ISC StormCast for Thursday, December 10th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 December 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 10th, 2020 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich. |
| 0:09.6 | And I'm recording from Jacksonville, Florida. |
| 0:14.0 | Well, to start out with, we do have an interesting proposal put forward by Cloudflare, Apple, and Fastly to make DNS over |
| 0:25.1 | HDPS even more anonymous. |
| 0:28.3 | As far as privacy goes, the weak point of DNS over HTTP was that the recursive resolver, |
| 0:34.7 | for example, Cloudflare, the company that you pick to terminate your DNS |
| 0:40.1 | over HTTP requests, was still able, theoretically, to log all of these requests and |
| 0:47.0 | associated with a particular user via the user's IP address. This new protocol, which goes by the acronym ODOH or oblivious DNS over H-DPS, does solve the problem |
| 1:02.6 | by routing the requests via a proxy. |
| 1:07.1 | Now, the trick here is that only the endpoint, so your recursive resolver, is actually able to decrypt the message. |
| 1:16.4 | So in addition to TLS, we actually have an encrypted payload. |
| 1:21.0 | The proxy is only forwarding it. |
| 1:24.1 | So the purpose of the proxy here is to lose information about the origin of the DNS request. |
| 1:31.3 | To make this all work, the client will first request a public key from the DNS Resolver, |
| 1:39.3 | then use that public key to encrypt the request, also include the client's public key with that |
| 1:47.3 | encrypted request. The proxy will just forward this encrypted message. The Resolver now is able |
| 1:54.8 | to decrypt the message using the private key that only the Resolver has, creates the response, encrypts it again, |
| 2:02.5 | using the public key that the client sent along with the request and pass the message back. |
| 2:11.0 | There is only sort of experimental implementations of this at this point. Interestingly, Apple |
| 2:16.6 | is cooperating with Cloudflare on this proposal, |
| 2:21.1 | so very likely we'll see this show up in Apple's operating systems in the future. Apple has been |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

