DNS Encryption explained - DNS over TLS (DoT) & DNS over HTTPS (DoH)

DNS Encryption explained - DNS over TLS (DoT) & DNS over HTTPS (DoH)

Christian Lempa

4 года назад

48,529 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@benoit.gerin-lajoie
@benoit.gerin-lajoie - 29.09.2023 07:13

You are addressing HALF of the problem : the "question" (request). What about the "reply" ? What is the packet configuration of the reply ? Does it contain your IP address (in clear) and the IP address of the encrypted url (in clear) ? If so, then... you aren't "protected" since your ISP can reverse lookup the DNS contained in the "reply" packet ! No ?

Ответить
@harshavmb
@harshavmb - 31.08.2023 12:36

How does the performance impact look here? DNS under 512 bytes is a UDP query, super fast. Most machines cache the results locally, but resolvers usually don't cache. They may have to take more burden of responding to users queries by encrypting, decrypting, additional payload etc.,
Also I'm not sure if bind daemon supports these protocols as it's widely used.

Ответить
@sumankumarpoddar6892
@sumankumarpoddar6892 - 27.08.2023 07:12

From India.. thanks 👍

Ответить
@jyxue
@jyxue - 13.08.2023 08:19

so helpful, much thanks

Ответить
@mario_vasquez_
@mario_vasquez_ - 06.05.2023 23:27

very good. demoing with wireshark was very useful. thank you and please keep making videos like this.

Ответить
@alqods80
@alqods80 - 01.02.2023 07:19

Very good video but the background music is annoying

Ответить
@aeroxx
@aeroxx - 25.01.2023 05:04

Thanks for the knowledge. So these techniques still need to be supported by the hosters/sites to make it fully encrypted?
I am just wondering if its really better to send the dns query via cloud based providers instead of „trusting/rely“ on your ISP. Probably depends on the country and their laws

Ответить
@angelsmalls7044
@angelsmalls7044 - 20.01.2023 17:13

Still confused if I should use DoH or DoT. I wanna be secure but also want to hide from my ISP.

Ответить
@markpelayo
@markpelayo - 08.01.2023 15:34

Thank you for your video. I have a question what do you think would be faster DoH or DoT?

Ответить
@zeytee
@zeytee - 15.12.2022 09:44

Very helpful and makes learning easy. I watched it twice to digest all details well.

Ответить
@sidhucr7985
@sidhucr7985 - 08.12.2022 00:51

can't connect to internet with my mobile data but with wifi....my browser says dns is hijacked or polluted please please help me to fix this issue

Ответить
@erikeriksson1920
@erikeriksson1920 - 23.10.2022 21:50

Annoying music.

Ответить
@sshadyh
@sshadyh - 30.09.2022 02:05

if you are using a VPN does it matter ?

Ответить
@b0ys0l09
@b0ys0l09 - 18.05.2022 05:37

Can zone transfers also be done the same?

Ответить
@contenteater
@contenteater - 09.05.2022 09:21

Wouldn’t encrypting your queries with DOH or DOT also protect you from the dns provider itself?
I understand that Cloudfare, Nextguard, etc claim not to keep logs but can they initially see all of our traffic?

Ответить
@skyscraperfan
@skyscraperfan - 19.04.2022 15:43

Doesn't my provider still know which domains I visit? It the provider has a DNS, the provider knows which IPs belong to which domain. So even if my provider does not see the DNS request, once I load a single package from the IP he will still know that I visited the website with that IP. If the DNS knows which IP belongs to which domain, the opposite should als be possible. So I do now really see how my privacy is protected unless I use a VPN.

PS: Be careful with Google's DNS servers! Google does not really provide that service for free. They will store all the domains you visited forever to send you even more targeted ads.

Ответить
@manishalankala1622
@manishalankala1622 - 30.03.2022 18:58

Nice

Ответить
@kaalmansur
@kaalmansur - 19.02.2022 00:13

Würde ich das Problem lösen, wenn ich einen VPN in meinem Wlan-Netzwerk etabliere und wenn nicht, warum nicht? Besten Dank! - Ich beantworte mal selbst, würde mich aber über Feedback freuen: das Problem entsteht "ausserhalb" meines Netzwerkes und die IP-Adresse wird über die Leitung "einsehbar" so kein TLS über DNS konfiguriert ist. Der VPN kann nur verhindern, dass jemand mein Wlan entert, davon wird das senden der IP ausserhalb des Netzwerkes aber nicht berührt, korrekt?

Ответить
@shuangliu2204
@shuangliu2204 - 09.02.2022 11:45

I like your accent as a non englsih native speaker

Ответить
@R1D9M8B4
@R1D9M8B4 - 06.02.2022 03:07

Thank you

Ответить
@mohsen3448
@mohsen3448 - 21.01.2022 00:25

Perfect Content and clear explanation! Kudos to you!
Please make more of this kinds of technical/conceptual videos related to security topics which are a great help for other IT/Network enthusiastic individuals such as myself!

Ответить
@GamesOfficialYouTube
@GamesOfficialYouTube - 19.12.2021 04:56

So so you recommend IPS DNS or CloudFlare DNS over HTPPS? Great video btw

Ответить
@bethanybellwarts
@bethanybellwarts - 12.11.2021 19:15

But doesn't this only hide the URL? Once the URL is resolved to an IP address, isn't that IP address then visible to your ISP, therefore they can still work out exactly what website you are accessing?

Ответить
@neelupatel5498
@neelupatel5498 - 02.08.2021 08:07

How do attackers use the DOH for malicious purposes? Will they use any tool to tunnel the DOH and then applies data exfiltration or they will exploit the server such as Cloudflare, Mozilla and then applies C2 commands.

Ответить
@kenanderson7769
@kenanderson7769 - 27.05.2021 05:18

An enable button on a web browser does not mean anything has been changed. I doubt firefox, a company dependent on google for its existence, can be trusted.

Ответить
@dilipdilipjohn
@dilipdilipjohn - 29.04.2021 10:21

How these settings are turned on..?
(Using DNS over WARP)

Ответить
@mrd4233
@mrd4233 - 06.04.2021 22:36

Very interesting topic! New to your channel!

Ответить
@BernieD940
@BernieD940 - 26.03.2021 23:08

Thanks, that was a good discussion.

Ответить
@glowinthedark9082
@glowinthedark9082 - 25.02.2021 14:08

just post all ip addresses

Ответить
@VEKTOR_87
@VEKTOR_87 - 23.12.2020 22:26

really helphufl thanks ! :)

Ответить
@AsifAAli
@AsifAAli - 30.11.2020 19:12

Very well explained. Thank you. 🙏🏽

Ответить
@GorkemYildirim
@GorkemYildirim - 17.11.2020 13:22

I learnt something new thanks to you.

Ответить
@skolarii
@skolarii - 28.09.2020 16:16

Wouldn't the purpose be defeated if a company's DNS doesn't support DoH or DoT?

Ответить
@payambakhshi1498
@payambakhshi1498 - 22.09.2020 04:04

Centralized or De-Centralized , that's the question too :) , thanks for the nice video

Ответить
@goks7
@goks7 - 09.09.2020 15:40

Awesome content, had been banging my head on such concepts. Request you to explain how to capture the data via Wireshark.

Ответить
@alimahaboob2287
@alimahaboob2287 - 30.08.2020 04:32

I want to see the configuration you did for stubby.yml file. Could you please share?

Ответить
@Reepix
@Reepix - 25.08.2020 11:38

Question: Considering android 9 pie now incorporates DoT configuration, browsers like Bromite incorporating DoH and DNS providers like Quad9 providing free encrypted options for both... is it possible/beneficial to use both simultaneously...? On android mobile or tablet devices

Ответить
@Punitkp94
@Punitkp94 - 03.08.2020 19:04

So, which one is better to use? DoT or DoH?????

Ответить
@HEWfunkingKNEWit
@HEWfunkingKNEWit - 11.06.2020 00:02

Yes pls more videos on this topic ✌

Ответить
@jojimerc7396
@jojimerc7396 - 29.05.2020 08:47

This channel is very helpful for DevOps.

Ответить