DNS over TLS

DNS over TLS (DoT) is a security protocol for encrypting and wrapping Domain Name System (DNS) queries and answers via the Transport Layer Security (TLS) protocol. The goal of the method is to increase user privacy and security by preventing eavesdropping and manipulation of DNS data via man-in-the-middle attacks.

As of 2020, Cloudflare, Quad9, Google, Quadrant Information Security, CleanBrowsing, LibreOps, DNSlify[1] Telsy,[2] AdGuard and Digitalcourage are providing public DNS resolver services via DNS over TLS.[3][4][5][6][7][8] In April 2018, Google announced that Android Pie will include support for DNS over TLS,[9] allowing users to set a DNS server phone-wide on both Wi-Fi and mobile connections, an option that was historically only possible on rooted devices. DNSDist, from PowerDNS, also announced support for DNS over TLS in version 1.3.0.[10] BIND users can also provide DNS over TLS by proxying it through stunnel.[11] Unbound has supported DNS over TLS since 22 January 2018.[12][13] Unwind has supported DoT since 29 January 2019.[14][15] With Android Pie's support for DNS over TLS, some ad blockers now support using the encrypted protocol as a relatively easy way to access their services versus any of the various work-around methods typically used such as VPNs and proxy servers.[16][17][18]

Implementations

Many public recursive servers support DoT, but client systems are often required to opt in.

Android clients running Android 9 (Pie) or newer support DNS over TLS.[19]

Linux and Windows users can use DNS over TLS as a client through the NLnet Labs stubby daemon or Knot Resolver.[20] Alternatively they may install getdns-utils[21] to use DoT directly with the getdns_query tool. The unbound DNS resolver by NLnet Labs also supports DNS over TLS.[22]

Apple's iOS 14 introduced OS-level support for DNS over TLS (and DNS over HTTPS). iOS does not allow manual configuration of DoT servers, and requires the use of a third-party application to make configuration changes.[23]

systemd-resolved is a Linux-only implementation that can be configured to use DNS over TLS, by editing /etc/systemd/resolved.conf and enabling the setting DNSOverTLS.[24][25] Most major Linux distributions have systemd installed by default.[26]

personalDNSfilter[27] is an open source DNS filter with support for DoT and DoH (DNS over HTTPS) for Java enabled devices including Android.

Nebulo[28] is an Open Source DNS changer application for Android which supports both DoT and DoH.

Criticisms and implementation considerations

DoT can impede analysis and monitoring of DNS traffic for cybersecurity purposes. DoT has been used to bypass parental controls which operate at the (unencrypted) standard DNS level; Circle, a parental control router which relies on DNS queries to check domains against a blocklist, blocks DoT by default due to this.[29] However, there are DNS providers that offer filtering and parental controls along with support for both DoT and DoH.[30][31][32][33] In that scenario, DNS queries are checked against block lists once they are received by the provider rather than prior to leaving the user's router.

Encryption by itself does not protect privacy, encryption is simply a method to obfuscate the data.

DoT clients do not directly query any authoritative name servers. Instead, the client relies on the DoT server using traditional (port 53 or 853) queries to finally reach authoritative servers. Thus, DoT does not qualify as an end-to-end encrypted protocol, only hop-to-hop encrypted and only if DNS over TLS is used consistently.

See also

References

  1. "Public DNS resolver | DNSlify - DNSlify | Anycast DNS for All". www.dnslify.com. Retrieved 2020-05-26.
  2. "Telsy TRT". Retrieved 2020-05-26.
  3. "How to keep your ISP's nose out of your browser history with encrypted DNS". Ars Technica. Retrieved 2018-04-08.
  4. "DNS over TLS - Cloudflare Resolver". developers.cloudflare.com. Retrieved 2018-04-08.
  5. "Google Public DNS now supports DNS-over-TLS". Google Online Security Blog. Retrieved 2019-01-10.
  6. "Quad9, a Public DNS Resolver - with Security". RIPE Labs. Retrieved 2018-04-08.
  7. "Troubleshooting DNS over TLS".
  8. "LibreDNS". LibreDNS. Retrieved 2019-10-20.
  9. "DNS over TLS support in Android P Developer Preview". Google Security Blog. April 17, 2018.
  10. "DNS-over-TLS". dnsdist.org. Retrieved 25 April 2018.
  11. "Bind - DNS over TLS".
  12. "Unbound version 1.7.3 Changelog".
  13. Aleksandersen, Daniel. "Actually secure DNS over TLS in Unbound". Ctrl blog. Retrieved 2018-08-07.
  14. "openbsd-cvs mailing list archives".
  15. "openbsd-cvs mailing list archives".
  16. "blockerDNS - Block Ads and Online Trackers So You Can Browse the Web Privately on Your Android Phone Without Installing an App!". blockerdns.com. Retrieved 2019-08-14.
  17. "The official release of AdGuard DNS — a new unique approach to privacy-oriented DNS". AdGuard Blog. Retrieved 2019-08-14.
  18. "Blahdns -- Dns service support DoH, DoT, DNSCrypt". blahdns.com. Retrieved 2019-08-14.
  19. "DNS over TLS support in Android P Developer Preview". Android Developers Blog. Retrieved 2019-12-07.
  20. "Knot Resolver".
  21. Package: getdns-utils, retrieved 2019-04-04
  22. "Unbound - About". NLnet Labs. Retrieved 2020-05-26.
  23. Cimpanu, Catalin. "Apple adds support for encrypted DNS (DoH and DoT)". ZDNet. Retrieved 2020-10-03.
  24. "resolved.conf manual page". Retrieved 16 December 2019.
  25. "Fedora Magazine: Use DNS over TLS". Retrieved 4 September 2020.
  26. "Systemd adoption". Retrieved 16 December 2019.
  27. "personalDNSfilter - a personal open source dns filter for stopping ads and more". zenz-solutions.de. Retrieved 2020-05-26.
  28. "Nebulo - DNS Changer for DNS over HTTPS/TLS - Apps on Google Play". play.google.com. Retrieved 2020-05-26.
  29. "Managing encrypted DNS connections (DNS over TLS, DNS over HTTPS) with Circle". Circle Support Center. Retrieved 2020-07-07.
  30. Inc, CleanBrowsing. "Parental Control with DNS over TLS Support". CleanBrowsing. Retrieved 2020-08-20.
  31. Inc, CleanBrowsing. "Parental Control with DNS Over HTTPS (DoH) Support". CleanBrowsing. Retrieved 2020-08-20.
  32. blockerDNS. "blockerDNS - Products". blockerdns.com. Retrieved 2020-08-20.
  33. "Protect your privacy with DNS-over-TLS on SafeDNS". SafeDNS. Retrieved 2020-08-20.
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.