Implications of DNS Encryption
the evolution of DNS services, rise of open resolvers, interception risks, DNS over TLS, and future trends pointing towards application-specific name services. Understand the potential fragmentation and challenges in the DNS ecosystem.
Download Presentation

Please find below an Image/Link to download the presentation.
The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.
You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.
The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.
E N D
Presentation Transcript
Implications of DNS Encryption Geoff Huston APNIC Labs
A Traditional View of the DNS The DNS is part of shared common infrastructure services Application Authoritative Servers Recursive Resolver Platform Local ISP Stub Resolver
The Rise of Open Resolvers The DNS as a service overlay Application Local ISP Authoritative Servers Open Recursive Resolver Platform Stub Resolver
Use of Open Resolvers More than a quarter of the Internet s users send queries to open resolvers Google is the dominant provider with 22% market share https://stats.labs.apnic.net/rvrs
Opportunities for Interception The DNS as a service overlay Application Local ISP Authoritative Servers Open Recursive Resolver Platform ECS leaks Stub Resolver resolver leaks transit interception ISP interception Platform Leaks
Opportunities for Interception DNS over TLS Application Local ISP Authoritative Servers Open Recursive Resolver Platform ECS leaks Stub Resolver resolver leaks transit interception ISP interception Platform Leaks
Sealing it up Open DoX Recursive Resolver Application Local ISP Authoritative Servers Open Recursive Resolver Platform Stub Resolver
Application Specific Name Services? ? Application-specific Name Servers Application Local ISP Authoritative Servers Open Recursive Resolver Platform Stub Resolver
Futures? The DNS appears to be receding as a common infrastructure DoH / DoQ are pushing the name space to become an application capability It s possible that the other end of the encrypted tunnel becomes an application-specific name service rather than generic DNS From such application-specific platforms its possible that application- specific name services are used Name pushing Customised names Other bright ideas! At that point the coherency of the name system is placed under pressure and fragmentation of this space becomes more likely