Why You Should Enable Encrypted DNS
If you are unfamiliar with DNS, it’s recommended that you read my previous post What is DNS? and then read this one
Before we discuss encrypted DNS, there are few things that you should know about
Man in The Middle
The man in the middle is a third party that inserts itself between two parties trying to communicate over the Internet. Consider you are sitting in Cafe connected to it’s WiFi and are trying to access Google. In this case, you and Google are two parties trying to communicate over the Internet. Anyone who tries to intercept traffic between you and Google is the man in the middle. This man could be the Cafe owner, someone at your Internet Service Provider (ISP) or even a state actor.
Secure HTTP (HTTPS)
You must have come across the bank advisory to always use HTTPS. The reason behind it is simple: HTTPS encrypts all the traffic between you and the bank. So if someone tries to intercept your traffic all they would see is gibberish. That’s why they ask you to share your password on HTTPS connection only. Everything you browse on HTTPS is always secure and HTTPS is used everywhere today. With HTTPS, the only people who know about your online activity are you and owners of the website you are accessing.
A Misconception
There’s a common misconception that using HTTPS is enough to maintain your privacy and security over the Internet. HTTPS secures only the traffic between your browser and the server you are trying to access. But as discussed in What is DNS? post, DNS queries happen even before connecting to website server. The traffic between you and the DNS server is plain text. Any man in the middle can view your DNS traffic and thus determine what websites you are visiting. Granted they won’t see your activity on the website but leaking DNS data is still a nightmare privacy scenario.
Encrypted DNS
Above situation can be mitigated using protocols like DNS over HTTPS (DoH) or DNS over TLS(DoT). Today most operating systems support one or both the protocols. Once enabled these protocol secure your DNS traffic. Used along with HTTPS, your privacy and security is improved significantly.
WebShield supports both these protocols and provides additional functionality like blocking categories, scheduling on top of encrypted connection. WebShield provides this service for small premium but there are free DoH/DoT providers too. Of course with the free ones, you miss the blocking and scheduling part but it’s still better than plain DNS. Here is Google’s free DoH endpoint:
https://dns.google/dns-query
If you have reached this far, there’s no reason to still use plain DNS. Enable encrypted DNS on your and your families devices now! If you need help configuring DoH/DoT, reach out to me or drop me a mail at email below.