logoalt Hacker News

slautoday at 4:13 AM2 repliesview on HN

This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).

This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.


Replies

TeMPOraLtoday at 6:45 AM

That's why I'm not a fan of DoH or certificate pinning. Those are tools of control.

tkeltoday at 4:30 AM

I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.

show 1 reply