TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Experimenting with same-provider DNS-over-HTTPS upgrade

22 pointsby migueldemouraover 5 years ago

9 comments

londons_exploreover 5 years ago
&gt; DoH would prevent other WiFi users from seeing which websites you visit,<p>This is <i>false</i>, and downright dangerous information. A network attacker can still see that you are visiting pornhub.com even with DoH, since you are sending the hostname in cleartext as part of the TLS handshake.<p>Google isn&#x27;t a snake-oil security solution - they shouldn&#x27;t be making such false claims.
评论 #20949605 未加载
评论 #20949723 未加载
评论 #20949617 未加载
评论 #20949635 未加载
tptacekover 5 years ago
Long story short: Chrome will do DoH DNS, but only if your current DNS provider already supports DoH, and, for now, only as an experimental feature.<p>People are upset about Firefox&#x27;s new default of routing DoH to Cloud Flare, and I understand why. But it&#x27;s useful to keep the issues distinct: DoH is a good thing (your ISP should not be able to see your DNS queries), even if routing them to Cloud Flare isn&#x27;t.
评论 #20949758 未加载
评论 #20943750 未加载
iforgotpasswordover 5 years ago
On this topic: I recently learned about <a href="https:&#x2F;&#x2F;support.mozilla.org&#x2F;en-US&#x2F;kb&#x2F;configuring-networks-disable-dns-over-https" rel="nofollow">https:&#x2F;&#x2F;support.mozilla.org&#x2F;en-US&#x2F;kb&#x2F;configuring-networks-di...</a><p>Is this just a Mozilla one man show or are there plans by anyone else to support this? Maybe make this a standard? Some googling revealed nothing... Now the way Google does it sounds somewhat reasonable but who knows what the future will bring, or what other software will adapt DoH.
评论 #20949647 未加载
nickcwover 5 years ago
Google make this point which I haven&#x27;t seen in any of the arguments so far:<p>&gt; In particular, we are aware of how DNS can play an important role in ISP-provided family-safe content filtering.<p>Lots of families with children use their ISP&#x27;s safe browsing facilities which is usually implemented via alternative DNS servers.<p>Yes it is not terribly difficult to defeat, but it is cheap and effective for small and non technical children.<p>This does at least seem like a more sensible experiment than Mozilla&#x27;s which will break the above scheme for every Firefox user.
评论 #20949801 未加载
nimrodyover 5 years ago
They say it will be enabled only for providers supporting this. Do they mean DNS servers supporting DoH?<p>If a network DHCP server publishes a local DNS server that is not on the list, DNS traffic will not bt encrypted?<p>So a network operator wishing to continue spying on its users just needs a local DNS proxy?
评论 #20950060 未加载
jwilkover 5 years ago
Archived copy that can be read without JS enabled:<p><a href="https:&#x2F;&#x2F;archive.is&#x2F;59JCD" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;59JCD</a>
Lioover 5 years ago
I&#x27;d be interested to know if this will affect the ability of things like Pi Hole to block advertising and user tracking via DNS?
评论 #20949734 未加载
评论 #20949389 未加载
throwawaynihilover 5 years ago
The only thing DoH gives anybody .. is even more of your private data to a centralized provider with questionable ethics, and the only company more ethically questionable than Google is Palantir. Run your own local resolver and move on with your life.
评论 #20949610 未加载
_Codemonkeyismover 5 years ago
Does anyone know how much money Mozilla gets from Cloudflare? Do they get any? I&#x27;ve tried to find something in Mozilla financial declarations but haven&#x27;t found anything.
评论 #20950003 未加载