OpenDNS Releases Encryption For All DNS Traffic

Domain Name System (DNS) services provider OpenDNS has released an open-source tool to encrypt DNS traffic to protect network connections between the user’s computer and the company’s servers.

The DNSCrypt tool is designed to secure plain-text DNS traffic and protect users from man-in-the-middle attacks, OpenDNS said. The DNS protocol acts as a phone directory for the Web, translating domain names into the actual IP addresses of the server the site is hosted on. With DNS, users don’t have to remember the numeric addresses.

Vulnerable DNS

Security experts have long warned that the DNS infrastructure was vulnerable to attack and needed to be secured. The “inherent weaknesses” in the architecture meant that attackers could intercept and redirect users to malicious sites, or eavesdrop on user activity through a man-in-the-middle attack, Melih Abdulhayoglu, CEO and chief security architect of Comodo, told eWEEK recently.

A recent F5 Networks report found that DNS attacks were the most frequent type of attacks faced by organisations. They are also the most difficult to defend against and have the highest impact on enterprises, according to the report.

“DNS has, unfortunately, always had some inherent weaknesses because it’s transported in plain-text,” David Ulevitch, OpenDNS CEO, wrote in a blog post announcing the DNSCrypt tool.

While there has been some effort to secure DNS, there hasn’t been much work done on the “last mile,” of the connection between the client machine and the Internet service provider or the DNS provider, according to Ulevitch. The “last mile” is when “bad things”, such as snooping, tampering and hijacking traffic, are “most likely to happen”, Ulevitch wrote. It’s also “ripe” for man-in-the-middle attacks, especially if the user is on an insecure network at a coffee shop, for example.

Encryption foils surveillance

Encrypting all DNS traffic is a fundamental change that improves security because it prevents anyone eavesdropping on Internet activity from seeing what Websites the user is visiting or modifying traffic, Ulevitch said. DNSCrypt uses elliptic-curve cryptography to encrypt traffic between customers’ servers and the OpenDNS servers.

DNSCrypt would effectively make most forms of DNS censorship obsolete and thwart surveillance systems trying to impose censorship, said security researcher Jacob Appelbaum.

According to Ulevitch, DNSCrypt is a “very strong first step” and is not intended to replace DNSSEC, the security protocol designed to verify and validate domain names.

DNSSEC is being deployed by many registrars to guard against DNS tampering. It uses public key cryptography to digitally “sign” DNS records for Websites to prevent tampering and cache poisoning. DNSSEC provides a way to verify that the server listed in the DNS record is actually the one the domain owner specified.

“Even if everyone in the world used DNSSEC, the need to encrypt all DNS traffic would not go away,” the company wrote on the FAQ page for DNSCrypt.

The company suggested that DNSCrypt is similar to Secure Sockets Layer in that it encrypts DNS traffic in the same way SSL wraps HTTP traffic. DNSCrypt would wrap DNS traffic and DNSSEC would sign and validate a subset of that traffic, according to the FAQ.

Currently available only for Mac OS X, OpenDNS also released DNSCrypt’s source code. It is still a “technology preview” and the company will be updating the code as needed, according to Ulevitch.

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Share
Published by
Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

Elon Musk’s X Head Of Global Affairs Resigns

X's global affairs head, Nick Pickles, confirms departure after a decade working at the platform…

1 day ago

CMA Halts Probe Into Microsoft’s Inflection AI Staff Hiring

British competition regulator closes investigation into Microsoft's hiring of Inflection AI staff, which it deems…

2 days ago

Telegram’s Pavel Durov Speaks Out Against French Charges

First public response made by Telegram CEO Pavel Durov, after arrest in France over alleged…

2 days ago

US Probes Four-Vehicle Crash Involving AI Driver Assistance

US authorities probe fatal four-vehicle crash caused by Ford Mustang Mach-E electric vehicle using BlueCruise…

3 days ago

Vestager To Step Down As EU Competition Chief

Margrethe Vestager set to step down as EU competition commissioner after a decade in office…

3 days ago

EU Seeks Industry Views On Google DMA Compliance

EU regulators to seek views from industry players on Google's DMA compliance plans ahead of…

3 days ago