{"id":18410,"date":"2019-04-11T11:31:12","date_gmt":"2019-04-11T10:31:12","guid":{"rendered":"https:\/\/www.ispreview.co.uk\/?p=18410"},"modified":"2019-04-22T09:00:02","modified_gmt":"2019-04-22T08:00:02","slug":"big-uk-broadband-isps-have-big-concerns-about-dns-over-https","status":"publish","type":"post","link":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html","title":{"rendered":"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS"},"content":{"rendered":"<p>A significant change is on the way that could improve the security of the internet&#8217;s Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although this could also create lots of new problems for broadband ISPs and mobile operators (e.g. disrupting UK Government required censorship systems) that may be hard to overcome.<!--more--><\/p>\n<p>At present the existing <strong>Domain Name System<\/strong> (DNS) works to convert Internet Protocol (IP) addresses into a human readable form (e.g. 123.56.32.1 to examplefakeblah.co.uk) and back again. Most of the time your ISP runs the DNS servers, but advanced end-users can also tweak their own devices (e.g. routers) to use third-party DNS solutions like OpenDNS or Google&#8217;s Public DNS (i.e. taking some control away from your ISP but as these services are often unencrypted then your ISP can still intercept the data).<\/p>\n<p>Unfortunately standard DNS systems do have plenty of vulnerabilities, such as situations where hackers can intercept your internet traffic through man-in-the-middle style attacks (e.g. eavesdropping, manipulation of DNS data or even blocking\/censorship). Malicious actors target this method because end-users are often left none the wiser when it occurs (a very stealthy vulnerability to exploit).<\/p>\n<p>In order to resolve this a new standard is being fast-tracked through the IETF called <a href=\"https:\/\/datatracker.ietf.org\/wg\/doh\/charter\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>DNS over HTTPS<\/strong><\/a> (DoH). Anybody with some basic IT knowledge will recognise HTTPS as being the encrypted protocol that many modern websites use to help keep your connection to them secure from prying eyes (e.g. https:\/\/www.ispreview.co.uk is encrypted, while using http:\/\/ would be unencrypted).<\/p>\n<p>The idea behind DoH is thus a simple one, with DNS requests being sent via HTTPS, sharing port 443 and secured via TLS as defined in <a href=\"https:\/\/datatracker.ietf.org\/doc\/rfc8484\/\" target=\"_blank\" rel=\"noopener noreferrer\">IETF RFC 8484<\/a>. The result is an encryption based protocol that has good privacy and security intentions, which is something that broadband ISPs do welcome as being of wider benefit to their users. This is of course assuming you trust the third-party DoH providers (see below).<\/p>\n<h3><span style=\"color: #339966;\"><strong>Sounds good, so what&#8217;s the problem with DoH?<\/strong><\/span><\/h3>\n<p>In order to work its magic DoH needs to function a bit differently from the normal DNS system and early adoption of this is also likely to be driven through centralised 3rd party DoH providers (e.g. Google, Cloudflare and Mozilla), effectively bypassing wider ISP capabilities that are dependent upon the existing DNS setup.<\/p>\n<p>For example, Mozilla&#8217;s <strong>Firefox<\/strong> browser (since v62) has implemented DoH to automatically handle your DNS requests, although at present it&#8217;s not enabled by default (you have to activate it manually), but in the future that will change (developments around the DoH standard are still somewhat of a work-in-progress but we&#8217;d expect many more companies to follow).<\/p>\n<p>In this setup the end-user (that&#8217;s you, dear reader) no longer has to worry about manually configuring their DNS settings to use a third-party provider. Instead the system is both encrypted and handled automatically by your web browser or other system. Essentially a significant security and privacy improvement, albeit without you having to do anything to benefit!<\/p>\n<blockquote class=\"bq1\"><p><strong>Firefox Statement<\/strong><\/p>\n<p>For more than 30 years, DNS has served as a key mechanism for accessing sites and services on the web. Browsers (including Firefox) use DNS to access a distributed database that turns URLs into TCP\/IP addressing information. Firefox cannot do much without the service. DNS hails from the days of a kinder, more gentle Internet where it was normal to make this kind of query using unencrypted protocols and send them to any nearby server who claimed to be able to answer it.<\/p>\n<p>This approach is no longer a fit for the modern Internet. Because there is no encryption, other devices along the way might collect (or even block or change) this data too. DNS lookups are sent to servers that can spy on your website browsing history without either informing you or publishing a policy about what they do with that information.<\/p><\/blockquote>\n<p>The downside of this approach to DoH (if you can call it a downside, as for others it&#8217;s more of an upside), at least from an ISP&#8217;s perspective, is that your DNS queries won&#8217;t hit the broadband provider&#8217;s own nameservers anymore and the provider itself would also struggle to separate out DoH from regular HTTPS traffic.<\/p>\n<div align=\"center\"><img decoding=\"async\" class=\"ngg-singlepic ngg-none\" src=\"https:\/\/www.ispreview.co.uk\/wp-content\/gallery\/2019-article-illustrations\/dns_vs_doh_bt_isp_diagram.png\" alt=\"dns vs doh bt isp diagram\" width=\"100%\" \/><br \/>\n<strong><a href=\"https:\/\/indico.uknof.org.uk\/event\/46\/contributions\/668\/attachments\/898\/1109\/UKNOF43_Potential_ISP_challenges_with_DNS_over_HTTPS_Issue_1A_050419.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">BT Diagram of DNS vs DoH<\/a> &#8211; <a href=\"https:\/\/www.uknof.org.uk\/\" target=\"_blank\" rel=\"noopener noreferrer\">UKNOF Slide<\/a><br \/>\n<\/strong><\/div>\n<p>On top of that each application (e.g. Firefox) would now be able to select their own DoH provider, as opposed to a single ISP \/ DNS setting being used by the majority of users for every application and device. The DoH approach can thus create a number of problems with network management and control, particularly for the largest ISPs like <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/britishtelecom\" rel=\"nofollow\" target=\"_blank\">BT<\/a>, <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/bskyb\" rel=\"nofollow\" target=\"_blank\">Sky Broadband<\/a>, <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/tt\" rel=\"nofollow\" target=\"_blank\">TalkTalk<\/a> and <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/vm\" rel=\"nofollow\" target=\"_blank\">Virgin Media<\/a>.<\/p>\n<h3><span style=\"color: #339966;\"><strong>Now it gets complicated<\/strong><\/span><\/h3>\n<p>The ability to see browsing \/ application requests at a household level means that many ISPs can make some use of standard DNS for performing tasks like <strong>internet filtering<\/strong> (i.e. blocking \/ censoring websites &#8211; such as due to parental controls and anti-malware features or legal requirements) and identifying bad (malware) traffic. But it goes much further than that.<\/p>\n<p><!--nextpage--><\/p>\n<p>ISPs have also built crucial relationships with <strong>Content Delivery Network<\/strong> (CDN) vendors, which help them to more efficiently cache and serve on-net content to give consumers the best experience and minimise network costs (indirectly this also keeps the price you pay for broadband down). But ISPs say some of that might be impacted if DoH providers get in the way of their normal DNS (i.e. more difficult for providers to steer certain content).<\/p>\n<p>Furthermore ISPs can also use DNS redirects for common support tasks, such as device\/router setup, mobile top-ups, network performance metrics (as often demanded by <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/link\/ofcom\" target=\"_blank\">Ofcom<\/a>) and broadband support. Getting these important features to work with DoH will be difficult and could impact a provider&#8217;s ability to help their customers. Not to mention issues for public Wi-Fi hotspots, which often start you off on &#8220;<em>captive portals<\/em>&#8220;.<\/p>\n<p>At this point it becomes clear that for all the benefits of DoH, there are also some potentially big challenges and costly problems for ISPs too. The risk of inconsistent experiences and thus greater complexity for end-users (e.g. needing to setup Parental Controls on each device you use instead of via a central control) is not something that the big players can lightly ignore.<\/p>\n<p>Admittedly the alternative perspective here is that when DoH becomes widespread and Government&#8217;s start asking why the DNS-level blocks that ISP use for certain tasks are no longer effective (not that they were ever very effective) then it becomes, as one provider put it to us, &#8220;<em>someone else&#8217;s problem<\/em>&#8221; (e.g. the DoH providers problem).<\/p>\n<p>Governments will thus end up needing to talk with many more parties in the internet connectivity process than just an ISP (e.g. Google, Mozilla etc.) in order to get their desire for greater use of censorship or other DNS dependent systems realised, which creates another set of problems for them. Meanwhile the DoH providers will rightly argue for the security benefits.<\/p>\n<blockquote class=\"bq1\"><p><strong>Andrew Glover, Chair of the UK <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/link\/ispa\" target=\"_blank\">ISPA<\/a>, said:<\/strong><\/p>\n<p>&#8220;The [<strong><a href=\"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/government-propose-to-setup-uk-regulator-for-internet-censorship.html\">Online Harms White Paper<\/a><\/strong>] lists ISP blocking of non-compliant sites as a potential enforcement mechanism of last resort. However, as technology evolves, including through new technical protocols such as DNS-over-HTTPS, the ability of ISPs to put in place technical measures could be substantially reduced. The legal basis of any blocking action taken will also need to be clear.&#8221;<\/p><\/blockquote>\n<p>Granted there are more sophisticated methods of network-level filtering available for ISPs than mere DNS level blocking, which is one of the easiest methods, but the costs may be unaffordable for all except the largest players (e.g. big ISPs can use DPI &#8211; Deep Packet Inspection but even this has its limits). Of course DPI won&#8217;t solve every other problem mentioned above and can carry a performance impact.<\/p>\n<p>Work is now on-going within the industry to find ways of adapting to the challenges created by DoH, particularly among the largest providers, although it remains to be seen how much success they have. The very nature of DoH makes all of these issues quite fundamentally difficult to resolve. DoH could also create new security risks of its own by potentially making it easier for certain malware to hide bad traffic, as well as being difficult to block without hindering HTTPS.<\/p>\n<p>Explaining the complexity of all this to end-users, when in the future they inevitably ask why something doesn&#8217;t work as intended, is another challenge entirely (support teams would need significantly more technical familiarity). For now none of the major DoH players have chosen to enable the feature by default, instead preferring to give end-users the option, but we expect this to change (e.g. it will become the default in Firefox).<\/p>\n<p>Tech-savvy end-users will of course be keen to manually enable this feature and in doing so we hope that they remain mindful of how it may impact some of the services offered by their ISP, which could cease to function correctly (i.e. don&#8217;t blame your ISP if you enable a third-party feature like this and suddenly something you use on their network stops working or doesn&#8217;t function at its best).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A significant change is on the way that could improve the security of the internet&#8217;s Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although this could also create lots of new problems for broadband ISPs and mobile operators (e.g. disrupting UK Government required censorship systems) that may be hard to overcome.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[6,1],"tags":[474,473,109,36,479],"class_list":["post-18410","post","type-post","status-publish","format-standard","hentry","category-editorial_article","category-uk_isp_news","tag-bt","tag-censorship","tag-internet-privacy","tag-ofcom-regulation","tag-security"],"share_on_mastodon":{"url":"","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS - ISPreview UK<\/title>\n<meta name=\"description\" content=\"A significant change is on the way that could improve the security of the internet&#039;s Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\" \/>\n<link rel=\"next\" href=\"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\/2\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS - ISPreview UK\" \/>\n<meta property=\"og:description\" content=\"A significant change is on the way that could improve the security of the internet&#039;s Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\" \/>\n<meta property=\"og:site_name\" content=\"ISPreview UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ispreview\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/ispreview\" \/>\n<meta property=\"article:published_time\" content=\"2019-04-11T10:31:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-04-22T08:00:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Mark Jackson\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ispreview\" \/>\n<meta name=\"twitter:site\" content=\"@ispreview\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Jackson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\"},\"author\":{\"name\":\"Mark Jackson\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/person\\\/de66a8b4e937c21c80e443d1bf9c35d5\"},\"headline\":\"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS\",\"datePublished\":\"2019-04-11T10:31:12+00:00\",\"dateModified\":\"2019-04-22T08:00:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\"},\"wordCount\":1554,\"commentCount\":22,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/gallery\\\/2019-article-illustrations\\\/dns_vs_doh_bt_isp_diagram.png\",\"keywords\":[\"BT\",\"Censorship\",\"Internet Privacy\",\"Ofcom Regulation\",\"Security\"],\"articleSection\":[\"Editorial Article\",\"ISP News\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\",\"name\":\"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS - ISPreview UK\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/gallery\\\/2019-article-illustrations\\\/dns_vs_doh_bt_isp_diagram.png\",\"datePublished\":\"2019-04-11T10:31:12+00:00\",\"dateModified\":\"2019-04-22T08:00:02+00:00\",\"description\":\"A significant change is on the way that could improve the security of the internet's Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although\",\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2019\\\/04\\\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/gallery\\\/2019-article-illustrations\\\/dns_vs_doh_bt_isp_diagram.png\",\"contentUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/gallery\\\/2019-article-illustrations\\\/dns_vs_doh_bt_isp_diagram.png\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#website\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/\",\"name\":\"ISPreview UK\",\"description\":\"Top Broadband ISP and Mobile Provider Information Site\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ispreview.co.uk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#organization\",\"name\":\"ISPreview.co.uk\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/ispreview_uk_logo.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/ispreview_uk_logo.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"ISPreview.co.uk\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/ispreview\",\"https:\\\/\\\/x.com\\\/ispreview\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mjack\\\/\",\"https:\\\/\\\/bsky.app\\\/profile\\\/ispreview.bsky.social\",\"https:\\\/\\\/mastodon.social\\\/@ispreview\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/person\\\/de66a8b4e937c21c80e443d1bf9c35d5\",\"name\":\"Mark Jackson\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/nggallery_import\\\/Mark-Jackson-96x96.jpg\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/nggallery_import\\\/Mark-Jackson-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/nggallery_import\\\/Mark-Jackson-96x96.jpg\",\"caption\":\"Mark Jackson\"},\"description\":\"By Mark Jackson Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and Linkedin.\",\"sameAs\":[\"http:\\\/\\\/www.ispreview.co.uk\",\"https:\\\/\\\/www.facebook.com\\\/ispreview\",\"https:\\\/\\\/x.com\\\/ispreview\"],\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/author\\\/markj\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS - ISPreview UK","description":"A significant change is on the way that could improve the security of the internet's Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html","next":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html\/2","og_locale":"en_GB","og_type":"article","og_title":"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS - ISPreview UK","og_description":"A significant change is on the way that could improve the security of the internet's Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although","og_url":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html","og_site_name":"ISPreview UK","article_publisher":"https:\/\/www.facebook.com\/ispreview","article_author":"https:\/\/www.facebook.com\/ispreview","article_published_time":"2019-04-11T10:31:12+00:00","article_modified_time":"2019-04-22T08:00:02+00:00","og_image":[{"width":1000,"height":1000,"url":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg","type":"image\/jpeg"}],"author":"Mark Jackson","twitter_card":"summary_large_image","twitter_creator":"@ispreview","twitter_site":"@ispreview","twitter_misc":{"Written by":"Mark Jackson","Estimated reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#article","isPartOf":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html"},"author":{"name":"Mark Jackson","@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/person\/de66a8b4e937c21c80e443d1bf9c35d5"},"headline":"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS","datePublished":"2019-04-11T10:31:12+00:00","dateModified":"2019-04-22T08:00:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html"},"wordCount":1554,"commentCount":22,"publisher":{"@id":"https:\/\/www.ispreview.co.uk\/#organization"},"image":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage"},"thumbnailUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/gallery\/2019-article-illustrations\/dns_vs_doh_bt_isp_diagram.png","keywords":["BT","Censorship","Internet Privacy","Ofcom Regulation","Security"],"articleSection":["Editorial Article","ISP News"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html","url":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html","name":"Big UK Broadband ISPs Have Big Concerns About DNS over HTTPS - ISPreview UK","isPartOf":{"@id":"https:\/\/www.ispreview.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage"},"image":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage"},"thumbnailUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/gallery\/2019-article-illustrations\/dns_vs_doh_bt_isp_diagram.png","datePublished":"2019-04-11T10:31:12+00:00","dateModified":"2019-04-22T08:00:02+00:00","description":"A significant change is on the way that could improve the security of the internet's Domain Name System (DNS) by adopting DNS over HTTPS (DoH), although","inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.ispreview.co.uk\/index.php\/2019\/04\/big-uk-broadband-isps-have-big-concerns-about-dns-over-https.html#primaryimage","url":"https:\/\/www.ispreview.co.uk\/wp-content\/gallery\/2019-article-illustrations\/dns_vs_doh_bt_isp_diagram.png","contentUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/gallery\/2019-article-illustrations\/dns_vs_doh_bt_isp_diagram.png"},{"@type":"WebSite","@id":"https:\/\/www.ispreview.co.uk\/#website","url":"https:\/\/www.ispreview.co.uk\/","name":"ISPreview UK","description":"Top Broadband ISP and Mobile Provider Information Site","publisher":{"@id":"https:\/\/www.ispreview.co.uk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ispreview.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.ispreview.co.uk\/#organization","name":"ISPreview.co.uk","url":"https:\/\/www.ispreview.co.uk\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/logo\/image\/","url":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg","contentUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg","width":1000,"height":1000,"caption":"ISPreview.co.uk"},"image":{"@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/ispreview","https:\/\/x.com\/ispreview","https:\/\/www.linkedin.com\/in\/mjack\/","https:\/\/bsky.app\/profile\/ispreview.bsky.social","https:\/\/mastodon.social\/@ispreview"]},{"@type":"Person","@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/person\/de66a8b4e937c21c80e443d1bf9c35d5","name":"Mark Jackson","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2023\/01\/nggallery_import\/Mark-Jackson-96x96.jpg","url":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2023\/01\/nggallery_import\/Mark-Jackson-96x96.jpg","contentUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2023\/01\/nggallery_import\/Mark-Jackson-96x96.jpg","caption":"Mark Jackson"},"description":"By Mark Jackson Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and Linkedin.","sameAs":["http:\/\/www.ispreview.co.uk","https:\/\/www.facebook.com\/ispreview","https:\/\/x.com\/ispreview"],"url":"https:\/\/www.ispreview.co.uk\/index.php\/author\/markj"}]}},"_links":{"self":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/18410","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=18410"}],"version-history":[{"count":0,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/18410\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=18410"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/categories?post=18410"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/tags?post=18410"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}