Oblivious DNS - Simply Explained

  Рет қаралды 18,397

Simply Explained

Simply Explained

3 жыл бұрын

Oblivious DNS is a privacy-friendly version of the DNS protocol. Preventing third-parties from keeping track of the sites you visit.
It builds on top of DoH (DNS over HTTPS) and adds a proxy server to prevent tracking. It was developed by Cloudflare, Apple and Fastly.
Currently, ODNS is not yet widely supported, but that could quickly change! Especially if Apple would push it to their iOS and macOS customers.
🎶 Music
"Lost Feelings" by Helena Decuyper:
/ project-34-1
🌍 Social
Twitter: / savjee
Facebook: / savjee
Blog: savjee.be
💌 Newsletter: newsletter.savjee.be (no more than once a month)
❤️ Become a Simply Explained member:
/ @simplyexplained
📚 Sources used to make this video:
savjee.be/videos/simply-expla...

Пікірлер: 44
@asjadmotara
@asjadmotara 3 жыл бұрын
Amazing work. Simple, elegant and something new to learn that remain in memories forever because of your easy to understand explaination.
@juliocesar-bz4on
@juliocesar-bz4on 2 жыл бұрын
Hi! I´m from Brazil and I love technology. Great explanation. I´m newcomer here. You got a new subscribed. Congrats!
@ThorstenStaerk
@ThorstenStaerk 3 жыл бұрын
Great how you make us understand! In my simple words - instead of trusting technology, with ODNS, you have to trust organization. You have to trust that the proxy and the ODNS server's org do not talk to each other.
@ayushpratap4726
@ayushpratap4726 3 жыл бұрын
Savee we missed you for so long !
@simplyexplained
@simplyexplained 3 жыл бұрын
My last video was 2 weeks ago ;)
@ayushpratap4726
@ayushpratap4726 3 жыл бұрын
@@simplyexplained oops ! My bad Yeah I saw that No SQL one ! Actually your content is highly anticipated that's why ;p
@zyansheep
@zyansheep 3 жыл бұрын
Notice: ISPs can still do reverse DNS lookups on IP addresses you connect to. This is *not* a replacement for Tor. Also I'm kinda suspicious about these proxy servers. If the organization who runs the DNS resolver also runs the proxy server, they can still figure out who you are and what websites you visit.
@simplyexplained
@simplyexplained 3 жыл бұрын
Yes, I did mention that both should be independently operated. Also: valid remark about the ISP's! They still see everything if they really want.
@mohamadrezapirayesh3811
@mohamadrezapirayesh3811 2 жыл бұрын
Great job thanks !
@rajtiwari665
@rajtiwari665 2 жыл бұрын
Well explained
@BloodnutXcom
@BloodnutXcom 3 жыл бұрын
Dns is always a balancing act. On the one hand, you want yo have control over your own devices through your router by, for example, blackholing some domain. But on the other hand you don't want third parties snooping on your request.
@gamedit2999
@gamedit2999 3 жыл бұрын
So if i ise this, my isp will not see the sites i visit? Or there is another ways that isp use to see my visit history?
@daniiln.9468
@daniiln.9468 7 ай бұрын
Does VPN help to hide the user’s IP from the DNS resolver and therefore solve the problem of the user’s identity exposure?
@dAtramt
@dAtramt 3 жыл бұрын
Haha. At 1:40 those Bitcoin bag emojis imply ISPs are selling browser our history history for Bitcoin.
@winwin-gw7rn
@winwin-gw7rn 3 жыл бұрын
why don’t put chain proxy servers just like tor
@mich2k1
@mich2k1 10 ай бұрын
Does this hide infos as SNI too?
@SochSumeet
@SochSumeet 3 жыл бұрын
😎🤟
@ahmedelwan9129
@ahmedelwan9129 3 жыл бұрын
what if the proxy and odns own by same company :D
@simplyexplained
@simplyexplained 3 жыл бұрын
That's what I said at the end. The only way it works, is if these two are independent.
@ilsunnylo3562
@ilsunnylo3562 3 жыл бұрын
So you are never safe.
@gsichtsgrabII
@gsichtsgrabII 3 жыл бұрын
Would Blockchain solve this problem?
@joefox9875
@joefox9875 3 жыл бұрын
Usually blockchain solutions are about connecting information, whereas I think if you want to be more private you want to be 'off the chain'
@quintaeco
@quintaeco 3 жыл бұрын
to protect against the man in the middle by implementing DNSSec
@happy91997
@happy91997 3 жыл бұрын
What's the weird music, sounds like some ghost is screaming
@simplyexplained
@simplyexplained 3 жыл бұрын
Link is in the description ;)
@johnmarks3650
@johnmarks3650 2 жыл бұрын
Terrible idea. So now if I want to exfiltrate data via a DNS tunnel I can encrypt the whole thing from end-to-end. I set my bot to use my proxy service and my my termination server. I have just bypassed a number of security tools and once it is past the proxy, you cannot even discover the source of the breach. Adversaries are going to have a hey-day with this. There are reasons the EU providers are banning Apple private relay, this is one of them. Second, who ever controls the termination server controls all. In the case of Apple private relay (Apple+Cloudflare) while they cannot see the origin IP, they still can set policy on what is being browsed, giving preferred partners quicker responses. I am not saying Apple will do this, but at some point an unscrupulous eventually entity will. Third, what happens when Governmental entities. what access to DNS queries/responses for a terrorist investigation, will this even survive or will it be legislated out of existence..
@andreujuanc
@andreujuanc 3 жыл бұрын
Not green anymore ;)
@logangraham2956
@logangraham2956 3 жыл бұрын
you forgot something.... [your device] -> [ISP] -> [proxy server] -> [ISP] -> [ODNS] -> [ISP] -> [proxy server] -> [ISP] -> [your device] you notice something :) the ISP has access to all the data along the entire chain . so really it doesn't matter.
@zyansheep
@zyansheep 3 жыл бұрын
The data going between proxy, odns and you isn't the issue (b.c. it's encrypted) the issue is that ISPs still know exactly what IP addresses you connect to. (Which they can then lookup the DNS address of using reverse DNS)
@logangraham2956
@logangraham2956 3 жыл бұрын
@@zyansheep the data is still a problem . it might not be readable but it still exists if i was the isp id follow the data from your device to the proxy. then follow the data as it leaves the proxy to the dns. and then obtain a copy of the ip address as it leaves the dns to go back to the proxy. and then follow the data back to your device. i just obtain the ip address you will go to and your device... tell me again why this entire process was useful XD.
@zyansheep
@zyansheep 3 жыл бұрын
@@logangraham2956 how would the ISP "follow the data"? The data is encrypted between the device, proxy, and dns server. The best they could do would be packet timing correlation which is incredibly difficult to pull off (and wouldn't tell them anything anyway unless they controlled the DNS server) Also I never said this process was useful, imo this just allows Cloudflare and Apple to spy on their users more. ISPs can get around this easily with reverse DNS lookups.
@logangraham2956
@logangraham2956 3 жыл бұрын
@@zyansheep its encrypted but it still exists
@logangraham2956
@logangraham2956 3 жыл бұрын
@@zyansheep your forgetting that it is their switch you go through to get to anything at all. do you not think they could see the packets encrypted or not.
@gurufrom212
@gurufrom212 3 жыл бұрын
First comment
@trappedcat3615
@trappedcat3615 3 жыл бұрын
First reply to Frist comment
@simplyexplained
@simplyexplained 3 жыл бұрын
😆
@zyansheep
@zyansheep 3 жыл бұрын
Nice
@quintaeco
@quintaeco 3 жыл бұрын
find a dns services that does not use any big tech services
@quintaeco
@quintaeco 3 жыл бұрын
NEVER TRUST BIG TECH
Oblivious Transfer - Computerphile
20:15
Computerphile
Рет қаралды 52 М.
Indian sharing by Secret Vlog #shorts
00:13
Secret Vlog
Рет қаралды 62 МЛН
Eccentric clown jack #short #angel #clown
00:33
Super Beauty team
Рет қаралды 30 МЛН
DNS Cache Poisoning - Computerphile
11:04
Computerphile
Рет қаралды 297 М.
IPFS: Interplanetary file storage!
9:15
Simply Explained
Рет қаралды 334 М.
DNS Encryption explained - DNS over TLS (DoT) & DNS over HTTPS (DoH)
12:21
Zero Knowledge Proof - ZKP
10:18
Simply Explained
Рет қаралды 186 М.
DNS: Domain Name System - Explained!
7:23
Simply Explained
Рет қаралды 12 М.
You want a real DNS Server at home? (bind9 + docker)
32:31
Christian Lempa
Рет қаралды 238 М.
Tor vs VPN | What's the Difference? (and which should you use?)
8:18
All Things Secured
Рет қаралды 672 М.
The Serverless Hype Explained!
7:08
Simply Explained
Рет қаралды 104 М.
How DNS Works
10:10
Mental Outlaw
Рет қаралды 13 М.
Solid - A Better Web (Simply Explained)
7:21
Simply Explained
Рет қаралды 61 М.
С Какой Высоты Разобьётся NOKIA3310 ?!😳
0:43
Main filter..
0:15
CikoYt
Рет қаралды 1,3 МЛН
Где раздвижные смартфоны ?
0:49
Не шарю!
Рет қаралды 599 М.