Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 10th, 2012, 08:39 PM
ncage1974 ncage1974 is offline
Infrequent Poster
 
Join Date: Dec 2009
Posts: 44
Default DNS ?

Just installed OpenDNS DNSCrypt for windows. I'm confused by an option that is automatically selected when you install DNSCrypt:
"Fall back to insecure DNS"?

What exactly is that? By the sound of it sounds like your dns queries are unencrypted. Is it misleading? Yet it says my status is "Protected". Can anyone clarify?

Also i assume dns is usually sent with UDP Packets? There is an option "DNSCrypt over TCP / 443 (Slower)" which i assume just means DNS will be sent over SSL which would be sent over SSL but if DNSCrypt actually works and is encrypted why would you need it?

For reference:
Enable OpenDNS: Checked
Enable DNSCrypt: Checked
DNS over TCP / 443 (slower): Unchecked
Fall back to insecure DNS: Checked
Status shows "Protected"
--which are all defaults.
  #2  
Old July 11th, 2012, 05:49 AM
Tomwa Tomwa is offline
Regular Poster
 
Join Date: Feb 2010
Posts: 160
Default Re: DNS ?

Quote:
Originally Posted by ncage1974
Just installed OpenDNS DNSCrypt for windows. I'm confused by an option that is automatically selected when you install DNSCrypt:
"Fall back to insecure DNS"?
If for whatever reason DNSCrypt is unable to make a successful query with encryption enabled it will resort to sending an unencrypted request to the OpenDNS servers. This is to prevent your internet from simply falling over dead should DNSCrypt stop functioning.

Quote:
Originally Posted by ncage1974
What exactly is that? By the sound of it sounds like your dns queries are unencrypted. Is it misleading? Yet it says my status is "Protected". Can anyone clarify?
If you have this option enabled then DNS queries won't fail if they aren't sent successfully while encrypted (For whatever reason) and will instead resort to a good-ole unencrypted DNS request. This shouldn't happen most of the time though I myself have disabled the option. Keep in mind DNSCrypt is still new and this option helps stability greatly (In fact I just fought with DNSCrypt a moment ago when it simply stopped handling DNS queries)

Quote:
Originally Posted by ncage1974
Also i assume dns is usually sent with UDP Packets? There is an option "DNSCrypt over TCP / 443 (Slower)" which i assume just means DNS will be sent over SSL which would be sent over SSL but if DNSCrypt actually works and is encrypted why would you need it?
DNS is usually sent of UDP Port 53. This is great but firewalls and other security programs can occasionally cause problems with requests. This is why the above option exists, port 443 isn't going to be as heavily restricted (since its used for secure HTTP) and may resolve the problems at the cost of speed.


Quote:
Originally Posted by ncage1974
For reference:
Enable OpenDNS: Checked
Enable DNSCrypt: Checked
DNS over TCP / 443 (slower): Unchecked
Fall back to insecure DNS: Checked
Status shows "Protected"
--which are all defaults.

I generally disable "Fall back to insecure DNS" as I prefer security over stability but I have encountered issues with DNSCrypt which I've had to solve on my own.

All your answers could be found here: https://www.opendns.com/technology/dnscrypt
__________________
KIS 2013 + LUA + SRP + SpywareBlaster + UAC Max + EMET Max + (Removed) Keyscrambler + Sandboxie + WinPatrol + PeerBlock + TrueCrypt (FDE 63 Char random ASCII key) + Tor (Privoxy + Polipo chain) + OpenDNS + HostsMan (MVPS + hpHosts (Ads/trackers)).

Last edited by Tomwa : July 11th, 2012 at 05:56 AM.
  #3  
Old August 7th, 2012, 10:15 AM
ncage1974 ncage1974 is offline
Infrequent Poster
 
Join Date: Dec 2009
Posts: 44
Default Re: DNS ?

Tomwa sorry for the long delayed reply but i really appreciate the thorough explanation.
  #4  
Old August 7th, 2012, 12:10 PM
jedisct1 jedisct1 is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: San Francisco, CA
Posts: 26
Default Re: DNS ?

Don't use the "fallback to insecure" option. If you care about security, don't use the UI at all. (this also applies to the Mac UI).
  #5  
Old August 7th, 2012, 12:25 PM
subhrobhandari subhrobhandari is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 241
Default Re: DNS ?

Quote:
Originally Posted by jedisct1
If you care about security, don't use the UI at all. (this also applies to the Mac UI).

Why so?
__________________
Realtime: Webroot SecureAnywhere Private Beta + Zemana Antilogger + HitmanPro Alert
On-Demand: Hitman Pro
Others: Router + EMET (Custom Conf.) + Fully Updated Windows 7 SP1 64Bit + Other Security Measures
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:38 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums