Access and Feeds

Security: Encrypted DNS could Thwart Hackers but also Concentrate DNS Handling to a Few

By Dick Weisinger

SSL encrypts data sent from a browser to a server, keeping that information confidential. Now more than 55 percent of all websites use SSL encryption by default. But SSL alone doesn’t plug all the potential security problems of browser to server communication.

DNS queries used to locate the server the data will be transmitted to are not encrypted. That means that even though the data exchanged via SSL is encrypted, it’s easy to track which servers you’re connecting to. That information is then often collected and used to serve up ads based on which servers and web pages you’re interacting with.

A solution to the unencrypted DNS problem is called DNS over HTTPS. The new technology is backed by Google Mozilla and Cloudflare. While it would be more secure, not everyone is happy about it.

Internet providers (ISPs) like AT&T, Comcast and Time Warner would lose insight into statistics about DNS traffic. But there’s also a worry that even though the technology might thwart hackers, it would change the flow of DNS traffic to go through the makers of browsers, like Google’s Chrome and Mozilla’s Firefox.

Google denies that that’s what they’re up to. A Google spokesperson said that “Google has no plans to centralize or change people’s DNS providers to Google by default. Any claim that we are trying to become the centralized encrypted DNS provider is inaccurate.”

A letter addressed to US lawmakers by a coalition of ISPs said that “because the majority of world-wide internet traffic…runs through the Chrome browser or the Android operating system, Google could become the overwhelmingly predominant DNS lookup provider. Google would acquire greater control over user data across networks and devices around the world. This could inhibit competitors and possibly foreclose competition in advertising and other industries.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)
One comment on “Security: Encrypted DNS could Thwart Hackers but also Concentrate DNS Handling to a Few
  1. If DNS is served by your local ISP resolver (or company/home), no chance this information could be used to display ads. If you use DOH with a provider of service like ads, you then are exposed…

Leave a Reply

Your email address will not be published. Required fields are marked *

*