3 ms·
Sounds like they're either sitting on something, or are grumpy that they lost access / visibility
by loopback_device 6y ago
Sounds like they're either sitting on something, or are grumpy that they lost access / visibility
- davismwfl 6y agoI think their point has merit. It isn't don't use DoH, it is don't use DoH outside your network and outside your control as it has been/can be exploited by 3rd parties. CISA, as the article points out, made the same argument, it isn't that DoH is bad, it is that a 3rd party DoH provider can actually do malicious things hidden from the IT admins and staff, making identifying a malicious endpoint the user was served via DNS harder. I am not above thinking any government agency might put out disinformation to protect a source/access, but this one seems like a reasonable position to take on security.
- dumpsterdiver 6y agoAgreed. DoH seems good for personal privacy (i.e. hides the um... meditation sites), but when it comes to enterprises, administrators will have no way of knowing what sites their users are actually being directed to.