasm 6y agoNew certs have to be sent to Certificate Transparency logs, any company mis-issuing them would be taking a colossal risk.
- nora-puchreiner 6y agoA MITM-attack which starts from DNS could be narrow targeted, forged DNS responses could be sent to a single person or an organization. Certificate Transparency monitors are futile here. Also, if the reputation risks is the only thing which could prevent them from doing so... it is not the security we expect from the cryptographic protocols. A subpoena/warrant could be a more "colossal" threat to their business.
- crtasm 6y agoIf the user is running Chrome the cert will not be trusted if it's not been sent to public CT logs. I'll give you that - based on a brief search - this does not appear to apply to other browsers yet. They risk losing their status as a trusted CA.
- nora-puchreiner 6y ago> They risk losing their status as a trusted CA. There are tons of goals more important than the trusted status. Killing Osama, arresting Silk Road, performing or exposure of election fraud, ... Losing of the status might happen sometimes later while the traffic interception/modification is what they can do right now. And it could be ordered by someone who do not care on those statuses at all.