3 ms·
DNS over TLS is just DoH but with an easily blocked separate port
by bepvte 7y ago
DNS over TLS is just DoH but with an easily blocked separate port
- Legogris 7y agoWhich is great from a local sysadmin perspective. With DoH I have no control of what various apps on devices on my devices are querying.
- bepvte 7y agohttps://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli..., also if you can block it this easily so can the government. The difference with a canary domain is that mozilla can disable it if its misused.
- vetinari 7y ago1) other applications or malware won't respect canary domain 2) to implement this canary, you have to break DNSSEC on entire .net root domain. Great.
- JoshTriplett 7y agoOr in other words, DoH works better on hostile networks because it looks like just one more HTTPS connection. That's an intentional design feature. You're attempting to intercept traffic, and any mechanism you could use to do so "transparently" could be used by any hostile network to do so. You can still intercept traffic from cooperating devices if you want, just not transparently. That's a feature, not a bug, and the Internet will be better for it.
- Legogris 7y agoRight, but I do think this is better handled at the OS layer. Hardcoding everyone to route through Cloudflare is a hardly a net win, and might be better or worse than your ISP depending on who and where you are.