Encrypted DNS and IPv6 Take Center Stage at Asia Pacific Domain Meeting in Dubai
The Internet Society will join APTLD 75 in Dubai on 20-21 February 2019, with Jan Žorž presenting on DNS-over-TLS, DNS-over-HTTPS and IPv6 connectivity.
The Internet Society has confirmed it will be actively contributing to the APTLD 75 meeting, taking place on 20 and 21 February 2019 in Dubai, United Arab Emirates. APTLD stands for the Asia Pacific Top Level Domain Association, an organisation that unites the managers of country-code top-level domains and other domain registries across the Asia Pacific region. Internet Society's Jan Žorž will first present on DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH) during the meeting's DNS Operations, Security, and Privacy session on 20 February from 11:30 to 12:30 UTC+4. He will then deliver a separate talk focused on IPv6 connectivity.
To understand why these talks matter, you need to know what the Domain Name System (DNS) actually does. Every time you type a website address into your browser, your device sends a query to a DNS resolver asking it to translate that readable name into the numerical IP address that computers use to find each other on the internet. Normally, these DNS lookups travel over the network in plain text, which means anyone who can see your internet traffic, such as your internet provider or someone running a public Wi-Fi hotspot, can see which websites you are visiting. DNS-over-TLS and DNS-over-HTTPS change this by encrypting DNS queries. DoT sends DNS requests through a dedicated secure channel protected by Transport Layer Security (TLS), the same encryption technology that secures HTTPS websites. DoH goes one step further and hides DNS queries inside ordinary HTTPS web traffic, making them much harder for outsiders to block or distinguish from normal browsing activity.
The APTLD 75 meeting's DNS Operations, Security, and Privacy session provides a natural forum for these discussions. Domain name registries, registrars, internet service providers, and corporate network teams all have a stake in how encrypted DNS is deployed. Privacy advocates have long pushed for wider adoption of DoT and DoH because they stop on-path observers from profiling users' browsing habits. At the same time, some network administrators raise concerns about losing visibility into DNS queries, which they have traditionally used to detect malware infections or enforce internal policies. Jan Žorž's presentation will walk attendees through both protocols and their real-world implications, helping them decide when and how to adopt encrypted DNS without sacrificing essential security controls.
The second presentation shifts the focus to IPv6 connectivity, a topic with important security and privacy dimensions of its own. IPv6 is the next-generation internet addressing system, designed to replace the older IPv4 scheme that is running out of unique addresses. IPv6 offers a vastly larger address space and includes some built-in security features, though its practical security still depends heavily on correct configuration by network operators. As more networks and devices move to IPv6, it becomes critical to ensure that DNS privacy protections such as DoT and DoH work just as well over IPv6 as they do over the older IPv4. A user's DNS queries should be equally private regardless of which addressing version their connection uses.
For everyday internet users, website owners, and IT teams, these developments are not abstract conference topics. Your choice of DNS resolver directly affects your browsing privacy and the security of your users. Turning on encrypted DNS helps prevent outsiders from tracking the sites you visit or redirecting you to fake websites through a technique called DNS spoofing. A privacy-first resolver such as AEU DNS, which supports encrypted DNS and keeps no logs, offers website owners and businesses a straightforward way to reduce that risk and keep their users' DNS queries confidential.
The Internet Society's active role at APTLD 75 highlights how central DNS privacy and IPv6 connectivity have become for the global internet community. The meeting gives regional operators a chance to learn from experienced practitioners and plan deployments that strengthen security and privacy without closing off the open internet.
Terms explained
- DNS
- The Domain Name System translates human-friendly website names into the numeric IP addresses computers use to find each other.
- DNS-over-TLS (DoT)
- A way to encrypt DNS queries by sending them through a secure channel protected by Transport Layer Security, the same technology that secures HTTPS websites.
- DNS-over-HTTPS (DoH)
- A method that hides DNS queries inside regular HTTPS web traffic, making them look like normal browsing and harder to block or snoop on.
- IPv6
- The next-generation internet addressing system that replaces the older IPv4 and provides a much larger number of unique addresses.
- APTLD
- The Asia Pacific Top Level Domain Association, a group that represents organisations managing country-code and other top-level domains in the region.
- Transport Layer Security (TLS)
- The encryption technology that protects the connection between your device and a website, ensuring data is private and unchanged.
How to protect yourself
- Turn on encrypted DNS in your web browser or device settings, choosing options like DNS-over-HTTPS or DNS-over-TLS when available.
- Use a privacy-focused DNS resolver that does not keep logs of the websites you visit.
- If you run a website or manage a network, ask your hosting provider or IT team to enable encrypted DNS and secure IPv6 configuration.
- Keep your router and devices updated so you receive the latest security fixes for DNS and IPv6.
- On public Wi-Fi, avoid doing anything sensitive until you have confirmed encrypted DNS is active on your device.
Source: internetsociety.org
