3 ms·
They would need to have a fallback in case people block DoH. I think this is way further out than people may realize. I've done pentesting in a lot of differen
by k4ch0w 5y ago
They would need to have a fallback in case people block DoH.
I think this is way further out than people may realize. I've done pentesting in a lot of different office networks and 53/UDP is open for all, but not 443/TCP unless you're a known device.
- somat 5y agoCan you reliably block DoH? I guess if you can figure out the DoH endpoint someone is using you can block that. On 443 blocking: Doesn't that defeat the purpose of having a "smart" streaming tv. If you are willing to blanket deny 443 you might as well just block the whole address and turn it into a dumb tv. And on that note. I have set up unsecured wifi access points before and seen the neighborhood samsung tvs eagerly use it to send their nefarious spyware payload.
- 1over137 5y ago>They would need to have a fallback in case people block DoH. How do you block DoH?
- danielheath 5y agoBlock port 443 and configure machines to use an http proxy with a cert installed?
- RedShift1 5y agoThe 90's called, they want their technology back >:-(
- 0x0000000 5y agoZscaler is a multi-billion dollar company, and the comment you replied to basically describes their primary product. Cloudflare now has a Secure Web Gateway product. So does VMware, and Cisco, and just about any networking/security vendor who is trying to make a play in the "SASE" space. Hate to say it, but invisible TLS-intercepting proxies are more widely used today than they were in the 90s.
- syshum 5y agothat would be a nightmare to manage and impractical for most home networks
- danielheath 5y agoSure, but if you’re rolling out an SOE for a business it’s really not much more work.
- notriddle 5y agoBlackhole 8.8.8.8, 8.4.4.8, 1.1.1.1, and 1.0.0.1. Technically, the provider could use something else, but are they so worried about ad blocking that they’ll run BGP anycast themselves?
- maccolgan 5y agoAdd 9.9.9.9, and the other IP. Besides 4.2.2.2 and 4.2.2.1. Also the IPv6 equivalents. There's almost an infinite number of DNS servers.