The DNS Encryption War: Why Privacy Tools and Security Teams Are Fighting Over DoH
Technically U20 Kesä

The DNS Encryption War: Why Privacy Tools and Security Teams Are Fighting Over DoH

DNS over HTTPS (DoH) encrypts the internet's phonebook—and it's breaking traditional network security. Here's what IT professionals need to know about DoH in 2026, why enterprises are concerned, and how to adapt.🔐 WHAT IS DNS OVER HTTPS:THE PROBLEM DoH SOLVES:- Traditional DNS = plaintext on port 53 (unencrypted since 1983)- ISPs, network operators, anyone on WiFi can see every domain you visit- DNS queries reveal: Health research, job hunting, political views, all browsing activity- Government censorship via DNS blocking- DNS hijacking attacks on public WiFiHOW DoH WORKS:- Wraps DNS queries inside HTTPS connections (port 443)- Encrypted with TLS (same as secure websites)- Network observers see encrypted HTTPS traffic, can't tell it's DNS- RFC 8484 standard (2018)DoH vs DoT (DNS over TLS):- DoT: Dedicated port 853, easier for networks to identify/block- DoH: Port 443 (standard HTTPS), indistinguishable from web traffic- Both: Same encryption strength (TLS)- DoH: Better privacy, harder to block- DoT: Easier for enterprises to monitor/control⚠️ WHY ENTERPRISES ARE CONCERNED:BROWSER-LEVEL DoH BYPASSES CORPORATE DNS:- Firefox enables DoH by default (85%+ US users in 2026)- Chrome auto-upgrades when available- Bypasses network security tools completelyWHAT GETS BROKEN:1. Malware blocking (can't filter queries to C2 servers)2. Content filtering (parental controls, workplace policies)3. Threat detection (can't log DNS queries to identify infections)4. Data loss prevention (can't block file-sharing, personal email)5. Incident response (DNS logs don't exist for forensics)6. Compliance (regulatory requirements to monitor traffic)REAL ATTACKS USING DoH:- Godlua DDoS worm (2019): Used DoH to hide C2 communications- ShadowPad backdoor (2024): Encrypted DNS tunneling- 87% of organizations experienced DNS attacks in 2026- Malware increasingly adopting encrypted DNS to evade detectionNSA WARNING (January 2021, still relevant 2026):"Enterprises should avoid external DoH resolvers. Deploy internal DoH/DoT resolvers and block external endpoints."🛠️ HOW ENTERPRISES ARE ADAPTING:SOLUTION 1: Deploy Internal DoH/DoT Resolvers- Windows Server 2025: DoH support added February 2026- Run corporate DoH server with threat intelligence/filtering- Configure devices via MDM/group policy- Result: Encrypted DNS + enterprise security controlsSOLUTION 2: Block External DoH Providers- Block Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9, etc.- Configure browser enterprise policies to disable DoH- Challenge: 931+ active DoH resolvers globally (can't block all)SOLUTION 3: Firefox Canary Domains- Firefox checks "use-application-dns.net" before enabling DoH- Corporate DNS returns specific response = Firefox disables DoH- Limitation: Only Firefox (Chrome doesn't use canary domains)SOLUTION 4: Roaming Client Agents- Deploy agents on devices (Cloudflare Gateway, Cisco Umbrella, DNSFilter)- Route DoH through corporate resolver- Works on BYOD and remote workers- Identity-aware policies even when encryptedSOLUTION 5: Shift to Endpoint Security- Network visibility lost → endpoint visibility gained- EDR (Endpoint Detection and Response) monitors device processes- TLS certificate monitoring, IP reputation, traffic patterns- Complement, don't replace, DNS security📊 CURRENT STATE (2026):ADOPTION RATES:- Firefox: 85%+ US users on DoH- Chrome: Auto-enabled since 2020- iOS/Android: "Private DNS" in system settings- Windows 11: DoH configuration built-in- Windows Server 2025: DoH server support (Feb 2026)JANUARY 2025 US EXECUTIVE ORDER:- Mandated DNS encryption for federal systems- Accelerated enterprise adoption- Government agencies deploying internal DoH/DoT resolvers

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(270)

Pass-ta-Key Attacks: Is Passwordless Security Still Safe?

Pass-ta-Key Attacks: Is Passwordless Security Still Safe?

Apple, Google, Microsoft, and the security industry have spent years telling us that passkeys are the future of authentication.No passwords.Less phishing.No reusable credentials for attackers to steal...

12 Syys 23min

SaaS Bloodbath: Why Your Trusted Apps Are Now the Attack Surface

SaaS Bloodbath: Why Your Trusted Apps Are Now the Attack Surface

Your company may not get hacked through the firewall. It may get breached through the SaaS app everyone trusts.In this episode of Technically U, we break down the growing SaaS security crisis and why ...

5 Syys 36min

The AI Data Disaster: What ChatGPT, Claude, and Gemini Really Do With Your Secrets

The AI Data Disaster: What ChatGPT, Claude, and Gemini Really Do With Your Secrets

143,000 ChatGPT, Claude, and Copilot conversations are publicly accessible right now. Here's what was exposed—and why your AI isn't as private as you think.🚨 THE HEADLINE:143,000 user conversations w...

29 Elo 21min

The BIMI Paradox: Why 90% of Companies Are Losing Thousands.

The BIMI Paradox: Why 90% of Companies Are Losing Thousands.

The BIMI Paradox: Why 90% of Companies Are Losing Thousands—And Why Your Logo Might Be Illegal in Inboxes (2026 Reality Check).BIMI (Brand Indicators for Message Identification): 90% of companies have...

29 Elo 26min

Beyond Surveillance: How Behavioral Analytics Became a Trust Problem

Beyond Surveillance: How Behavioral Analytics Became a Trust Problem

Behavioral Analytics in 2026: How Companies Are Moving From Surveillance to Trust ArchitectureThe paradox nobody talks about: 76% of companies see efficiency gains from monitoring. But 60% of employee...

20 Elo 17min

The Confidence Gap: Why Executives Think AI Agents Are Secure (And Why They're Wrong)

The Confidence Gap: Why Executives Think AI Agents Are Secure (And Why They're Wrong)

The Confidence Gap: AI Agents and the Security Crisis Nobody Is Talking AboutEighty-two percent of executives feel confident that their existing AI agent policies are enough to keep their organization...

8 Elo 18min

Seeing Is No Longer Believing: How Deepfake Fraud Targets Businesses and Families

Seeing Is No Longer Believing: How Deepfake Fraud Targets Businesses and Families

What if the voice on the phone sounds exactly like your boss, your bank, or someone in your family — but it isn’t them?In this episode of Technically U, we break down Deepfake Fraud and why it has bec...

31 Heinä 23min

The AI Criminal Playbook: How Cybercrime Changed Forever in 2026

The AI Criminal Playbook: How Cybercrime Changed Forever in 2026

The next generation of cybercrime may not come from a hacker typing code in a dark room.It may come from someone using AI to generate phishing emails, clone voices, create fake identities, manipulate ...

24 Heinä 16min