29 ms·
I don't really understand what kind of improvement is the DNS over HTTPS. Yes some middle parties won't be able to tamper with my DNS queries. At what price? T
by zaro 7y ago
I don't really understand what kind of improvement is the DNS over HTTPS.
Yes some middle parties won't be able to tamper with my DNS queries. At what price? Total control for the people providing the DOH endpoints.
So chrome for sure will be using Google DNS for this, and with their efforts to remove ad blocking this fits nicely that you won't be able to use simply DNS based blocker.
- marksomnian 7y agoWe already have this situation though - the people who control DNS resolvers already have total control. ISPs have already been known to abuse this power [0]. This proposal doesn't solve this problem. Rather, it solves the problem of e.g. your ISP intercepting, logging and/or modifying your DNS request. The solution will then just be to run your own DoH endpoint / proxy. [0]: https://arstechnica.com/tech-policy/2009/08/comcasts-dns-redirect-service-goes-nationwide/ https://arstechnica.com/tech-policy/2009/08/comcasts-dns-red...
- zaro 7y agoMy first question in running my own DOH proxy will be how it works in my home network? Right now I have my own dns configuration on my router, and any device that connects to the router is automatically using this dns. With DOH this doesn't seem to be the case though. I'll need to go and change the settings for each device to use my own DOH proxy. But whether I'll be allowed to do so is quite unclear if you ask me. Becauae what happens when chrome says : "we have you covered, it's best to use only our DNS over HTTPS. If you need something else you can buy enterprise subscription"
- zamadatix 7y agoAre you worried about things like Chrome fucking you over or are you worried about DNS encryption? The former does not require the latter, it's just one of a million ways to do it. Probably one of the more roundabout ways to be honest.
- zaro 7y agoYou are right, Chrome doesn't need the DNS encryption to screw me. But I think what they need is screw all of us, in a way which we won't resist much because it's for our own good.
- nathanlied 7y agoIs there a reason DHCP can't be extended to provide DOH, too? As long as the OSes of connecting devices support it, I don't see why not.
- zaro 7y agoI don't know of any such reason. But I look at this from another angle. This could have been DNS over TLS, or any other form of encryption. But it is DNS over HTTPS. This makes sense only for a browser, because they have the https stack already. But if we are talking about libc, it's very different story, there is no Http, let alone HTTPS there.
- throw0101a 7y ago> Rather, it solves the problem of e.g. your ISP intercepting, logging and/or modifying your DNS request. So does DNS over TLS (DoT). But the Mozilla folks don't seem to be interested in implemented that for some reason.
- judge2020 7y agohttps://news.ycombinator.com/item?id=21303450 https://news.ycombinator.com/item?id=21303450