7 ms·
Any device at home an go to http://nas http://nas and get on my nas, "http://desktop" http://desktop", "http://router" http://router", and "http://shed" http://
by isostatic 7y ago
Any device at home an go to http://nas http://nas and get on my nas, "http://desktop" http://desktop", "http://router" http://router", and "http://shed" http://shed" and get on those.
How does that work in this bold new future? I'll have to register a domain name and add a bunch of A records for 192.168.0.1, but then it still won't work -- I'll have to do "http://desktop.mydomain.com" http://desktop.mydomain.com".
Worse, while going to "shed" will work in chrome, it will fail in firefox. My guest network captive portal may well break too if someone visits with firefox.
- Gaelan 7y agoFirefox claims they will detect this situation and disable DoH.
- Tharkun 7y agoDetect it, how? By forwarding the request to a local resolver after DoH fails, and thus leaking information?
- ripdog 7y agoDo you... really care if someone outside you network knows the domain you chose for an internal network service? That's not sensitive information. Also, there's basically no way for cloudflare, even if they were being malicious about it, to collect and use that information. What would they do with it?
- userbinator 7y agoIt's definitely sensitive information --- useful for attackers to find out the structure of the LAN.
- Tharkun 7y agoYes, I care. Why don't you? I work for Tier 1 banks. They are paranoid, and rightly so. One of their many paranoid rules is that hostnames can never betray the machine's purpose. You could easily analyze DoH stats and deduce certain machines' functions. Leaking information is bad.
- roelschroeven 7y agoI don't know why you're downvoted, because that is a very good question. What you have to do is add an entry in your local nameserver for domain use-application-dns.net and set it to NXDOMAIN. See https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https https://support.mozilla.org/en-US/kb/configuring-networks-di.... Hopefully Google will use the same method for disabling DoH in Chrome. But I won't be surprised if they're going to force DoH even harder, and make it even more difficult to turn off.