3 ms·
There isn't one today, aside from running your own DNS server, and you can run your own DNS-over-HTTPS server. My understanding is that Firefox still respects /
by vertex-four 6y ago
There isn't one today, aside from running your own DNS server, and you can run your own DNS-over-HTTPS server. My understanding is that Firefox still respects /etc/hosts in DNS-over-HTTPS mode, too. I'm unaware of any such tooling that installs a glibc resolver stub.
RFC8890 explicitly refers to "the interests of that child's parents or guardians" when the child is using a web browser, although individual system configuration is not within the remit of the IETF.
RFC 8484 makes no reference to how DNS-over-HTTPS should be configured, and in the face of widespread DNS hijacking, enforcing DNS-over-HTTPS in browsers may have been the correct solution - but that doesn't mean we can't do better by defining a standard (perhaps under the remit of the Free Desktop XDG group), encouraging operating system vendors to ship secure DNS configured by default, and then convincing Firefox et al to use that standard.
- someguydave 6y agoSure, because big tech pretends to care about privacy and freedom of speech but only insofar as it results in them cutting out every layer of control between their servers and the end users they would like to own. So everything will be tunneled over opaque HTTPS proxies and there will be no facility for people to filter anything - even end users. Apple, for instance, pretends to care about user privacy and control but refuses to offer a configurable IP firewall in iOS or end-user control over name resolution for filtering.
- someguydave 6y ago>you can run your own DNS-over-HTTPS server. Yes, but is there a facility to force the browser to use your server or will Google re-write Chomium to "bypass" "rogue" DoH servers which filter content Google doesn't wish them to filter?