Show HN: dingo - a Google DNS-over-HTTPS caching proxy in Go
github.com
github.com
Worth pointing out, this is not a google project, it just uses Google's DNS over HTTP endpoint.
We have one we made at https://www.openresolve.com/
1/ I hope to update the project to use QUIC soon, so it will use encrypted UDP to fetch DNS data from Google Public DNS. It is somehow similar to the DNS over DTLS idea, developed under IETF dprive WG.
2/ dingo does not need to resolve dns.google.com. Providing the server IP address is enough (IPv4 or IPv6, make sure it is close to your location). dingo verifies the server certificate to make sure we talk to Google. It can even "spoof" the TLS SNI string to avoid HTTPS firewalls, too (by default it asks for www.google.com, which is pretty benign).
3/ Last but not least, it's just my first non-trivial Golang project - thanks for all your suggestions! :)
The Google documentation explains that (look for "random_padding") at https://developers.google.com/speed/public-dns/docs/dns-over...
Are you confirming SNI is being used for censorship?
https://wiki.untangle.com/index.php/Web_Filter#HTTPS_Options
http://www.watchguard.com/help/docs/wsm/xtm_11/en-us/content...
Here's an example release.sh I have in most of my projects https://github.com/micromdm/scep/blob/master/cmd/scepclient/...
However you implement it, encrypting DNS probably has it's place, but it doesn't make a whole lot of sense for most applications.
[0] https://en.wikipedia.org/wiki/Datagram_Transport_Layer_Secur...
https://datatracker.ietf.org/doc/draft-ietf-dprive-dnsodtls/
https://datatracker.ietf.org/doc/draft-ietf-dprive-dtls-and-...
It's not immediately obvious what the thing does from the description.
"A caching DNS proxy for the Google DNS-over-HTTPS. It effectively encrypts all your DNS traffic."
https://developers.google.com/speed/public-dns/docs/dns-over...