{"id":16546,"date":"2019-10-09T10:45:15","date_gmt":"2019-10-09T18:45:15","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/10\/09\/news-10285\/"},"modified":"2019-10-09T10:45:15","modified_gmt":"2019-10-09T18:45:15","slug":"news-10285","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/10\/09\/news-10285\/","title":{"rendered":"A Controversial Plan to Encrypt More of the Internet"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5d9cbce0fa59c50009c4a124\/master\/pass\/DNS%20security-browser.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Wed, 09 Oct 2019 11:00:00 +0000<\/strong><\/p>\n<p class=\"content-header__row content-header__dek\">The road to routing all Domain Name System lookups through HTTPS is pocked with disagreements over just how much it will help.<\/p>\n<p>The security community generally agrees on the importance of encrypting private data: Add a <a href=\"https:\/\/www.wired.com\/story\/smartphone-security-101\/\">passcode to your smartphone<\/a>. Use a <a href=\"https:\/\/www.wired.com\/story\/ditch-all-those-other-messaging-apps-heres-why-you-should-use-signal\/\">secure messaging app like Signal<\/a>. Adopt <a href=\"https:\/\/www.wired.com\/2017\/03\/pornhub-https-encryption\/\">HTTPS web encryption<\/a>. But a new movement to encrypt a fundamental internet mechanism, promoted by browser heavyweights like Google Chrome and Mozilla&#x27;s Firefox, has sparked a heated controversy.<\/p>\n<p>The changes center around the Domain Name System, a decentralized directory that acts essentially as the internet&#x27;s address book. When you send data to or request it from a server, a DNS lookup ensures that it goes to and comes from the right place. Google and Mozilla plan to encrypt those interactions sometime this year. Which sounds straightforward enough\u2014but not everyone is convinced that the shift solves more problems than it potentially creates.<\/p>\n<p>The concept of DNS was developed in the mid-1980s, and hasn&#x27;t evolved much since the early 1990s. Like many <a href=\"https:\/\/www.wired.com\/story\/bgp-route-leak-internet-outage\/\">foundational internet protocols<\/a>, DNS has been remarkably flexible and serviceable over the years. But having roots that predate the rise of the modern internet has led to inevitable problems, one of which is that those address lookups aren&#x27;t encrypted. That\u2019s a big deal. Any time your browser attempts a DNS lookup, that request can pass across multiple servers. Your internet service provider, lurking government snoops, and just anyone on the same Wi-Fi network can see what websites you visit, even if they can&#x27;t see what you do once you actually load the sites.<\/p>\n<p>It gets even worse. Since DNS requests are unencrypted, bad actors can manipulate them to strategically send you to the wrong website. It\u2019s like listing your address under someone else&#x27;s name, and getting all their packages delivered to your house. This type of attack, known as <a href=\"https:\/\/www.wired.com\/story\/what-is-dns-hijacking\/\">DNS hijacking<\/a>, has been on the rise; in January, the Department of Homeland Security even <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/cyber.dhs.gov\/ed\/19-01\/&quot;}\" href=\"https:\/\/cyber.dhs.gov\/ed\/19-01\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">issued an emergency directive<\/a> about the threat.<\/p>\n<p>&quot;Yeah it\u2019s going to be work, but that\u2019s fine, just do the work.&quot;<\/p>\n<p>Matthew Prince, Cloudflare<\/p>\n<p>Which explains the push for encrypted DNS: It would make those types of surveillance and misdirection much harder. The Internet Engineering Task Force standards body has already codified a few different methods for implementing it, namely \u201cDNS over HTTPS\u201d (DoH) and \u201cDNS over TLS\u201d (DoT). Both protocols apply ubiquitous web encryption to DNS requests. The two standards are very similar, except DoT separates encrypted DNS traffic into its own recognizable channel (an attribute network defenders largely prefer), while DoH intermingles encrypted DNS traffic with general HTTPS encrypted web traffic so they&#x27;re indistinguishable (an additional privacy benefit to some). Each approach has its pros and cons, but both Mozilla and Google have elected to go with DoH in their browsers.<\/p>\n<p>No matter which version you choose, though, adding a layer of encryption to DNS requires some systemic rejiggering. It&#x27;s like writing down your order at a restaurant, locking it in a small safe, and then handing the safe to the waiter to take back to the kitchen. You won&#x27;t give away any personal information about your culinary preferences, but you also won&#x27;t get the right meal.<\/p>\n<p>To get around this complication, secure DNS protocols rely on intermediaries called &quot;resolvers,&quot; which can still see the requests unencrypted as they come through. Mozilla has piloted its encrypted DNS with the internet infrastructure company Cloudflare acting as the main resolver. Cloudflare has already been <a href=\"https:\/\/www.wired.com\/story\/new-encryption-service-adds-privacy-protection-for-web-browsing\/\">offering encrypted DNS<\/a> with a service called 1.1.1.1 for more than a year. Mozilla chose the company because it pledged to delete all DNS logs after 24 hours, never share data with third parties, and submit to audits to confirm that data is really being deleted. But users can set Firefox to default to any resolver that supports DoH. Similarly, Chrome is <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blog.chromium.org\/2019\/09\/experimenting-with-same-provider-dns.html&quot;}\" href=\"https:\/\/blog.chromium.org\/2019\/09\/experimenting-with-same-provider-dns.html\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">starting out<\/a> by offering DoH with <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.chromium.org\/developers\/dns-over-https&quot;}\" href=\"https:\/\/www.chromium.org\/developers\/dns-over-https\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">six resolvers<\/a>, including Cloudflare and Google itself.<\/p>\n<p>That centralization of DNS requests <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.yeettheayys.cf\/?p=69&quot;}\" href=\"https:\/\/www.yeettheayys.cf\/?p=69\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">worries<\/a> detractors. Unlike end-to-end encrypted messaging, in which only you and the person you\u2019re talking to can read the messages on each of your devices, encrypted DNS doesn\u2019t quite succeed at boxing <em>everyone<\/em> out. It cuts telecoms and governments out of the equation in one way, but introduces new tech giants and third parties in another.<\/p>\n<p>&quot;I would love it if there were 100 other encrypted DNS providers that customers could choose from,&quot; says Cloudflare CEO Matthew Prince. &quot;We think that would be great. I get that there being a limited set of choices doesn\u2019t feel good. But there&#x27;s nothing proprietary about this. You can download open source software and run this today.&quot;<\/p>\n<p>The pro-privacy Electronic Frontier Foundation has acknowledged the concerns about consolidating DNS with so few resolvers, but <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.eff.org\/deeplinks\/2019\/09\/encrypted-dns-could-help-close-biggest-privacy-gap-internet-why-are-some-groups&quot;}\" href=\"https:\/\/www.eff.org\/deeplinks\/2019\/09\/encrypted-dns-could-help-close-biggest-privacy-gap-internet-why-are-some-groups\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">recently suggested<\/a> that the potential privacy benefits are worth the downside so long as more entities get into the space. Specifically, EFF called on internet service providers to start acting as encrypted DNS resolvers themselves. Ideally, this would involve getting ISPs to sign on to strict privacy protections like those Cloudflare has promised to adhere to as part of the process of adding support for DoH.<\/p>\n<p>That may not happen anytime soon, though. And even if it did, you can see how it would be difficult in practice to get entities already making money off of mining DNS data to really change their ways. A consortium of telecommunications trade associations wrote a <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.ncta.com\/sites\/default\/files\/2019-09\/Final%20DOH%20LETTER%209-19-19.pdf&quot;}\" href=\"https:\/\/www.ncta.com\/sites\/default\/files\/2019-09\/Final%20DOH%20LETTER%209-19-19.pdf\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">letter to Congress<\/a> in September opposing encrypted DNS and calling Google anti-competitive for starting to support it in Chrome. This argument seems specious at best, given that Chrome will be able to use a number of resolvers, not just Google\u2019s. The overall effort, though, reflects how invested ISPs are in protecting their access to DNS data, seemingly so they can mine it to fuel targeted advertising. ISPs do also use insight into DNS requests to offer services like content filtering for children. House of Representatives investigators are <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.wsj.com\/articles\/google-draws-house-antitrust-scrutiny-of-internet-protocol-11569765637&quot;}\" href=\"https:\/\/www.wsj.com\/articles\/google-draws-house-antitrust-scrutiny-of-internet-protocol-11569765637\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">currently assessing<\/a> the letter\u2019s claims.<\/p>\n<p>The ranks of DoH opponents aren&#x27;t filled only with self-interested corporations. Cybersecurity professionals argue that encrypting DNS requests will make it harder to spot intrusions and malware on their networks, without truly giving web users a more private experience. Meanwhile, encrypted DNS advocates say that these concerns are overblown, especially for large companies that can just set up their own encrypted DNS resolver to access local traffic as before\u2014although those measures aren\u2019t necessarily feasible for the majority of organizations.<\/p>\n<p>\u201cThere are real operational and security implications of both DoH and DoT,\u201d says Roland Dobbins, a principal engineer at Netscout Arbor. \u201cEveryone needs to consider that things like identifying compromised devices and defending DNS infrastructure from DDoS attacks could become much more complex and costly.\u201d<\/p>\n<p>DDoS attacks on DNS servers can have very real consequences. For example, a <a href=\"https:\/\/www.wired.com\/2016\/10\/internet-outage-ddos-dns-dyn\/\">massive 2016 assault<\/a> on the DNS provider Dyn caused widespread connectivity outages on the East Coast of the United States and around the country.<\/p>\n<p>&quot;We&#x27;re just trading who can potentially track us.&quot;<\/p>\n<p>Jake Williams, Rendition Infosec<\/p>\n<p>Researchers have already <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module&quot;}\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">spotted malware<\/a> built to <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bleepingcomputer.com\/news\/security\/new-godlua-malware-evades-traffic-monitoring-via-dns-over-https\/&quot;}\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-godlua-malware-evades-traffic-monitoring-via-dns-over-https\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">evade detection<\/a> by connecting to command and control servers using encrypted DNS requests. And another major concern is that if hackers were to compromise a trusted DNS resolver, they would be able to pull off devastating DNS hijacking attacks that wouldn&#x27;t be detectable to the outside world. A <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.cyberscoop.com\/trustico-digicert-ssl-certificates-revoked\/&quot;}\" href=\"https:\/\/www.cyberscoop.com\/trustico-digicert-ssl-certificates-revoked\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">similar issue<\/a> already exists when hackers <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/slate.com\/technology\/2016\/12\/how-the-2011-hack-of-diginotar-changed-the-internets-infrastructure.html&quot;}\" href=\"https:\/\/slate.com\/technology\/2016\/12\/how-the-2011-hack-of-diginotar-changed-the-internets-infrastructure.html\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">compromise<\/a> the \u201ccertificate authorities\u201d that underpin general HTTPS web encryption.<\/p>\n<p>Firefox and Chrome are still in the experimental phases of testing encrypted DNS, so most of your connections likely won&#x27;t take advantage of it for now anyway, and there are still ways to opt out of using it at all. But as with the push to get websites to adopt HTTPS encryption, encrypted DNS will likely move forward now if Chrome and Firefox find that the change doesn\u2019t have too much of an impact on speed or reliability for users.<\/p>\n<p>\u201cYeah it\u2019s going to be work, but that\u2019s fine, just do the work,\u201d says Cloudflare\u2019s Prince. \u201cI\u2019m astonished how political this has been. It makes me uncomfortable that every coffee shop I\u2019m going to knows every site that I\u2019m visiting. It seems like it\u2019s a no brainer to be adding encryption. Let\u2019s just do it!\u201d<\/p>\n<p>For the average person, encrypted DNS will offer valuable privacy protections against ISPs and other entities that are hungry for user data. Even so, analysts caution that potentially risky web browsing should still take place with sturdier protections, like a <a href=\"https:\/\/www.wired.com\/2017\/03\/want-use-vpn-protect-privacy-start\/\">VPN<\/a> or the <a href=\"https:\/\/www.wired.com\/story\/the-grand-tor\/\">anonymity service Tor<\/a>.<\/p>\n<p>Critics of DNS over HTTPS do recognize the irony of pushing for less encryption out of a desire to protect people when the security and cryptography communities overall take a hard line against law enforcement on the <a href=\"https:\/\/www.wired.com\/story\/encryption-wars-facebook-messaging\/\">value of encrypted communication platforms<\/a> free of backdoors. But the difference, they say, is that end-to-end encryption or encryption at rest cuts everyone out except the data&#x27;s owners, while DNS encryption only shifts trust.<\/p>\n<p>\u201cFrom an enterprise standpoint, DNS monitoring is critical to ensuring security. Losing the visibility into DNS is tremendous operational loss and will help attackers more than it ensures privacy,\u201d says Jake Williams, a former NSA hacker and founder of the security firm Rendition Infosec. \u201cAs long as you trust resolvers like Cloudflare, then there&#x27;s no issue. And I personally trust Cloudflare, but others may not. We&#x27;re just trading who can potentially track us.\u201d<\/p>\n<p>Vulnerable web users who&#x27;ve never given any of this a second thought\u2014and don&#x27;t even know what DNS is\u2014would probably say, though, that they&#x27;ll take whatever they can get.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/dns-over-https-encrypted-web\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5d9cbce0fa59c50009c4a124\/master\/pass\/DNS%20security-browser.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Wed, 09 Oct 2019 11:00:00 +0000<\/strong><\/p>\n<p>The road to routing all Domain Name System lookups through HTTPS is pocked with disagreements over just how much it will help.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-16546","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16546"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16546\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16546"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}