3 ms·
No, because instead of setting your network to give out your DNs server to all of your devices, it’s ignored by the apps Instead of setting your devices to use
by iso947 6y ago
No, because instead of setting your network to give out your DNs server to all of your devices, it’s ignored by the apps
Instead of setting your devices to use a dns server of your choice it’s ignored by the apps
Some apps allow you to configure them, so now you’re configuring 200 apps on 20 devices rather than just one dhcp setting.
(Oh and OSs have generally broken hosts files)
- JMTQp8lwXL 6y agoSorry, what I was trying to say is: you know each app tries to use a certain DNS server. So, in your Rasp Pi, you route their DNS server to point your own (as you would with an /etc/hosts file), that way when DoH occurs, you control the final resolution. What I'm suggesting isn't merely setting up the 'default' dns server. What I'm suggesting is 'cnaming' the name servers that apps attempt connecting to, to point elsewhere.
- iso947 6y agoIf you know the iP the DOH client uses you can intercept it. But you can’t spoof it without breaking TLS, which means deploying your own certificate This general industry move will lead to more tls breaking proxies and more network interception. All because people don’t want to understand how a network and os work. Making doh at the application later normal it moves the power towards the centralised advertising network and away from the individual. That the SV culture likes this is unsurprising.