11 ms·
"To help keep Android users’ DNS queries private, Android supports encrypted DNS." And DNS based ad filtering impossible.
by StreamBright 4y ago
"To help keep Android users’ DNS queries private, Android supports encrypted DNS."
And DNS based ad filtering impossible.
- est31 4y agoYeah this is likely the #1 reason why it's been implemented by Google. It's sad that this is one of the first Rust features. Proprietary and user hostile.
- staticassertion 4y agoIt doesn't make DNS based ad filtering impossible unless you're doing that at the router level. You can still do it locally (like via hosts file) or via the DNS resolver itself.
- est31 4y agoBoth hosts file and custom DNS resolvers require the device to cooperate.
- staticassertion 4y agoYes, based on your other comment it sounds like you're concerned about "smart" devices like TVs that are on the internet. It's unfortunate that those devices lock you out but that's kinda on those devices.
- DownGoat 4y agoAs I painfully experienced recently, browsers on desktop ignores host file with DoH enabled. Had to create a separate browser profile to get this to work with DoH and other privacy/security settings to work
- meibo 4y agoCould also be that other reason, which might be that you're no longer sending every domain you visit in plaintext over the internet... Not to mention that DNS over HTTP AdBlock is basically just as easy to set up nowadays.
- throw0101a 4y ago> Not to mention that DNS over HTTP AdBlock is basically just as easy to set up nowadays. Only if the device in question uses the ad-blocking DNS servers. Firefox (IIRC) by default does not use the operating system's resolv.conf. Smart TVs (and Chromecast) have also been known to ignore DNS settings from DHCP. * https://labzilla.io/blog/force-dns-pihole https://labzilla.io/blog/force-dns-pihole And since the DNS traffic now looks like HTTP(S) traffic, your only recourse is to block all HTTP access and tunnel it through a proxy. As an IT guy, and the person who runs a home network, this reduces the visibility of what is happening on my network(s). Reduced visibility is bad IMHO.
- Forbo 4y agoYou can force Firefox to use use a DNS server of your choosing with a canary domain: https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
- throw0101a 4y agoI'd prefer it Firefox was opt-in instead of opt-out, and if they'd just use the OS settings like every other piece of code on my system.
- jeltz 4y agoYou will still do so with SNI.
- est31 4y agoYeah and if you don't use SNI, but the website sits on its own IP, then the website can be found out via the ip, which is transmitted in the clear (unless VPNs/tunneling etc are used).
- Asooka 4y agoIf it's user hostile, isn't that against the Rust code of conduct? Can't Google's license to use Rust be revoked in that case?
- staticassertion 4y agoNo
- detaro 4y agoIsn't DNS based filtering usually done by configuring the device to use a DNS server that filters? (vs intercepting traffic to another server and modifying that)
- darkhorn 4y agoWhy? Don't you know how to disable or point to your own DoH?
- est31 4y agoIf the device e.g. your smart TV, has an option for it, then you can do that. If it hardcodes a bunch of resolvers, you can't do much about it.
- darkhorn 4y agoIn Android you can disable it or point it to your own DoH. Classic DNS resolvers can have same "hardcoded" problem.
- est31 4y agoWith classic DNS resolvers you can modify the responses on the fly as long as you provide the box its network. Not possible with DoH.
- iso1631 4y agoYou just nat UDP/53 traffic and resolve it yourself. Now you have to identify the specific DoH server they're using and block it, and hope it falls back to something you can control.
- Melatonic 4y agoTheoretically you can run a firewall that blocks all common resolvers but its more work
- WesolyKubeczek 4y agoThere have been devices that used 8.8.8.8 no matter what your network said. Now, you can obviously make your own 8.8.8.8 for your network, but good luck also supply proper TLS certificates for the encrypted DNS traffic. Yeah, you _still_ can tweak this and you _still_ can configure that, but it’s getting more finicky ever so slightly every time. “Still” is the key, to hint at how volatile it all is.
- stevewatson301 4y agoAdding your own DoH server has always been possible, see for example https://developers.cloudflare.com/1.1.1.1/setup/android/ https://developers.cloudflare.com/1.1.1.1/setup/android/ though you can add an adblocking server in its place.
- kuschku 4y agoHow do I do that on a Chromecast?
- jeroenhd 4y agoChromecast doesn't run Android, of course, so I'm not sure how it's relevant to this article. Personally, I've statically routed my Chromecast to forward UDP/53 to my PiHole and it's been very effective so far. Too bad blocking trackers also breaks the applications on Chromecast, making the block effectively useless, but that's the choice I made when I bought one of those things.
- RF_Savage 4y agoBut can't the ads in the app also use some known good DoH server?
- ccouzens 4y agoIt puts the device owner in charge rather than the network owner. I've checked, my android gives me the option to reconfigure it including turning it off. It makes DNS based advert adding Impossible. Hopefully this is the end of captive portals.