Author Topic: DNS over HTTPS  (Read 1450 times)

0 Members and 1 Guest are viewing this topic.

Offline loungehake

  • Dummy Half
  • Poster
  • *
  • Posts: 426
  • Come on lad! You've only got 70 yards to go.
DNS over HTTPS
« on: April 29, 2023, 10:38:56 AM »
Does Avast have any problems with DNS over HTTPS?
Windows 10 Pro 22H2 x64, Avast Free 24.3.6108, Malwarebytes Anti-Exploit, Malwarebytes Anti-Ransomware

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: DNS over HTTPS
« Reply #1 on: April 29, 2023, 12:43:55 PM »
Not much to work with here:
Is there a specific DNS that is involved in the problem  ?
Is there a particular site that is effected  ?
Are you getting and Avast alert or other browser error message  ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline loungehake

  • Dummy Half
  • Poster
  • *
  • Posts: 426
  • Come on lad! You've only got 70 yards to go.
Re: DNS over HTTPS
« Reply #2 on: May 01, 2023, 09:28:23 AM »
Hi David.  It's a question of encryption impairing Avast's detection of bad web sites.  Encrypting DNS traffic enhances privacy but might have the downside of helping rogue web sites elude detection by such as Avast.
Windows 10 Pro 22H2 x64, Avast Free 24.3.6108, Malwarebytes Anti-Exploit, Malwarebytes Anti-Ransomware

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: DNS over HTTPS
« Reply #3 on: May 01, 2023, 01:00:18 PM »
Well encryption shouldn't impact Avast detection abilities as the site in itself 'isn't encrypted' only the traffic between your computer and the site is encrypted/secured to prevent snooping.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline loungehake

  • Dummy Half
  • Poster
  • *
  • Posts: 426
  • Come on lad! You've only got 70 yards to go.
Re: DNS over HTTPS
« Reply #4 on: May 02, 2023, 09:41:36 PM »
I guess that what you are saying is that Avast decrypts all traffic received over TLS connections and that includes DNS over HTTPS.  I am confident in my belief that Avast does this.

Some argue that DNS over HTTPS prevents some antimalware software from identifying rogue Internet players and that this is why DNS traffic sent/received in clear ensures identification of those rogues.
Windows 10 Pro 22H2 x64, Avast Free 24.3.6108, Malwarebytes Anti-Exploit, Malwarebytes Anti-Ransomware

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: DNS over HTTPS
« Reply #5 on: May 02, 2023, 10:04:27 PM »
The encryption is done at the point of origin, if you connect to an https URL it creates a secure connection, so traffic between your system and the site is secure. 

You also set Avast to scan HTTPS and other secure means of connection and other pages in the Web Shield settings.  For the most part these would be preselected.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Mr. Consumer

  • Full Member
  • ***
  • Posts: 134
Re: DNS over HTTPS
« Reply #6 on: May 03, 2023, 10:10:05 AM »
I use DNS Over HTTPS system-wide and also in the browser in my test browsers. It doesn't affect the protection provided by Avast's Web Shield. So you can use DoH without any issue :)

Offline loungehake

  • Dummy Half
  • Poster
  • *
  • Posts: 426
  • Come on lad! You've only got 70 yards to go.
Re: DNS over HTTPS
« Reply #7 on: May 04, 2023, 12:54:27 PM »
Thanks. That's how I see it.
Windows 10 Pro 22H2 x64, Avast Free 24.3.6108, Malwarebytes Anti-Exploit, Malwarebytes Anti-Ransomware