12 ms·
NSA Recommends How Enterprises Can Securely Adopt Encrypted DNS
- nimbius 6y ago>NSA recommends that an enterprise network’s DNS traffic, encrypted or not, be sent only to the designated enterprise DNS resolver. its either a slow day at the NSA or federal agencies have become so intellectually bankrupted by the cloud that they consider proclamations of the fundamentals of DNS and networking to be some sort of sage wisdom.
- freeone3000 6y agoSomebody has to recommend the basic stuff, otherwise it's just rumor. This is a topical addition to a list of DNS recommendations.
- TedDoesntTalk 6y agoNow you can point to that and say “We use the best DNS practices as recommended by the NSA.”
- belorn 6y agoI read that to mean: Do not allow doh to tunnel all your dns traffic out to cloudflare regardless of the promise of encryption. Send it only to the designated enterprise DNS resolver, ie the one under control by the enterprise. All other DNS resolvers should be disabled and blocked, ie all those public dns resolvers.
- salawat 6y agoIn other words "MitM everything". It gets so tiresome. I used to think the people who called out tyranny everywhere were just nuts, but it never ceases to amaze that everything nowadays keeps going "centralize and control".
- wmf 6y agoSending your DNS queries to a resolver that you control is hardly MITM. In this case "you" is a company.
- StreamBright 6y agoWhat he means is that NSA and related has the ability to MITM HTTPS while another actors do not, probably.
- userbinator 6y ago...and in the case of people using DNS-based adblocking and such, "you" is... yourself.
- vaduz 6y ago> Sending your DNS queries to a resolver that you control is hardly MITM. That's if your users are well-behaved and follow the rules. To stop the users from being badly behaved, NSA recommends blocking connectivity to well-known IP addresses of the public DoH resolvers (e.g. Cloudflare) and TLS inspection to stop connections that try to go to less well known ones, including via ODoH, which means your TLS inspection device must understand the protocol. To do TLS inspection at that level you need to MitM all HTTPS traffic going everywhere, as you need to read all HTTPS traffic to any possible host, as any of them may be a DoH resolver or relay. Q.E.D.
- deathgrips 6y agoYou seem to be implying that a company should not know what kind of web requests are coming from its computers.
- vaduz 6y ago> You seem to be implying that a company should not know what kind of web requests are coming from its computers. Please point out where I made that claim. All I am saying is that the way "knowing what kind of web requests" - and DNS request in this case - is achieved is by becoming a third party in supposedly two party encrypted communication. The company certainly has the authority to do so (check your local laws, though, as there are some exceptions) - but it is MitM in function and practice, if not in name. "TLS inspection" and "data loss prevention" are simply common euphemisms for the technique. It's also not new, MitM proxies and for that matter endpoint introspection (e.g. keyloggers at the user machine) have been in use for decades in the enterprise, and have been making their way into BYOD private machines as well via various MDM tooling. Using your company DNS server as the grandparent has mentioned is not MitM. Inspecting all traffic by all devices in your company to try to enforce the use of said DNS server requires MitM, though.
- blondin 6y agounless i am reading this wrong, they are not saying don't send your requests to Cloudfare, Apple, etc. i am not entirely privy to all this, but aren't they entreprise grade DNS resolvers?
- Spooky23 6y agoThey are high quality services, not controlled by the company. It’s pretty obvious that allowing unloggable DNS traffic in an enterprise is a bad idea. It makes ex filtration trivial.
- salawat 6y agoExfiltration already is trivial DNS or not. Just admit that you want to be able to eavesdrop on all activity whatsoever. What, you think that anyone looking to get something out undetected isn't using raw IP's?
- Spooky23 6y agoOn my network? Absolutely, ability to inspect packets is absolutely essential. On a public network? Different story. I’ve personally been engaged in incident response and in many scenarios DNS is a control mechanism for malware, or uses it for various purposes. It’s often a key piece of evidence for reconstruction of an incident. Raw IPs can be used as well, but that doesn’t negate my point.
- 0xquad 6y ago>Raw IPs can be used as well, but that doesn’t negate my point. And in fact if you have enterprise-wide visibility on DNS requests, you have the opportunity to detect the use of an IP that was not returned in a request. Making it immediately suspect.
- jorblumesea 6y agoSecurity recommendations aren't supposed to be brilliant insights. They're just best practices.
- 737min 6y agoExactly right. Many security problems are due to forgoing the simple things in favor of exotic.
- rasengan 6y agoSpecifically, they are saying that in a home/personal environment, it makes sense to use DoH with a public resolver like cloudflare, but in enterprise, you will not be able to maintain tight control over internal use as browsers role out with DoH by default unless you block those public resolvers and enforce policy to use the enterprise resolver. It doesn't matter unless you care about these tight controls though even in enterprise.
- StreamBright 6y agoIt is going to be super hard to block DoH since it is indistinguishable from normal HTTPS traffic. If you MITM the HTTPS connection the browser can detect that and refuse to use the connection. Many companies are in this situation that MITMing HTTPS is not working very well. I think Google enforces HSTS[1]. Not sure how that works with DOH. I also think that we need browsers that do not have any other means of DNS resolution than the good old operating system wide /etc/resolv.conf (or similar). I am not going to fight with Google if I have the right to have my own DNS server or not. They are taking the open internet inch by inch. This is the last drop. 1. https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
- rasengan 6y agoThat's a good point -- I wasn't really thinking about the practicability since it's not something I had much interest in. That said, I guess either blackholing the DNS so it can't initially be resolved, or even figuring out any and all IP addresses it resolves to and blackholing those IPs would be a start. I agree, however, that it should be possible to run your own _______. That's what the internet was meant to be.
- XorNot 6y agoAt an enterprise level the browser configuration is controlled by the IT department. Your MITM CA certificate is going to be forced into the trusted list everywhere.
- 6y ago
- 0xquad 6y agoThey are responding to the very recent emergence of applications (like Firefox) that (optionally) use their own encrypted DNS, thus bypassing the enterprise's ability to apply security policy based on DNS. (Visibility on DNS is also useful to help detect some malware.) I'll allow it.
- vaduz 6y agoIt's clearly also spurred by the attempts to further obfuscate the use of DoH via Oblivious DoH [0] - though they don't go into much details on it. [0] https://news.ycombinator.com/item?id=25344358 https://news.ycombinator.com/item?id=25344358
- Daho0n 6y ago>thus bypassing the enterprise's ability I think you could change it to read " bypassing the NSA's ability" and find the real reason behind this.
- 0xquad 6y agoThey aren't recommending you don't use DoH. Just that you don't allow individual apps to bypass your enterprise resolver. In fact I use the same strategy at home (with DoT) to enforce ad and tracker blocking. It's just common sense really. From the document: >[...] NSA recommends that the enterprise DNS resolver supports encrypted DNS, such as DoH, and that only that resolver be used in order to have the best DNS protections and visibility.
- aftbit 6y agoI wonder when smart TV manufacturers will begin using DNS-over-HTTPS to make it harder for PiHole et al to block their ads.
- jccooper 6y agoI kinda doubt they're concerned about the tiny percentage of users who would do such a thing.
- novok 6y agoAnd that's when you start adopting reverse dns + mac address filtering
- morpheuskafka 6y agoI wonder why they haven't done this along time ago. They don't even need a full DoH endpoint, just an auto-updating hosts file downloaded from a non-blockable domain (one used for other TV features) would do it.
- tptacek 6y agoThere's no reason any of these products need to use on-prem DNS of any sort, except maybe for the DNS lookup to the central server that they require to operate at all. I know a lot of people base DoH concerns on the idea that it allows their set-top box to evade their local DNS policy, but that's not a coherent argument; these boxes can tunnel all their traffic out, if they want to (you can block that, but it's all-or-none, which is the thing the DNS boffins claim they can work around).
- edgan 6y agoI already use an Nvidia Shield instead of my smart TV, even though both are Android TV. It is such a better experience. If any device started taking over it's DNS in a way I couldn't override, and I had reason to care, I would stop using it. PiHole is already a meh solution. My two primary apps on my Shield are SmartTubeTV and Kodi. I won't pay for YouTube when they force bundle it with other services I don't want. The alternative of ads has gotten to ridiculous levels, and then the ads in the video from them on top. SponsorBlock is another game changer. Sadly it isn't in an AndroidTV app yet. On my phone it is Vanced all the way for YouTube, and it does have SponsorBlock.
- Randor 6y agoI don't understand why people can't see the dangers of moving everything to DoH. For example if you have a 3000 user network and 2900 of them are using a local resolver. You have almost no chance of finding those 100 nodes doing DoH without MITM everything over 443. Someone will probably respond with something like: "Just block the IP address ranges of public DoH resolvers" and that would work for the resolvers we know about.
- userbinator 6y agoI don't understand why people can't see the dangers of moving everything to DoH Because "more security" is hard to argue against. The huge corporations who ultimately want to take control of the population have realised that, and are using that excuse to get in bit by bit.
- creata 6y agoHow will DoH help "huge corporations... take control of the population"?
- userbinator 6y agoFirst they take the DNS queries. Then they start routing the rest of the traffic through their servers, while advertising how it's all "for your privacy and security", of course. There's another article on the front page about how these companies already wield immense power: https://news.ycombinator.com/item?id=25802366 https://news.ycombinator.com/item?id=25802366 To be clear, I'm not against the principles behind DoH, and think traffic going from the local network into the Internet benefits from encryption; I'm against how it's being implemented at the application-level and its subversive nature.
- creata 6y agoThat's fair enough, but in the short term, Cloudflare is more trustworthy (and tolerant of free speech!) than my ISP and government. Is there an initiative in which I have to trust none of these parties?
- dylan604 6y agoFrom under my tinfoil hat, I have to wonder why we would listen to any recommendations from the NSA? Why would we not believe they are going to make recommendations of methods they know how to exploit? Taking off my tinfoil hat, I understand that one of the purposes of the NSA is to keep US information safe. Following their recommendations should make your data safer. However, Snowden showed us that the NSA doesn't always follow the rules it is supposed to operate within. Does that mean they are always be suspect? How do we decide when their recos are for the good fo all?
- VWWHFSfQ 6y agoThe NSA has a long history [0](PDF) of providing guidance for "best practices" for securing USA corporate networks. It's part of their job. [0](PDF) https://apps.nsa.gov/iaarchive/customcf/openAttachment.cfm?FilePath=/iad/library/ia-guidance/security-configuration/operating-systems/assets/public/upload/Guide-to-the-Secure-Configuration-of-Red-Hat-Enterprise-Linux-5.pdf&WpKes=aF6woL7fQp3dJinJ4QbpaBwMLGCPwaJSSChDqa https://apps.nsa.gov/iaarchive/customcf/openAttachment.cfm?F...
- dylan604 6y agoYes, I stipulated that in my post. However, we have seen how the NSA wants data from US corporations. If they make a "recommendation" for corps to use, then how do we know it is solely for the corporation's best interests rather than the NSA's own interests in more easily accessing the corp's data while providing false sense of security? We do know that the NSA pushed for a particular type of RSA encryption to become the default because they already knew how to break the encryption. Once something like that is known in the wild, credibility will from then on be suspect at best as to true motive.
- 29083011397778 6y agoI feel it wouldn't be completely unjustified to trust NSA recommendations simply because America isn't the only country in the world with intelligence agencies. The NSA is commonly assumed to be offensive, but part of their job is to aid in defence as well. Ensuring (malicious) foreign actors have trouble gaining information is a National interest just as much as the NSA themselves gaining access.
- jcpham2 6y agoNice try NSA
- asdfthrowawayyy 6y agoBunch of garbage, NSA and FBI hate ESNI. Firefox silently pulled all production ESNI code as of v83 without a word of warning to anyone. As in, the Firefox development team simply killed encrypted SNI and told nobody that may have been using ESNI in despot regimes, in exchange for future ECH support which is not implemented anywhere yet. Nor will ECH be endpoint supported any time soon.
- collsni 6y agoThey are just saying within enterprises it is of the enterprises best interest to control all aspects of dns so all traffic can be monitored. Which you seriously need to do if you aren't doing it already. Dns needs to be monitored holistically it is a great place to catch IOCs.
- deathgrips 6y agoI think I found the one Hacker News in this thread that actually works in security ops.
- room505 6y agohttps://www.lawfareblog.com/explaining-sigint-annex https://www.lawfareblog.com/explaining-sigint-annex
- permille42 6y agoCould someone create a replacement for DNS entirely please? DNS does WAY more than what the typical user needs it for and services that present it are resultantly much more complex than what is needed for the 99% use case. The 99% use case: resolve x.y.z to some IP address. What I think should happen: 1. At each level, a public/private keypair is used to authenticate valid records for the name. Eg: .com has public/private keypair(s) to represent who can sign x.com records. .com owner only needs to publish these. Reliable sources ( ISPs etc ) can then share these. 2. The x.com records themselves would be: Mapping from x.com to IP address(s) / public key. 3. The x.com owners could then publish out their x.y.com records freely and they could be mirrored by everyone. Unlike the current methodology, there would be far less need to trust where you get the records from. The public/private keypairs should change WAY less frequently. Agreeably in such a widely distributed system you wouldn't have nice TTL, but that is for the better. DNS records should not be changing that frequently. Such a new system also should be done in a fully distributed way and NOT controlled by a bunch of money grubbing bastards who make way too much money from records. It should NOT cost $20/yr to own a record pointing x.y to a number. It's absurd and really needs to stop.
- permille42 6y agoMy bad for having an idea on how to modernize. Assholes.
- userbinator 6y agoDid you just reinvent DNSSEC...?
- permille42 6y agoNo. My point isn't to use security on top of existing DNS records. My point is to make a brand new distributed system entirely that is free for all instead of run by a bunch of greedy internet thugs.
- ENOTTY 6y agoThere's good money to be made selling a solution that detects and blocks rogue DoH requests. Anyways, it's possible: https://dl.acm.org/doi/abs/10.1145/3407023.3409192 https://dl.acm.org/doi/abs/10.1145/3407023.3409192
- egberts1 6y ago^^^THIS^^^ Especially given that malicious JavaScript can now make DoH toward their distributed command and control centers.
- nuker 6y agoWhy they advised DoH and not DoT? DoT is simpler, no http cookies ambiguity. Easier to block counter argument does not really apply to businesses...
- vaduz 6y agoFor non-malicious apps, generally speaking DoT is something you need to specifically enable, whereas certain major applications are working towards using DoH by default (or they already do [0]). DoH is also mixed with regular HTTPS traffic, so it is much harder to detect and act upon - so businesses need to spend more effort to counter it. As a bonus, most of the mitigations in use here also apply to DoT, so you are also getting it in the bargain... [0] https://blog.mozilla.org/blog/2020/02/25/firefox-continues-push-to-bring-dns-over-https-by-default-for-us-users/ https://blog.mozilla.org/blog/2020/02/25/firefox-continues-p...
- 1vuio0pswjnm7 6y agoThere has certainly been evidence of censorship amongst the thousands of third party open resolvers. Are there any examples of known "malicious" third party DoH or DoT resolvers. Has anyone been studying this.