3 ms·
People say: "I'll just block it in my hosts file" With DNS over HTTPS you can't. You can't even intercept DNS and reroute it to your own DNS server. Suppose
by DannyB2 7y ago
People say: "I'll just block it in my hosts file"
With DNS over HTTPS you can't. You can't even intercept DNS and reroute it to your own DNS server.
Suppose a device, let's say a RoKu (or many other) wants to use a DNS that you cannot block, it could use Google's DNS over HTTPS to a private name server of its choosing. Your DNS, and your hosts file doesn't matter. This makes it significantly harder to block anything (probably ads, but not necessarily only ads).
You could try to intercept these requests, but how do you know an HTTPS request is for DNS? And for what name it is being requested?
Taken further, a device, say an Apple TV, hypothetically, could even use a proprietary DNS protocol to talk to its own mother ship.
- Spivak 7y agoYou could make the same arguments to say that these devices should be speaking HTTP instead of HTTPS for the purposes of allowing the use of a proxy to inspect, redirect, and provide custom responses for requests. Ultimately if a device in your network is your adversary and you’re giving it an open connection the internet then it’s game over. If there was actually a significant portion of people who blocked ads with DNS vendors would have implemented DoT with certificate pinning a long time ago.