4 ms·
So DNS over HTTPS sounds great.
by marichards 8y ago
So DNS over HTTPS sounds great.
- judge2020 8y agoI don't see ISPs starting DOH servers up within the next 5 years, so either way, you'll be performing dns lookups to a central server.
- marichards 8y agoI'm under the impression Firefox intends to do DOH with Cloudflare shortly. Does this allow Cloudflare to tie together user sessions to different HTTPS domains? If X and Y are Cloudflare fronted domains, can they now pair sessions? I'm guessing a DOH session queries for domain X and immediately an HTTPS connection appears for X, then queries for Y and another appears at Y. Then the whole DOH session becomes identifiable once Cloudflare fronts any service with email sign in. Unless I'm mistaken at least UDP DNS made the guess work a lot harder because you couldn't pin a session down behind an internet gateway as easily.
- auslander 8y agoCloudflare is not as bad as it looks. It is much worse :) As a reverse proxy, it strips SSL, in fact MITMs your traffic. All your data is in plaintext to Cloudflare, which leaks not only history, but also logins/passwords, IPs, credit card numbers, coin wallets, everything. I don't see obvious solution today for DNS queries be private. Pointing your system to Google or Cloudflare DNS is plainly giving away your browsing history, for free, DOH (dns over https) or not. As of today, all my devices are using always-on VPN, and using my VPN provider's DNS.