4 ms·
You can’t track all requests anyway, as they can be trivially tunneled through encrypted streams with bundled certs. This is the tradeoff of running arbitrary
by cle 5y ago
You can’t track all requests anyway, as they can be trivially tunneled through encrypted streams with bundled certs.
This is the tradeoff of running arbitrary Turing-complete programs. If you don’t like what a program is doing, or that it doesn’t use libc or some standard way to do DNS resolution, your only options are to either change the program to do what you want, or don’t run it.
- throw0101a 5y ago> You can’t track all requests anyway, as they can be trivially tunneled through encrypted streams with bundled certs. Previously I can track devices (a) making DNS requests, and then (b) make TCP and/or UDP requests. Anything that made a data request without a DNS request was probably using a hard-coded IP, which would be suspicious. With DoH, it's all-HTTPS all-the-time: > DoH is an over the top bypass of enterprise and other private networks. But DNS is part of the control plane, and network operators must be able to monitor and filter it. Use DoT, never DoH. * https://twitter.com/paulvixie/status/1053886628832382977 https://twitter.com/paulvixie/status/1053886628832382977 > or don’t run it. So Firefox further circles the drain with regards to market share? Is this part of some grand 4D chess plan by Mozilla that is perhaps beyond my intellect?
- SilverRed 5y agoThe cat is out of the bag regardless of what Firefox does. Even without firefox any bit of malware could bundle their own DoH library.