Cloudflare and Apple launch privacy-focused DNS protocol

Oblivious DNS-over-HTTPS safeguards users' browsing habits from third parties

Cloudflare has proposed a DNS standard, co-authored with Apple, that aims to further improve internet privacy.

ODoH, which stands for Oblivious DNS-over-HTTPS, was developed by engineers from Cloudflare, Apple, and Fastly and works by separating IP addresses from queries in order to safeguard users’ browsing habits from third parties, including internet service providers.

The tool works by encrypting a DNS query and passing it through a proxy server between the user and the website they intend on visiting. Due to the DNS query being encrypted, the proxy has no way of identifying its contents and even prevents the DNS resolver from specifying who is the sender of the query. 

That is why the ‘O’ in ODoH stands for ‘oblivious’, because, as Cloudflare engineers Sudheesh Singanamalla and Tanya Verma explained on the company’s blog, “the target only knows about the proxy, the target and any upstream resolver are oblivious to the existence of any client IP addresses”.

“This puts clients in greater control over their queries and the ways they might be used. For example, clients could select and alter their proxies and targets any time, for any reason,” they added.

According to Cloudflare, ODoH does not negatively impact performance in any way, making prioritising privacy easier for its users.

The tool was launched with Cloudflare’s proxy partners, including PCCW, SURF, and Equinix. SURF technical product manager Joost van Dijk described the move to ODoH as “a true paradigm shift, where the users’ privacy or the IP address is not exposed to any provider, resulting in true privacy”. 

“With the launch of ODoH-pilot, we’re joining the power of Cloudflare’s network to meet the challenges of any users around the globe. The move to ODoH is not only a paradigm shift but it emphasizes how privacy is important to any users than ever, especially during 2020. It resonates with our core focus and belief around Privacy,” he added.

DNS-over-HTTPS has been met with some controversy in the UK due to its conflict with the Investigatory Powers Act, which requires that ISPs at least have the ability to capture information about their customers if so required by the state.

Featured Resources

Choosing a collaboration platform

Eight questions every IT leader should ask

Download now

Performance benchmark: PostgreSQL/ MongoDB

Helping developers choose a database

Download now

Customer service vs. customer experience

Three-step guide to modern customer experience

Download now

Taking a proactive approach to cyber security

A complete guide to penetration testing

Download now

Recommended

Unsecured cloud storage led to data exposure at New England energy company
data protection

Unsecured cloud storage led to data exposure at New England energy company

22 Apr 2021
Geico data breach leads to stolen driver’s license numbers
data breaches

Geico data breach leads to stolen driver’s license numbers

21 Apr 2021
1Password targets enterprise customers with Secrets Automation
IT infrastructure

1Password targets enterprise customers with Secrets Automation

14 Apr 2021
The definitive guide to IT security
Whitepaper

The definitive guide to IT security

9 Apr 2021

Most Popular

REvil threatens to release Apple’s hardware schematics
ransomware

REvil threatens to release Apple’s hardware schematics

21 Apr 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021
Samsung Galaxy S21 Ultra review: Ultra in every sense of the word
Mobile Phones

Samsung Galaxy S21 Ultra review: Ultra in every sense of the word

22 Apr 2021