EDIT: clearly shouldn't have used unexplained acronyms: DoH = DNS over HTTPS, DoT = DNS over TLS (which typically uses port 853)
EDIT: clearly shouldn't have used unexplained acronyms: DoH = DNS over HTTPS, DoT = DNS over TLS (which typically uses port 853)
DNS over TLS can be easily blocked by blocking port 853. To block DNS over HTTPS you need to block the entire HTTPS traffic.
DOH also doesn't help much with censorship: If you look at traffic patterns, you can detect and block DOH servers pretty easily: look for small queries to a constant endpoint that come just before new connections.
Your explained method is nearly impossible to implement for medium to large scale networks.
Hell, you can go even more trivial with barely any effort: for every new https connection to an unknown server, send a DNS query. If you get a response, block the IP.
HTTP adds nothing but complexity.
But what they should have done (and still could) is to have the server use SNI to determine whether it should speak HTTPS or DoT and then let the clients use DoT by providing the relevant server name.
Think DNS over TLS. Okay. You think $ip:$port is a dns connection. You send query with DoT protocol. You get answers. Bingo! It’s DNS.
If it’s DNS over HTTPS, you can’t tell. What domain(dns.quad9.net or cloudflare-dns.com or dns.google or whatever you can imagine) is it? What endpoint and method(/dns-query?url= or whatever you can imagine) is it? You can’t tell.
HTTP adds complexity. Complexity adds security.
And you still have the traffic patterns that will give you the information with sufficient confidence.
And blocking https packets with mere confidence is impossible.
So, yeah, I can serve up DOH on my own server with a custom endpoint, custom client configuration, and generate cover traffic. But that's not exactly easy. And http doesn't help: I can do that without http, something like https://github.com/yrutschle/sslh, or using SNI (which, as of TLS 1.3, is encrypted).
And merely saying something is impossible doesn't make it so. It doesn't even make it hard.
(I guess DNS over https and DNS over TLS is the same thing.)
> tls-upstream: <yes or no> > Enabled or disable whether the upstream queries use TLS only for transport.
BTW, you can also use it on Linux.
https://www.dnsknowledge.com/unbound/configure-unbound-dns-o...
It's not.
I've always thought they are the same thing.