How DNS Over HTTPS & DNS Over TLS Help to Prevent DNS Spoofing

Поділитися
Вставка
  • Опубліковано 8 вер 2024
  • Amazon Affiliate Store
    ➡️ www.amazon.com...
    Gear we used on Kit (affiliate Links)
    ➡️ kit.co/lawrenc...
    Try ITProTV free of charge and get 30% off!
    ➡️ go.itpro.tv/lts
    Use OfferCode LTSERVICES to get 5% off your order at
    ➡️ lawrence.video...
    Tesla Referral Program Offer
    🚘 www.tesla.com/...
    Lawrence Systems Shirts and Swag
    👕 teespring.com/...
    Digital Ocean Offer Code
    ➡️ m.do.co/c/85de...
    HostiFi UniFi Cloud Hosting Service
    ➡️ hostifi.net/?v...
    Protect you privacy with a VPN from Private Internet Access
    ➡️ www.privateint...
    Google Fi Service Referral Code
    📱g.co/fi/r/TA02XR
    More Of Our Affiliates that help us out and can get you discounts!
    ➡️ www.lawrencesy...
    Twitter
    🐦 / tomlawrencetech
    Patreon
    🔗 / lawrencesystems
    Our Forums
    🔗 forums.lawrenc...
    GitHub
    🔗 github.com/law...
    Discord
    🔗 / discord
    Our Web Site
    🔗 www.lawrencesy...
    PIA Internet Access Affiliates Link
    www.privateint...
    www.imperva.co...

КОМЕНТАРІ • 39

  • @justinbrash7626
    @justinbrash7626 5 років тому +13

    Also worth noting that you can enable DNS over HTTPS in Preferences > Network Settings in Firefox 66.0.3. So not necessary to go into about:config.

    • @kamalhm-dev
      @kamalhm-dev 5 років тому

      Thanks! didn't notice its already there

  • @Weirlive
    @Weirlive 5 років тому +9

    Just came here to say "WHAT IS JEN DOING WITH THE INTERNET!?!?!?!" :D amazing videos as always!!

    • @thaipapayasalad
      @thaipapayasalad 5 років тому

      Since she is the employee of the month, the internet lords have allowed her to use it for her speech 😂😂

  • @raymondfb
    @raymondfb 5 років тому +5

    Need a outbound firewall rule to prevent IoT hosts and others from overriding DNS settings provided via DHCP.

  • @GavinBogie
    @GavinBogie 5 років тому +6

    DNS over tls or Https what is faster?

  • @chris2ao
    @chris2ao 5 років тому +1

    Can you do a video on how to set this up on the UniFi USG?

  • @didjeri
    @didjeri 5 років тому +5

    Am I correct by assuming that once this gets mainstream - adblocking will be near impossible?

    • @am385
      @am385 5 років тому +4

      They will still work. The browser still knows every where you go. Ad blockers work by looking at the s and injected content to see what host they are from. If the host in on the block list, it will block it. If it didn't block it the browser would then do a DNS request on the host to get the data. That DNS request would be blocked from your ISPs eyes but the browser still knows where it is going.

    • @teemuvesala9575
      @teemuvesala9575 3 роки тому +2

      Incorrect. I use encrypted DNS and even regular browser adblocking extensions can still filter just fine. You can add adblocking filters on some DNS providers, or you can use something like AdGuard that decrypts HTTPS traffic locally so it can filter the ads efficiently.

  • @thezentrader
    @thezentrader 4 роки тому

    This Jen is the internet!

  • @playtime5423
    @playtime5423 5 років тому

    On your video for pfblocker you stated for best practice to set up firewall rules to block LAN for being able to use another DNS than the pfSense set DNS. Now using DNS over TLS that uses port 853, would I need to also set up the same firewall rules along with the ones for port 53 if I’m using pfSense DNS Resolver to do DNS over TLS? Or just rules for 853?

  • @mathesonstep
    @mathesonstep 5 років тому +1

    I have cloudflare's dns over https setup with cloudflared

  • @mathiasmoh1385
    @mathiasmoh1385 5 років тому

    What's about using a transparent proxy with Https? Then you will be able to log the SNI or also block the connection. I'm using this with pfsene at our school environment to block websites.

  • @AssTelescope
    @AssTelescope 4 роки тому

    I strongly suggest you disable DNS over https and use a VPN or Tor if you care about privacy or spoof attacks. We should notngive google and cloudflare complete control of DNS queries.

  • @RonLaws
    @RonLaws 5 років тому +1

    using a DNS Address for a DNS Server is moot, a reason why your "DNS Server" is always specified as an IP Address is exactly this. the same thing applies to DNS over HTTPS.

  • @adisona5582
    @adisona5582 3 роки тому

    Hey Lauren, can I setup DNS over https on Android?

  • @CoreyThompson73
    @CoreyThompson73 5 років тому +3

    DNS over TLS makes sense to prevent spoofing..... DoH adds a lot of overhead and actually results in less privacy as it leaks all the information that is part of the HTTP header (user agent, cookies/session information, etc.).....But it becomes what DNS servers do you end up trusting? Do you really trust CloudFlare or Google or OpenDNS?
    As far as doing your own, it's just a https server that looks at the "dns" field in the query string. Could do a bash, PHP, or JS to serve it.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  5 років тому

      Why not trust CloudFlare, Quad9, Google or OpenDNS?

    • @Noodles.FreeUkraine
      @Noodles.FreeUkraine 5 років тому +1

      @@LAWRENCESYSTEMS Why not trust Google? Seriously? 😳

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  5 років тому

      What are they going to do with your DNS?

    • @danbrown586
      @danbrown586 5 років тому +6

      @@LAWRENCESYSTEMS What does your ISP do with your DNS? Google's business model is explicitly to monetize every possible piece of information they can. For your ISP, that's at most a side business. Cloudflare makes some pretty strong privacy promises. Personally, I run my own resolver on my pfSense box.

    • @Noodles.FreeUkraine
      @Noodles.FreeUkraine 5 років тому +2

      @@LAWRENCESYSTEMS What they do with anything else? Collect every single bit of anything they get their hands on? Mind you, I love your videos and your positive personality. You certainly are a great guy. What I never understood was your knack for Google products, though, considering that if there's one thing that doesn't make them money, it's privacy. I get it, some folks don't care. But even considering a company that bases its entire livelihood on collecting and connecting data to *enhance* personal privacy is… a bit rich.
      I'm not saying that CloudFlare, Apple et. al. won't snoop at all, but at least it's not their entire business model and some of them take an active stance towards privacy, for whatever that's worth (we'll never know for sure of course). But in all honesty, giving Google data for privacy reasons is like handing over your whiskey collection to an alcoholic for safekeeping.
      Oh and yeah, that downvote isn't mine lol

  • @JimDumser
    @JimDumser 5 років тому +1

    DNS over HTTPS and DNS over TLS are 2 different protocols. DoT has been around longer and is supported in pfSense (Tom did a video on it in 2018, ua-cam.com/video/7niY890CEUM/v-deo.html). DoH is newer and seems like more of a workaround.

  • @helloworld9730
    @helloworld9730 5 років тому

    06:36
    every single IT kind of problems ROFL

  • @JimDumser
    @JimDumser 5 років тому

    network.trr.bootstrapAddress...