republican-creole
site Search:


 
   
story category
OpenDNS Releases DNSCrypt
Traffic Encryption For Added Security
by Karl Bode Thursday 08-Dec-2011 tags: business · security · software
Tipped by state See Profile
OpenDNS this week announced that the company is offering yet another service to customers -- this one dubbed DNSCrypt. As the name suggests, DNSCrypt is free software that encrypts all traffic between your computer and OpenDNS, preventing snooping, spying and man-in-the-middle attacks, and boosting both privacy and security -- particularly when on the go and using a mobile hotspot.

"Our hope and expectation is that this will become what SSL is to HTTP," OpenDNS says in a statement to Broadband Reports. Over at the OpenDNS blog, company CEO David Ulevitch makes a few comments on why they created the new software:

DNSCrypt changes this and has the potential to completely revolutionize Internet security. DNS has, unfortunately, always had some inherent weaknesses because it’s transported in plain text. DNSSEC has never attempted to address that (crazy, I know). Encrypting all DNS traffic means a fundamental change to the security of the system on the whole and a strong improvement. It’s not the only solution, and there’s still an important place for verification and validation of domains like DNSSEC provides, but it’s a very strong first step.

Those interested in giving the software a try can download DNSCrypt beta here, though sadly it's Mac-only at the moment.

view: topics flat text 
Post a:

WilTarbuckle

@waltersgolf.com

Mac Only?

Surprising...

vpoko
Premium
join:2003-07-03
Boston, MA

Usefulness

I can see how this would be useful to prevent a fake IP address from being returned by someone in the position to pull off a man-in-the-middle attack (e.g., hotspot operator). But it won't prevent that party from knowing which sites you're visiting, since they can reverse-DNS the domain name from the IP address, which they will have when you access the site (even if over SSL).

Romney2012
Defeat Obama 2012-Chg we can believe in
Premium
join:2002-03-03
USA
kudos:4

1 edit

Will only work on Mac computer for now

If you read the OpenDNS web site you will see the DNSCrypt software will only work on Mac computers for now. Windows later. And other devices like tablets and smartphones - who knows when.

Noah Vail
Son made my Avatar
Premium
join:2004-12-10
Lorton, VA
kudos:1
Reviews:
·Bright House
·Sprint Mobile Br..

1 edit

Mixed Bag

I see another utility to consume user resources. At least the user knows what this one is doing.

and

I've sniffed WAN side DNS traffic. There's a lot of information for that location - but not which user is generating it.

It's less clear who would get the sort of access it would take to capture those packets.

edit - re: vpoko See Profile's post... I wasn't considering mobile users.
It's a good point.

NV
--
Adopting other people's animosity is The New Stupid.
treichhart

join:2006-12-12

Its only for mac for right now

Per the website its only available for mac's for right now.

cableties
Premium
join:2005-01-27
Reviews:
·Verizon FiOS

Sadly?

Keep your panties on there, karl!

So its for the mac "at this moment". SO!
It will be out for the PC soon.

Besides, how many Mac users ACTUALLY use OpenDNS and are looking for encrypted.... hey... hmmmm... I have a mac...
--
Splat

nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse

What's the point?

DNSSEC protects your security with the use of digital signature that can ensure that you have the correct DNS results.

DNSCrypt seems to do little more than encrypt the transmission of data that is already in the public domain.

I guess this helps OpenDNS gain a monopoly on the sale of your browsing habits for profit.
--
AT&T Uverse; Zyxel NBG334W router (behind the 2wire gateway); openSuSE 12.1; firefox 8.0

vpoko
Premium
join:2003-07-03
Boston, MA

Re: What's the point?

Are you sure that's how DNSCrypt works? I'm not asking to argue, I'm really not sure.

Public key encryption can be used in few ways. If OpenDNS encrypts the data using a public key that you generate, and you decrypt it with your private key, that encrypts the data but doesn't confirm authenticity (because anyone could have used your public key to encrypt data).

On the other hand, if they use a private key that they generated to encrypt the data they send, and you use the corresponding public key to decrypt it, it doesn't protect the data (since anyone has the public key to decrypt it) but it dues authenticate it since only the possessor of the private key could have generated that cyphertext.

I'm not sure how OpenDNS' system works, but I would hope it's the latter.

nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse

Re: What's the point?

said by vpoko:

Are you sure that's how DNSCrypt works? I'm not asking to argue, I'm really not sure.

I am crudely assuming that the encrypted channel between you and openDNS is perfect.

At best, that can protect traffic between you and openDNS. However, openDNS is not an authoritative supplier of DNS data. If you use DNSSEC, then you are checking the authentication signature from the authoritative originator of the data.
--
AT&T Uverse; Zyxel NBG334W router (behind the 2wire gateway); openSuSE 12.1; firefox 8.0
GraysonPeddi

join:2010-06-28
Tallahassee, FL
So since I use BIND9 as a DNS Server and resolver (no forwarders in my DNS server), all I have to do is enable DNSSEC in the options {}; section, am I right?

»dnssec.surfnet.nl/?p=402

I am using Debian Sid+Experimental.

--
Current Soft Phone (temp): Ekiga (ordered Yealink T22P to switch from Ekiga)
Phone System: Asterisk 1.8; Server: Ubuntu Server 10.04 with Windows Server 2008 R2 Standard as guest

dvd536
as Mr. Pink as they come
Premium
join:2001-04-27
Phoenix, AZ
kudos:4
said by nwrickert:

I guess this helps OpenDNS gain a monopoly on the sale of your browsing habits for profit.

ding ding ding. we have a winner!
--
Oh YES! let me drop everything i'm doing regardless of who it affects to deal with your petty little problem!

Sircolby45

join:2005-11-26
Reviews:
·WildBlue
said by nwrickert:

I guess this helps OpenDNS gain a monopoly on the sale of your browsing habits for profit.

Now you know why they released it for Macs first. Aim for the most gullible first. Hey guys look at this. It will make you more "secure" than everybody else. You must have it!
--
[IMG]»img218.imageshack.us/img218/2636···3dg6.gif
Windows 7 Pro 64-Bit / Core i5 - 760 / GTX 460 1GB SLI / 8GB DDR3 RAM / Vertex 2 120GB SSD
JigglyWiggly

join:2009-07-12
Pleasanton, CA

Re: What's the point?

mac only? How odd.

cork1958
Cork
Premium
join:2000-02-26

Re: What's the point?

said by JigglyWiggly:

mac only? How odd.

Exactly what I thought. Why in the world would they make it for Mac only, first?

said by Sircolby45:

said by nwrickert:

I guess this helps OpenDNS gain a monopoly on the sale of your browsing habits for profit.

Now you know why they released it for Macs first. Aim for the most gullible first. Hey guys look at this. It will make you more "secure" than everybody else. You must have it!

Yep,
That's the reason why. I'll just stick with my own DNS servers, if you don't mind. Don't like OpenDNS anyway.
--
The Firefox alternative.
»www.mozilla.org/projects/seamonkey/

Noah Vail
Son made my Avatar
Premium
join:2004-12-10
Lorton, VA
kudos:1
Reviews:
·Bright House
·Sprint Mobile Br..

Re: What's the point?

said by cork1958:

I'll just stick with my own DNS servers, if you don't mind. Don't like OpenDNS anyway.

Me too. Unbound employs DNSSEC natively, it's all I install anymore.

NV
--
Adopting other people's animosity is The New Stupid.

sykl0ps
Premium
join:2011-06-23
Gainesville, FL
Seems like an interesting way to do a limited beta test to me. Only mac while they see how their servers respond, if all is well, let loose the windows version.

diontaz

@comcast.net

Not only for Mac

The code is open source and it works only on Linux and BSD: »github.com/opendns/dnscrypt-proxy

The whole point, unlike the name suggests, is that queries and replies are also authenticated.

The OSX package is more recent on Github too: »github.com/opendns/dnscrypt-osx-···ownloads

Monday, 04-Jun 22:20:50 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.