5 ms·
At least Firefox supports a way for LANs to disallow DoH usage via regular-DNS responses: https://kb.isc.org/docs/using-response-policy-zones-to-disable-mozilla
by PreInternet01 2y ago
At least Firefox supports a way for LANs to disallow DoH usage via regular-DNS responses: https://kb.isc.org/docs/using-response-policy-zones-to-disable-mozilla-doh-by-default https://kb.isc.org/docs/using-response-policy-zones-to-disab...
Possibly, Chrome/Edge support the same or similiar mechanisms, but I haven't checked recently.
Alternatively, your school uses a HTTPS middlebox that knows how to distinguish DoH requests from regular SSL traffic to 1.1.1.1.
In any case, this is most likely not an 'attack' on you, and characterizing it as such is unlikely to lead to fruitful discussions around the policy.
- schoen 2y agoIn a computer security sense it is an attack, because there are parties with conflicting goals and one party is trying to use technical means to stop another party from achieving its goals. (The students can also be viewed as attackers by the network operator when they try to circumvent the blocking by disguising the nature of their communications.) It's true that it would be socially awkward to say to school officials that they are carrying out an "attack" against students.