<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NSA Guidance on Implementing Encrypted DNS in Threats</title>
    <link>https://community.isc2.org/t5/Threats/NSA-Guidance-on-Implementing-Encrypted-DNS/m-p/42592#M236</link>
    <description>&lt;P&gt;Beware of third-party DNS resolvers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DoH provides the benefit of encrypted DNS transactions, but it can also bring issues to enterprises, including a false sense of security, bypassing of DNS monitoring and protections, concerns for internal network configurations and information, and exploitation of upstream DNS traffic, NSA officials wrote in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://media.defense.gov/2021/Jan/14/2002564889/-1/-1/0/CSI_ADOPTING_ENCRYPTED_DNS_U_OO_102904_21.PDF" target="_blank" rel="noopener"&gt;published recommendations&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="NSA recommended enterprise DNS architecture with DoH" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/5141i93405E2820BDB330/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DoH.PNG" alt="NSA recommended enterprise DNS architecture with DoH" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NSA recommended enterprise DNS architecture with DoH&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:46:24 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:46:24Z</dc:date>
    <item>
      <title>NSA Guidance on Implementing Encrypted DNS</title>
      <link>https://community.isc2.org/t5/Threats/NSA-Guidance-on-Implementing-Encrypted-DNS/m-p/42592#M236</link>
      <description>&lt;P&gt;Beware of third-party DNS resolvers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DoH provides the benefit of encrypted DNS transactions, but it can also bring issues to enterprises, including a false sense of security, bypassing of DNS monitoring and protections, concerns for internal network configurations and information, and exploitation of upstream DNS traffic, NSA officials wrote in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://media.defense.gov/2021/Jan/14/2002564889/-1/-1/0/CSI_ADOPTING_ENCRYPTED_DNS_U_OO_102904_21.PDF" target="_blank" rel="noopener"&gt;published recommendations&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="NSA recommended enterprise DNS architecture with DoH" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/5141i93405E2820BDB330/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DoH.PNG" alt="NSA recommended enterprise DNS architecture with DoH" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NSA recommended enterprise DNS architecture with DoH&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:46:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/NSA-Guidance-on-Implementing-Encrypted-DNS/m-p/42592#M236</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:46:24Z</dc:date>
    </item>
  </channel>
</rss>

