4 ms·
Lots of tech giants are forcing DoH so their apps can phone home despite safeguards such as pi-hole. There's not a lot that you can do about that (if they are u
by anonymousisme 5y ago
Lots of tech giants are forcing DoH so their apps can phone home despite safeguards such as pi-hole. There's not a lot that you can do about that (if they are using certificate pinning, which they probably are). You can however do something about 8.8.8.8 (and 8.8.4.4). Just put a static route in your firewall that points those to your DNS of choice (or to a black hole).
- gizdan 5y agoI'm still in the stages of setting up a fullt featured firewall at home, but I wonder what would happen if you block doh/dot addresses completely in such cases. Something to try in the future when I have my home network set up properly I guess.
- KozmoNau7 5y agoYou can block all outgoing requests to ports 53 and 853 for DNS and DoT respectively. That's the easy part. For DoH, you either have to block port 443 (bad idea), or block the IPs of all known DoH providers. Then you can run for example a Pi-Hole and add a firewall rule to allow outgoing DNS traffic only for that. And of course that will not stop device/app makers from using nonstandard ports or even tunnelling their DNS traffic through other protocols.