5 ms·
That is, until software on any of these devices start running their DNS queries through DoH directly, circumventing any DNS filtering at the perimeter. This is
by xjay 7y ago
That is, until software on any of these devices start running their DNS queries through DoH directly, circumventing any DNS filtering at the perimeter.
This is what browsers, like Firefox, are likely to do as it stands today.
- StreamBright 7y agoThen there can be a browser that does not do that and this is what I will use.
- andrerm 7y agoUntil you're minority, the browser don't receives funds enough and dies
- tinus_hn 7y agoAnd then you change the setting from the default to make it do what you want. The sky is not falling.
- TeMPOraL 7y agoUntil they take that setting away from you, "because security". Not to mention that where DNS was centrally managed before, now you have to change settings in each and every application that uses DoH to resolve names on the Internet. (And then Google decides to do cert pinning on DoH, and suddenly you can only ever use 8.8.8.8 and 1.1.1.1, and if you want to change it, you need to buy Enterprise version of Chrome.)
- andrerm 7y agoI do think you're right. And I also think that DoH will legitimate MITM because if application developers can break an long standing contract like DNS on OS well... "why can't we"
- andrerm 7y agoUntil you can't any more
- xg15 7y agoIt's nice that browsers are likely offering an opt-out. However it seems likely to me that DoH will soon be used by non-browser apps as well, which are in no way obligated to provide an opt-out. What will you do about them?
- zaarn 7y agoThe target is not Application Level DOH, Firefox implements DOH now because it will take a while until OS' ship it, and the OS vendors want to know it's worth it first. Once OS vendors include support, your pihole can run a DoH server locally and all apps in your network use that DoH server.
- xg15 7y agoI don't believe OS-level support would be relevant. Once there is a decent set of public/commercial DoH servers available, devs can simply follow the browsers' example: Directly embed a DoH client into the application and supply a hardwired list of URLs and certificates. To my knowledge, you cannot block that with pihole. At least, if I were an app developer with financial interest in users not blocking my ads and trackers, this would seem like an obvious thing to do.
- zaarn 7y agoI don't see why that would happen once OS-level support is deployed? After all, glibc already did the hard work, why do it again? (Oh and Applications with Ads were already able to do this, no need for firefox to do anything at all, it's just too complicated to be worth it)
- xg15 7y agoWell, it has happened like this with TLS certificate validation. In theory, apps can use the system cert stores and you as a user can install custom root CAs if you want to find out what an app is actually sending. In practice, many apps have pinned certificates embedded to prevent that. > it's just too complicated to be worth it That's the point. It's complicated and costly today if you have to design your own protocol, run your own DNS proxy and be the target of outrage if someone finds out. It won't be if DoH normalizes application-specific DNS servers and provides an ecosystem with infrastructure and tooling for it.