Measuring the Availability and Response Times of Public Encrypted DNS Resolvers

08/09/2022
by   Ranya Sharma, et al.
0

Unencrypted DNS traffic between users and DNS resolvers can lead to privacy and security concerns. In response to these privacy risks, many browser vendors have deployed DNS-over-HTTPS (DoH) to encrypt queries between users and DNS resolvers. Today, many client-side deployments of DoH, particularly in browsers, select between only a few resolvers, despite the fact that many more encrypted DNS resolvers are deployed in practice. Unfortunately, if users only have a few choices of encrypted resolver, and only a few perform well from any particular vantage point, then the privacy problems that DoH was deployed to help address merely shift to a different set of third parties. It is thus important to assess the performance characteristics of more encrypted DNS resolvers, to determine how many options for encrypted DNS resolvers users tend to have in practice. In this paper, we explore the performance of a large group of encrypted DNS resolvers supporting DoH by measuring DNS query response times from global vantage points in North America, Europe, and Asia. Our results show that many non-mainstream resolvers have higher response times than mainstream resolvers, particularly for non-mainstream resolvers that are queried from more distant vantage points – suggesting that most encrypted DNS resolvers are not replicated or anycast. In some cases, however, certain non-mainstream resolvers perform at least as well as mainstream resolvers, suggesting that users may be able to use a broader set of encrypted DNS resolvers than those that are available in current browser configurations.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/14/2020

Measuring the Performance of Encrypted DNS Protocols from Broadband Access Networks

Until recently, DNS traffic was unencrypted, leaving users vulnerable to...
research
05/03/2023

Training Natural Language Processing Models on Encrypted Text for Enhanced Privacy

With the increasing use of cloud-based services for training and deployi...
research
08/09/2022

Understanding User Awareness and Behaviors Concerning Encrypted DNS Settings

Recent developments to encrypt the Domain Name System (DNS) have resulte...
research
02/07/2022

One to Rule them All? A First Look at DNS over QUIC

The DNS is one of the most crucial parts of the Internet. Since the orig...
research
02/20/2020

D-DNS: Towards Re-Decentralizing the DNS

Nearly all Internet services rely on the Domain Name System (DNS) to res...
research
03/15/2019

White Mirror: Leaking Sensitive Information from Interactive Netflix Movies using Encrypted Traffic Analysis

Privacy leaks from Netflix videos/movies is well researched. Current sta...
research
05/30/2022

Snoopy: A Webpage Fingerprinting Framework with Finite Query Model for Mass-Surveillance

Internet users are vulnerable to privacy attacks despite the use of encr...

Please sign up or login with your details

Forgot password? Click here to reset