Unencrypted DNS traffic between users and DNS resolvers can lead to privacy and security concerns. In response to these privacy risks, many browser vendors have deployed DNS-over-HTTPS (DoH) to encrypt queries between users and DNS resolvers. Today, many client-side deployments of DoH, particularly in browsers, select between only a few resolvers, despite the fact that many more encrypted DNS resolvers are deployed in practice. Unfortunately, if users only have a few choices of encrypted resolver, and only a few perform well from any particular vantage point, then the privacy problems that DoH was deployed to help address merely shift to a different set of third parties. It is thus important to assess the performance characteristics of more encrypted DNS resolvers, to determine how many options for encrypted DNS resolvers users tend to have in practice. In this paper, we explore the performance of a large group of encrypted DNS resolvers supporting DoH by measuring DNS query response times from global vantage points in North America, Europe, and Asia. Our results show that many non-mainstream resolvers have higher response times than mainstream resolvers, particularly for non-mainstream resolvers that are queried from more distant vantage points -- suggesting that most encrypted DNS resolvers are not replicated or anycast. In some cases, however, certain non-mainstream resolvers perform at least as well as mainstream resolvers, suggesting that users may be able to use a broader set of encrypted DNS resolvers than those that are available in current browser configurations.
翻译:用户和 DNS 分辨率解析器之间未加密的 DNS 流量在用户和 DNS 分辨率解析器之间可以导致隐私和安全关切。 针对这些隐私风险, 许多浏览器供应商已经部署了 DNS over- HTTPS (DoH) 来加密用户和 DNS 分辨率解析器之间的查询。 今天, 许多 DH 的客户端部署, 特别是在浏览器中, 只选择几个解析器, 尽管在实际操作中部署了更多加密的 DNS 分辨率解析器。 不幸的是, 如果用户只有很少选择加密的解析器, 并且只有少数能从任何特定的偏好点很好地处理。 然后, 许多 DH 被应用来帮助解决的私隐性问题, 仅帮助转换到不同的第三方。 因此, 有必要评估更多加密 DNS 分辨率解析器的性能特性, 以确定加密的 DNS 解析器用户在实际操作中有多少选项。 在本文中, 我们探索一大批加密的 DNS 解析器的性能通过测量 DNS 查询时间, 在北美、 欧洲和亚洲的可选取的选取的选点, 许多非流流解解解解器的解的解器中, 的解解的解的解者在不甚甚甚甚甚甚甚甚甚甚 的解的解的解的解的解的解的解的解的解解解解的解的解的解的解算器中, 。