Cloudflare, Apple And Fastly Developed 'Oblivious DNS-Over-HTTPS' To Improve Internet Privacy

Each time an internet user visits a website, the browser the person uses initiates a DNS resolver to convert web addresses to machine-readable IP addresses to be used to locate where on the internet the web page is located.

This process is not encrypted.

What this means, every time an internet user loads a website, the DNS query is sent in clear text, meaning that internet service providers (ISPs) are able to know what users are trying to visit.

In privacy's perspective, this can expose user browsing habit to unwanted third-parties.

DNS-over-HTTPS (DoH) adds encryption to DNS queries, making it harder for ISPs to know what websites users are visiting, and making things difficult for hackers to hijack DNS queries and point victims to malicious websites instead of the real website they want top visit.

But that still doesn’t stop the DNS resolvers from seeing which website users are trying to visit.

And here, Cloudflare, Apple and Fastly said that they have developed 'Oblivious DNS-over-HTTPS', or ODoH for short, that goes a step further than DoH..

Oblivious DNS-over-HTTPS
Credit: Cloudflare

ODoH is built on a previous work by Princeton academics.

ODoH can make it even more difficult for internet providers to know which websites people visit, by decoupling DNS queries from internet users.

This is to prevent DNS resolvers from knowing which sites users are trying to visit.

ODoH does this by wrapping a layer of encryption around the DNS query and passes it through a proxy server. Because the DNS query is encrypted, the proxy cannot see what data is inside it, which at the same time acts like a protection to prevent DNS resolver from seeing who sent the query in the first place.

“What ODoH is meant to do is separate the information about who is making the query and what the query is,” said Nick Sullivan, Cloudflare’s head of research.

In simple terms, ODoH ensures that only the proxy knows the identity of the internet user, and ensures that the DNS resolver only knows the website being requested. ODoH makes proxy and DNS resolver to never "collude", in that the two are never controlled by a single entity.

Sullivan said that page loading times on ODoH are “practically indistinguishable” from DoH and shouldn’t cause any significant changes to browsing speed.

[block:block=87]
Oblivious DNS-over-HTTPS
Credit: Cloudflare

According to Cloudflare on a blog post:

"To safeguard DNS from onlookers and third parties, the IETF standardized DNS encryption with DNS over HTTPS (DoH) and DNS over TLS (DoT). Both protocols prevent queries from being intercepted, redirected, or modified between the client and resolver. Client support for DoT and DoH is growing, having been implemented in recent versions of Firefox, iOS, and more. Even so, until there is wider deployment among Internet service provider."

"ODoH works by adding a layer of public key encryption, as well as a network proxy between clients and DoH servers."

"In ODoH, the ‘O’ stands for oblivious, and this property comes from the level of encryption of the DNS messages themselves. This added encryption is `end-to-end` between client and target, and independent from the connection-level encryption provided by TLS/HTTPS."

"The ODoH protocol is a practical approach for improving privacy of users, and aims to improve the overall adoption of encrypted DNS protocols without compromising performance and user experience on the Internet."

Initially, ODoH is implemented on only a few of the companies involved, including Cloudflare's own 1.1.1.1 DNS resolver.

Others should wait until ODoH is built straight inside browsers and/or the operating systems before it can ever be used.