DNS Resolution and ManagementEncrypted "Secure DNS"In recent years TLS-encryption has been applied to DNS messaging, which in effect hides the DNS messages and prevents the restriction of network traffic by domain name. This allows anyone from students wanting to access improper material to malware purveyors wanting to command and spread the reach of their malicious programs to skirt domain access controls using the encrypted DNS messaging afforded by "Secure DNS." LAD returns control over domain access to the network administrator by baring the contents of DNS requests and other DNS messages for examination, while maintaining the encryption of TLS-encrypted datastreams. LAD thereby renders malware detectable, trackable and blockable, without affecting legitimate traffic. It simply appears to the malware, adware and spyware that their requests have merely timed out, likely due to temporary network connectivity issues, but they have, in fact, timed out permanently. Learn more about TLS decryption. LAD provides you with your own domain name resolution services, including DNS logs that let you see where your computers actually go on the Internet. By placing DNS service right on your own LAD device you are in control, with no intermediaries, so you know for sure that whatever resolution of a domain name happened was true and correct at the time. Even if someone hacks your ISP's domain name server, it would not affect you. Even if you get a virus that changes the settings on your computer to go to a false domain name server (a common tactic), LAD's DNS service would block this off so you still get true resolution. In addition to standard domain name resolution, LAD's DNS services include LateralDNS, a feature that lets you control domain name resolution at a granular level. This makes it possible both to resolve domain names and block the resolution of domains selectively, with scheduling and device-level distinctions (read more about LateralDNS). DNS is a critical element of the Internet's infrastructure, but one that often gets overlooked or taken for granted. As an integral tool for getting you to the Internet locations you want to go, it gets frequently exploited, either at the DNS server or the browser level. A hacked DNS server may allow resolution of most domain names normally, except when it comes to the domain name of your financial institution it may send you first to the hacker's server, so that your communications with your financial institution's website, including passwords, pass through the hacker's equipment for harvesting. You would likely never know that they inserted themselves in between you and your bank, because the appearance and functions of the bank’s website would appear completely normal. In this situation a standard firewall would provide no protection because the traffic the firewall sees would appear legitimate and not trigger any red flags. By using LAD's DNS services, you remove the possibility of being caught by this exploit as LAD itself would cross-reference the domain names and check directly with the domain registries and specific individual, authoritative DNS servers to confirm that they are who they say they are. While LAD protects you from DNS exploits and hacks affecting the DNS settings on your own PC, you could still be vulnerable if a legitimate domain name server gets hacked as neither LAD, nor a firewall nor antivirus would have a way to verify whether a legitimate domain name server is operating properly or has been compromised. Other LAD Features
How to get LAD |