3 ms·
There are instructions on how to route all operating system DNS requests through DoH here: https://developers.cloudflare.com/1.1.1.1/dns-over-https/cloudflared-
by flarex 7y ago
There are instructions on how to route all operating system DNS requests through DoH here: https://developers.cloudflare.com/1.1.1.1/dns-over-https/cloudflared-proxy/ https://developers.cloudflare.com/1.1.1.1/dns-over-https/clo....
One advantage that DoH has over DNSCurve is that it is much harder to detect or block due to it being encapsulated as https traffic.
- zrm 7y ago> There are instructions on how to route all operating system DNS requests through DoH here Then the next step is to get operating systems to ship it by default and support DoH as a DHCP option: https://tools.ietf.org/html/draft-peterson-doh-dhcp-00 https://tools.ietf.org/html/draft-peterson-doh-dhcp-00 > One advantage that DoH has over DNSCurve is that it is much harder to detect or block due to it being encapsulated as https traffic. If you're using a network subject to active adversarial man in the middle attacks like that then you probably want to be sending all your traffic through some kind of encrypted tunnel rather than only DNS.
- thatfunkymunki 7y agoYes but many such active adversarial networks prevent most traffic besides http/tls leaving the network. DoH solves this problem.
- zrm 7y ago> Yes but many such active adversarial networks prevent most traffic besides http/tls leaving the network. DoH solves this problem. So do VPN tunnels over HTTPS/TLS. There is also happy eyeballs. Use DNSCurve and DoH at the same time and accept whichever answers first, which will be DNSCurve whenever it isn't blocked. Then in a few years when middleboxes have given up trying to block DNSCurve because the alternative is no advantage to them, we can deprecate inefficient DoH to a strict fallback and eventually be rid of it entirely (because they couldn't block DNSCurve anymore if it was 95% of DNS traffic).