TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Cloudflare and Apple made a new DNS protocol to protect your data from ISPs

81 pointsby janniksover 4 years ago

6 comments

okanesenover 4 years ago
Related: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25344358" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25344358</a>
评论 #25357353 未加载
pbronezover 4 years ago
I wonder if this protocol could provide any relief to network admins trying to protect themselves from aggressive Smart TVs and other IoT devices that use DNS over HTTPS to avoid local DNS blocks. I suspect not, since anything designed to protect against ISP snooping should be available to device manufacturers to protect against local admin snooping.
评论 #25357792 未加载
评论 #25357915 未加载
评论 #25360984 未加载
nora-puchreinerover 4 years ago
Since 1.1.1.1 introduction, Cloudflare is able to perform HTTPS man-in-the middle attacks even for the websites which do not use Cloudflare CDN: they could forge DNS answer and proxy HTTPS traffic of any website via their CDN, instantaneously issuing a valid HTTPS certificate, as they have root certs and could issue certs for any domain.<p>Since ODoH they could perform such attacks without being spotted by ISPs. Nice.
评论 #25369422 未加载
评论 #25366413 未加载
ferozover 4 years ago
If you would like to try out an independent ODoH proxy with Cloudflare DNS, I added ODoH proxying to my DoH server last night - instructions on using it are here: <a href="https:&#x2F;&#x2F;padlock.argh.in&#x2F;2020&#x2F;12&#x2F;08&#x2F;odoh.html" rel="nofollow">https:&#x2F;&#x2F;padlock.argh.in&#x2F;2020&#x2F;12&#x2F;08&#x2F;odoh.html</a>
评论 #25357425 未加载
egberts1over 4 years ago
I’m sticking with DNS over dual server&#x2F;client certificate.<p>My home LAN gateway is blocking DoH because the hassle of issuing enterprise-based intermediate CA is not worth the effort to do a Squid TLS transparent proxy so that one can “Pi-hole” to block stray DNS&#x2F;domains.<p>This means my own set of authoritative DNS servers.
alexpc201over 4 years ago
By now I don’t understand why DNS is not a browser functionality. Or an operating system service.
评论 #25369437 未加载