<div dir="ltr"><div class="gmail_default" style="font-size:small">By coincidence, I yesterday restreamed a DOH explainer from the recent Radical Networks conference.</div><div class="gmail_default" style="font-size:small"><br></div><div class="gmail_default" style="font-size:small"><a href="https://twitter.com/ISOC_Live/status/1196568587466469378">https://twitter.com/ISOC_Live/status/1196568587466469378</a><br></div><div class="gmail_default" style="font-size:small"><br></div><div class="gmail_default" style="font-size:small">joly</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Nov 19, 2019 at 3:25 PM Sam Lanfranco <<a href="mailto:lanfran@yorku.ca">lanfran@yorku.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><font face="Tahoma" size="2"><div><font size="3">I could do with some expert opinion and enlightenment here. From what I read the following move is likely to have a negative effect on the security of the DNS system.</font></div><div><br></div><font size="5">From circleID: Microsoft Announces Plans to Adopt DoH in Windows</font><table width="100%" cellspacing="0" cellpadding="0" border="0" align="center"><tbody><tr><td style="padding:18px 15px 0px;font-family:Helvetica,Arial,sans-serif;font-size:26px;line-height:34px;font-weight:bold;color:rgb(0,0,0);border-left:1px solid rgb(221,221,221);border-right:1px solid rgb(221,221,221)" bgcolor="#ffffff"><p><font size="3"><font size="2" face="Tahoma"><strong>Microsoft announced today its plans to adopt DNS over HTTPS (DoH) protocol</strong>
in Windows and will also keep other options such as DNS over TLS (DoT)
on the table for consideration. "[S]upporting encrypted DNS queries in
Windows will close one of the last remaining plain-text domain name
transmissions in common web traffic," noted company in a post." Microsft
further <a href="https://circleid.us15.list-manage.com/track/click?u=71b27c0808a16ff6f58bfc4fc&id=0acb188067&e=a464e87593" target="_blank">added</a>:
"For our first milestone, we'll start with a simple change: use DoH for
DNS servers Windows is already configured to use. There are now several
public DNS servers that support DoH, and if a Windows user or device
admin configures one of them today, Windows will just use classic DNS
(without encryption) to that server. However, since these servers and
their DoH configurations are well known, Windows can automatically
upgrade to DoH while using the same server."</font> </font><br></p><font size="3" face="Tahoma">For commentary on the issue: <a href="https://www.zdnet.com/article/dns-over-https-causes-more-problems-than-it-solves-experts-say/" target="_blank">https://www.zdnet.com/article/dns-over-https-causes-more-problems-than-it-solves-experts-say/</a></font></td></tr><tr><td style="padding:10px 15px 0px;font-family:Helvetica,Arial,sans-serif;font-size:16px;line-height:24px;color:rgb(0,0,0);border-left:1px solid rgb(221,221,221);border-right:1px solid rgb(221,221,221)" bgcolor="#ffffff">Sam L.<br></td>
</tr>
<tr>
<td style="padding:7px 15px 15px;font-family:Verdana,Helvetica,Arial,sans-serif;font-size:12px;line-height:15px;color:rgb(102,102,102);border-bottom:1px solid rgb(221,221,221);border-left:1px solid rgb(221,221,221);border-right:1px solid rgb(221,221,221)" bgcolor="#ffffff"><br></td></tr></tbody></table></font></div>
</blockquote></div>