Microsoft Announces Plan To Support DoH In Windows

Peter Reutemann <[email protected]> Tue, 19 Nov 2019 09:03:11 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LuF9eN_74NWjJUm65n-kTbTrzLcL1gLeQT+SXhN9o4Mg@mail.gmail.com>
'Microsoft's Core Network team just announced they plan on supporting
DoH in the Windows resolver. In the blog post, the company writes:

Providing encrypted DNS support without breaking existing Windows
device admin configuration won't be easy. However, at Microsoft we
believe that "we have to treat privacy as a human right. We have to
have end-to-end cybersecurity built into technology." We also believe
Windows adoption of encrypted DNS will help make the overall Internet
ecosystem healthier. There is an assumption by many that DNS
encryption requires DNS centralization. This is only true if encrypted
DNS adoption isn't universal. To keep the DNS decentralized, it will
be important for client operating systems (such as Windows) and
Internet service providers alike to widely adopt encrypted DNS. With
the decision made to build support for encrypted DNS, the next step is
to figure out what kind of DNS encryption Windows will support and how
it will be configured. Here are our team's guiding principles on
making those decisions:

Windows DNS needs to be as private and functional as possible by
default without the need for user or admin configuration because
Windows DNS traffic represents a snapshot of the user's browsing
history. To Windows users, this means their experience will be made as
private as possible by Windows out of the box. For Microsoft, this
means we will look for opportunities to encrypt Windows DNS traffic
without changing the configured DNS resolvers set by users and system
administrators.
Privacy-minded Windows users and administrators need to be guided to
DNS settings even if they don't know what DNS is yet. Many users are
interested in controlling their privacy and go looking for
privacy-centric settings such as app permissions to camera and
location but may not be aware of or know about DNS settings or
understand why they matter and may not look for them in the device
settings.
Windows users and administrators need to be able to improve their DNS
configuration with as few simple actions as possible. We must ensure
we don't require specialized knowledge or effort on the part of
Windows users to benefit from encrypted DNS. Enterprise policies and
UI actions alike should be something you only have to do once rather
than need to maintain.
Windows users and administrators need to explicitly allow fallback
from encrypted DNS once configured. Once Windows has been configured
to use encrypted DNS, if it gets no other instructions from Windows
users or administrators, it should assume falling back to unencrypted
DNS is forbidden.'

-- source: https://yro.slashdot.org/story/19/11/18/1929229

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz