3 ms·
> It means you have a full time job just changing it back to the way you want it in every application on every device, and even then you're liable to miss some
by sciurus 7y ago
> It means you have a full time job just changing it back to the way you want it in every application on every device, and even then you're liable to miss some.
Hopefully not. Firefox has some techniques for disabling DoH that rely on computer or network-wide changes. If other applications also adopt these or similar techniques, you'd only have to make the change in one place to turn it off for every application running on any computer on a network.
Specifically, as I understand it, Firefox disables DoH if
1) Windows Group Policy is used to manage a computer
2) A canary domain is blocked
https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs#w_how-will-doh-impact-enterprises-with-custom-dns-solutions https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs...
(Disclosure: I work for Mozilla, but not on the Firefox browser)
- zrm 7y ago> 1) Windows Group Policy is used to manage a computer This is solving the problem only where it least matters. If you're using Group Policy then you can configure DNS using Group Policy anyway, so any default there is already easy to override. Where the default really matters is on the devices where the only central management is DHCP, because those are the devices that require manual interaction to fix an application that defaults to ignoring the DHCP configuration. > 2) A canary domain is blocked That could work, but what happens when the ISPs start blocking the canary domain? The FAQ says they'll monitor it but that doesn't tell you how they'll address it when it happens.
- yellowapple 7y ago> but what happens when the ISPs start blocking the canary domain? Put your own DNS server in front of it that resolves the canary domain, I guess. The absurdity of rolling a DNS server solely to unblock a domain blocked by an upstream DNS server specifically so that an application can resolve that domain and consequently not actually use your DNS server is not lost on me.
- zrm 7y agoTechnically correct -- the best kind of correct. Though obviously if you've got your own DNS server in front of the ISP's then you could just configure that to resolve names however you like. Which would then typically cause it to accurately resolve the canary domain by default and thereby cause the application to not use it. Hmm.