4 ms·
There is less and less choice over your DNS provider. With the classic DNS protocol, requests were routinely hijacked by ISPs. With new protocols like DOH, you
by Skunkleton 5y ago
There is less and less choice over your DNS provider. With the classic DNS protocol, requests were routinely hijacked by ISPs. With new protocols like DOH, you now have to go manually configure every application and cross your fingers it does what you want. Not everything can be configured to a specific DOH gateway.
As it stands today, I can no longer reliably block hosts by domain name on my own network thanks to DOH.
- readams 5y agoThis is a completely separate problem and not related to the root DNS servers. As an individual user, you do not contact the roots.
- setBoolean 5y agoThis really rubs me the wrong way about DoH. At the moment I mitigate this by outright blocking the Top 10 public DNS servers network wide.
- Aeolun 5y ago> As it stands today, I can no longer reliably block hosts by domain name on my own network thanks to DOH. You should be able to mitm all your own https traffic right? Not sure if that’s worth it though.
- Skunkleton 5y agoIf you were to MITM, that would mean all HTTPS connections, not just DOH.
- Aeolun 5y agoWell yeah, but you’re not really afraid of knowing your own traffic right?
- Skunkleton 5y agoNo, but I am a little afraid of doing a bad job with my MITM server and exposing myself to vulnerabilities.