3 ms·
It makes it very hard to control your network. I have a DNS setup at home that I want all my equipment using. It blocks ads and other sites I don't want accesse
by robertcope 7y ago
It makes it very hard to control your network. I have a DNS setup at home that I want all my equipment using. It blocks ads and other sites I don't want accessed. With DoH, I can't really be sure that browsers, devices, etc aren't using an alternative DNS system.
- pingyong 7y agoYou can't be sure anyway though? The only thing that router controls are standard DNS queries, probably sent through a standard port. If they're using anything different at all, the router won't catch it, even if it's not encrypted.
- LinuxBender 7y agoYou could null route or firewall all the open resolvers, or at least the most common ones. If your router is linux, that might look like /sbin/ip route add blackhole 9.9.9.9 2>/dev/null /sbin/ip route add blackhole 1.1.1.1 2>/dev/null /sbin/ip route add blackhole 1.0.0.1 2>/dev/null /sbin/ip route add blackhole 8.8.8.8 2>/dev/null /sbin/ip route add blackhole 8.8.4.4 2>/dev/null I'm probably leaving many of them off. There is probably a RBL for those by now. Here is one [1] and here is a list of them. [2] [1] - https://github.com/bambenek/block-doh https://github.com/bambenek/block-doh [2] - https://github.com/curl/curl/wiki/DNS-over-HTTPS https://github.com/curl/curl/wiki/DNS-over-HTTPS
- heavenlyblue 7y agoBut the plain DNS makes you absolutely unable to control your DNS queries outside your network. Nothing stops anyone in the middle intercepting your queries and returning whatever they want, including your provider.