DNS OVER HTTPS (DOH)
2018 Workshop on Internet Economics (WIE) December 2018
DNS OVER HTTPS (DOH) Performance Implications & Risks 2018 - - PowerPoint PPT Presentation
DNS OVER HTTPS (DOH) Performance Implications & Risks 2018 Workshop on Internet Economics (WIE) December 2018 DOH THE PROTOCOL DEVELOPED TO COUNTER PERCEIVED THREATS Hostile governments & political environments: Surveillance
2018 Workshop on Internet Economics (WIE) December 2018
2
DEVELOPED TO COUNTER PERCEIVED THREATS
HOW IT WORKS
compact UDP/53 DNS protocol SO FAR SO GOOD!
DOH – THE PROTOCOL
3
THE STUB IS THE BROWSER OR MOBILE OS
“TRUSTED RECURSIVE RESOLVERS”
IF JUST GOOGLE AND MOZILLA MOVE
UH OH…
DOH – THE IMPLEMENTATION
4
DRAMATIC CENTRALIZATION OF THE INTERNET’S MOST WIDELY DISTRIBUTED PROTOCOL
based commercial providers (61% to just one)
internal tools/systems, compromise of an admin account from 1 – 2 dozen sys admins
NO MORE LOCAL POLICY EXPRESSION IN EACH NETWORK CONNECTING TO THE INTERNET
RISKS
5
SEVERELY LACKING
and community consideration of the results and implications.
time, not the time to fetch the destination content and whether that was fully localized via a CDN – in essence it was slower to get AN answer and unclear if it was the BEST / MOST LOCAL answer.
resolver load on a per-query basis is likely to be much higher for DoH vs. UDP/53 DNS. For comparison, the Comcast DNS resolvers receive over 500 billion queries per day. The infrastructure to handle 25,000 users for a few hours is in no way comparable to billions of queries, so no server-side scaling conclusions can be drawn.
MEASUREMENTS TO DATE
6
BEST ANSWER VS. ANY ANSWER, OPEN DATA, BETTER CONTROL OVER VARIABLES
something like RIPE Atlas or (FCC MBA) SamKnows probes
CDN-based and likely to be most localized (most popular content – not long tail)
MEASUREMENTS NEEDED