HomeSecurityApple adds support for encrypted DNS

Apple adds support for encrypted DNS

In a presentation at its developer conference this week, Apple announced that upcoming versions of its iOS and macOS operating systems will support the ability to handle encrypted DNS communications.

Apple said that iOS 14 and macOS 11, due for release this fall, will support both DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) protocols.

Normal DNS (Domain Name System) traffic is carried in clear text and has been used by internet service providers and others to track users in the past, usually to create profiles for sale to online advertisers.

However, DoH and DoT allow desktops, phones, or individual applications to make DNS queries and receive DNS responses in encrypted form, a feature that prevents third parties and malicious threat actors from monitoring a user's DNS queries and inferring the destination of web traffic.

To improve the privacy of iOS and macOS, Apple says it plans to add new features and functionality to its app development frameworks.

These new features will allow developers to create or update their existing applications and use DoH or DoT to encrypt DNS traffic.

Apple DNS

Apple says developers can create apps to apply DoH/DoT settings to the entire operating system (via network extension apps or MDM profiles), to individual apps, or to selected network requests within an app.

"There are two ways that encrypted DNS can be enabled," said Tommy Pauly, Apple Internet Engineer at Apple.

“The first way is to use a single [encrypted] DNS server as the default solution for all applications on the system. If you provide a public [encrypted] DNS server, you can now ‘write’ a network extension application that configures the system to use your server. Alternatively, if you use Mobile Device Management to configure corporate settings on devices, you can download a profile to configure encrypted DNS settings for your networks,” Pauly said.

“The second way to enable encrypted DNS is to choose it directly from within an application. If you want your application to use encrypted DNS, even if the rest of the system doesn’t, you can choose a specific server to use for some or all of your application’s connections,” Pauly added.

Additionally, Apple's DoH and DoT applications will also be aware of the context. For example, if a user has a VPN application installed or is part of a bonded (corporate) network, the DoH/DoT server will not override the DNS settings provided by the aforementioned.

Additionally, developers can also write “rules” to enable support for encrypted DNS communications only in specific situations or environments, such as when the user is using their mobile data network, a specific WiFi network that the user does not trust, or certain types of applications.

And in the event that a network provider blocks encrypted DNS communications on its network, Apple also plans to warn users so they can take other actions to maintain their privacy.

Apple joins Mozilla, Google and Microsoft, who have announced support for encrypted DNS communications in their respective products – Firefox, Chrome, Edge & Windows 10.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS