NSA advises companies to avoid third party DNS resolvers

Discussion in 'privacy problems' started by Minimalist, Jan 14, 2021.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
  2. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    I understand why US government agencies are told to use US government-backed DNS service, but advice for enterprise network’s is weird for me. SOHO, small and medium companies have really small IT resources, so operating crucial DNS service in secure manner is quite a burden. Mind it that you can chain recursive DNS resolvers, so internal domains may be resolved locally, but all other by external, third-party service. That external service also does some blocklist(thread feed)-based filtering and secures against some types of attacks on DNS system.
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Appears to me that 3rd party DNS resolver is OK as long as it uses encrypted DNS; e.g. Cloudflare, etc..
     
  4. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    Externaly hosted but owned and operated by enterprise staff.

    I will read rest of it later to check whether chaining enterprise DNS resolver to third-party is allowed.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.