3 ms·
While I agree that it's a step forward you should proxy your whole traffic anyways if you want to enjoy the benefits of encrypted DNS. Otherwise intermediaries
by t0astbread 6y ago
While I agree that it's a step forward you should proxy your whole traffic anyways if you want to enjoy the benefits of encrypted DNS. Otherwise intermediaries routing your packets can still see what you connect to by looking at the IP header (or SNI, if not encrypted).
DoH/DoT is still useful because it allows you to proxy your DNS over Tor (for example) without having to worry about tampering (or surveillance if you also use separate circuits per domain).