Jump to content

Recommended Posts

Posted
Google have been doing this for many years by using 'QUIC' protocol. Many web filters etc wont inspect some web traffic when this is turned on. We had issues earlier this year meaning a user could access a certain website through our filtering. After further investigation, we turned off this setting and we could see the logs going through and being blocked. Hope this helps

I recommend ensuring that your firewall is set to block UDP ports 80 and 443, which are used by QUIC (as opposed to the TCP ports 80 and 443 which are HTTP/HTTPS). Browsers will fall back to HTTP and HTTPS if QUIC is blocked.

 

Unfortunately there are a few things, such as WeChat, which also use UDP port 80, and you need a firewall that will do deep packet inspection if you want to allow things like WeChat whilst also blocking QUIC.

  • 1 month later...
Posted

Internet imbeciles, aka British ISP lobbyists, backtrack on dubbing Mozilla a villain for DNS-over-HTTPS support

 

The brain-dead Internet Service Providers Association (ISPA) has backtracked on its nomination of Mozilla as an "internet villain" for 2019 after online outcry.

 

"In the 21 years the event has been running it is probably fair to say that no other nomination has generated such strong opinion," the bonkers UK-based lobbying organization said in a post on Tuesday announcing the decision to un-villainize the open-source outfit.

 

"The villain category is intended to draw attention to an important issue in a light-hearted manner," explained the hapless fools, "but this year has clearly sent the wrong message, one that doesn’t reflect ISPA's genuine desire to engage in a constructive dialogue. ISPA is therefore withdrawing the Mozilla nomination and Internet Villain category this year."

 

The association's staff of disappointment magnets (ha, just kidding, ISPA, just some light-hearted fun) decided that Mozilla's decision to improve the general security of the internet by adopting the DNS-over-HTTPS (DoH) standard was worthy of scorn – albeit that good ol' light-hearted scorn – and used their "Internet Heroes and Villains" annual awards to highlight their wrongheaded opposition to the idea.

 

DoH works by running DNS lookups – which turn, say, human-friendly domain names like theregister.co.uk into IP addresses your browser can use to reach our web servers – over encrypted HTTPS connections to DNS servers provided by the likes of Cloudflare and Google, bypassing ISPs.

 

By channeling these translations over secure connections, the lookups appear indecipherable to networks they pass through, such as your broadband provider's. These networks will therefore potentially struggle to monitor which sites you're surfing to, when using DNS-over-HTTPS, due to the encryption.

  • 1 month later...
Posted

New blog post from Mozilla.

 

What’s next in making Encrypted DNS-over-HTTPS the Default

 

In 2017, Mozilla began working on the DNS-over-HTTPS (DoH) protocol, and since June 2018 we’ve been running experiments in Firefox to ensure the performance and user experience are great. We’ve also been surprised and excited by the more than 70,000 users who have already chosen on their own to explicitly enable DoH in Firefox Release edition. We are close to releasing DoH in the USA, and we have a few updates to share.

 

After many experiments, we’ve demonstrated that we have a reliable service whose performance is good, that we can detect and mitigate key deployment problems, and that most of our users will benefit from the greater protections of encrypted DNS traffic. We feel confident that enabling DoH by default is the right next step. When DoH is enabled, users will be notified and given the opportunity to opt out.

 

This post includes results of our latest experiment, configuration recommendations for systems administrators and parental controls providers, and our plans for enabling DoH for some users in the USA.

  • 3 weeks later...
Posted

Firefox: 'no UK plans' to make encrypted browser tool its default

 

The maker of the Firefox web browser has told the government it has no plans to turn a controversial web privacy tool on by default in the UK, despite launching it in the US later in September.

 

Mozilla has announced it will make the tool, called DNS-over-HTTPS, or DoH, the default for all users in the US.

 

The decision has prompted concern in the UK, since the technology breaks many of the centralised filtering and blocking systems in place to prevent easy access to child abuse images, piracy and terrorist material, as well as optional parental controls.

 

In a letter sent to Nicky Morgan, the culture secretary, seen by the Guardian, Mozilla’s vice-president of global policy, trust and security, Alan Davidson, said the non-profit organisation “has no plans to turn on our DoH feature by default in the United Kingdom and will not do so without further engagement with public and private stakeholders”.

 

DNS-over-HTTPS is a significant rewrite to one of the basic layers of the internet, the domain name system, which computers use to turn a readable web address, such as theguardian.com, into an IP address that tells the computer which specific server to connect with. Typically, that search is carried out in an unencrypted fashion, which can allow attackers to hijack requests. By adding encryption, DoH adds extra security to the browsing process.

 

Davidson added in his letter to Morgan: “We do strongly believe that DoH would offer real security benefits to UK citizens. The DNS is one of the oldest parts of the internet’s architecture, and remains largely untouched by efforts to make the web more secure.

 

“Because current DNS requests are unencrypted, the road that connects your citizens to their online destination is still open and used by bad actors looking to violate user privacy, attack communications, and spy on browsing activity. People’s most personal information, such as their health-related data, can be tracked, collected, leaked and used against people’s best interest. Your citizens deserve to be protected from that threat.”

 

One side-effect of DoH is that it also bypasses UK web filters, which use the same technique, hijacking DNS lookups, to prevent easy access to websites blocked by internet service providers.

 

The Internet Watch Foundation, which provides ISPs with a list of websites that host child abuse imagery, for filtering purposes, expressed its concern over the technology for that reason. “We feel that the way in which DNS-over-HTTPS is proposed to be implemented could expose millions of people across the world to the worst imagery of children being sexually abused and could mean that the victims of such abuse could be exposed to countless sets of eyes,” a spokesperson told the tech site the Register.

 

The trade body for British ISPs even nominated Mozilla as one of its “internet villains of the year” in July over the issue. The ISPA cited as its reason “their proposed approach to introduce DNS-over-HTTPS in such a way as to bypass UK filtering obligations and parental controls, undermining internet safety standards in the UK”.

 

A month later, the body withdrew the nomination and cancelled the “award” entirely, saying it “clearly sent the wrong message”.

 

Google has also announced plans to test DoH in its Chrome web browser, starting in October. The company will not turn on DoH for every user, but says it will default to DoH for those relatively technical users who have already chosen to switch their DNS provider to companies such as Google, Cloudflare and OpenDNS.

Posted

Experimenting with same-provider DNS-over-HTTPS upgrade

 

As part of our long standing commitment to making the web safer to use, we will be conducting an experiment to validate our implementation of DNS-over-HTTPS (aka DoH) in Chrome 78. As the name implies, the idea is to bring the key security and privacy benefits of HTTPS to DNS, which is how your browser is able to determine which server is hosting a given website. For example, when connected on a public WiFi, DoH would prevent other WiFi users from seeing which websites you visit, as well as prevent potential spoofing or pharming attacks. This experiment will be done in collaboration with DNS providers who already support DoH, with the goal of improving our mutual users’ security and privacy by upgrading them to the DoH version of their current DNS service. With our approach, the DNS service used will not change, only the protocol will. As a result, existing content controls of your current DNS provider, including any existing protections for children, will remain active.

 

More concretely, the experiment in Chrome 78 will check if the user’s current DNS provider is among a list of DoH-compatible providers, and upgrade to the equivalent DoH service from the same provider. If the DNS provider isn’t in the list, Chrome will continue to operate as it does today. The providers included in the list were selected for their strong stance on privacy and security, as well as the readiness of their DoH services, and also agreed to participate in the experiment. The goals of this experiment are to validate our implementation and to evaluate the performance impact.

 

Our experiment will run on all supported platforms (with the exception of Linux and iOS) for a fraction of Chrome users. On Android 9 and above, if the user has specified a DNS-over-TLS provider in the private DNS settings, Chrome may use the associated DoH provider, and will fallback to the system private DNS upon error.

By keeping the DNS provider as-is and only upgrading to the provider’s equivalent DoH service, the user experience would remain the same. For instance, malware protection or parental control features offered by the DNS provider will continue to work. If DoH fails, Chrome will revert to the provider’s regular DNS service. Opting-out of the experiment will be possible from Chrome 78 by disabling the flag at chrome://flags/#dns-over-https.

 

Most managed Chrome deployments are excluded from the experiment. For enterprise and education customers, we invite administrators to read the upcoming release notes for details about DoH policies which will be published on our Chrome Enterprise blog.

  • 1 month later...
Posted

Windows 10 is getting DoH support.

 

https://techcommunity.microsoft.com/t5/Networking-Blog/Windows-will-improve-user-privacy-with-DNS-over-HTTPS/ba-p/1014229

 

Here in Windows Core Networking, we’re interested in keeping your traffic as private as possible, as well as fast and reliable. While there are many ways we can and do approach user privacy on the wire, today we’d like to talk about encrypted DNS. Why? Basically, because supporting encrypted DNS queries in Windows will close one of the last remaining plain-text domain name transmissions in common web traffic.

 

Providing encrypted DNS support without breaking existing Windows device admin configuration won't be easy. However, at Microsoft we believe that "we have to treat privacy as a human right. We have to have end-to-end cybersecurity built into technology."

 

We also believe Windows adoption of encrypted DNS will help make the overall Internet ecosystem healthier. There is an assumption by many that DNS encryption requires DNS centralization. This is only true if encrypted DNS adoption isn’t universal. To keep the DNS decentralized, it will be important for client operating systems (such as Windows) and Internet service providers alike to widely adopt encrypted DNS.

  • 5 months later...
Posted
Windows 10 is getting DoH support.

It now has it! :)

 

Windows Insiders can now test DNS over HTTPS

 

If you have been waiting to try DNS over HTTPS (DoH) on Windows 10, you're in luck: the first testable version is now available to Windows Insiders! If you haven’t been waiting for it, and are wondering what DoH is all about, then be aware this feature will change how your device connects to the Internet and is in an early testing stage so only proceed if you’re sure you’re ready. Having said that, if you want to see the Windows DoH client in action and help us create a more private Internet experience for our customers, here is what you need to do:

 

First, make sure your Microsoft account is part of the Windows Insider Program. If you know you are already a Windows Insider, make sure you are in the Fast ring and go to Step 2. If not, go here and follow the instructions for the Fast ring so you can get the latest Insider Preview build.

 

Once this is done, run Windows Update, reboot, and verify you’re running Build 19628 or higher. You can do this by clicking here or by going to the Settings app -> System -> About.

 

Once you know your Windows install has our DoH client, we need to activate it. You can do that by:

 

  1. Opening the Registry Editor
     
     
  2. Navigate to the registry key:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters


     
     

  3. Create a new DWORD value named “EnableAutoDoh”
     
     
  4. Set its value to 2

Posted

Have Microsoft updated their DNS server to support DoH? Or is this just for public DNS traffic?

 

I've been playing around with a DNS - DoH proxy so I can can carry on using standard DNS on my internal network and DoH for anything external. Working pretty well so far!

Posted
I am not a dev so not sure about specifics - what Arthur states seem right to me :) Android obviously won't be affected by this client obviously. Android does not seem to have a lot of use on School devices so it's not on the priority list at the moment. I don't think an iOS client is expected either as iPads are being phased out in most US Schools it seems.

Yeah right...NYC just rolled out 300,000 iPads to schools.

 

Both Securly and Lightspeed Relay have clients that can do HTTPS inspection for iOS in Safari and there is Chrome for iOS?

Posted
Just a note. The clients actually don't do HTTPS inspection as they read what comes out of the browser before it gets displayed. HTTPS inspection is needed when traffic is being intercepted between the browser and the internet. Result is the same, that the filter can see the HTTPS content as it's not HTTPS when the filter looks at it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...