Hacker News new | past | comments | ask | show | jobs | submit login
DNS-over-HTTPS privacy and security concerns (godaddy.github.io)
11 points by fanf2 on Sept 7, 2019 | hide | past | favorite | 6 comments



I've had Doh enabled since Firefox added the feature. Zero issues; works great. They are starting to roll this out by default for a small portion of their users: https://www.zdnet.com/article/mozilla-to-gradually-enable-dn...

Most of the privacy concerns seem related to the reduced ability of countries and employers to control the browsing behavior of people. IMHO this is mostly a good thing. I don't want to inform my government or employer of every website I visit. Lack of their ability to do this is the whole point of DOH. It's a feature not a bug. It's the reason I enabled it in my browser: it improves my privacy and security.


In your case, who is the more-than-countries-employers trusted party on the other end of DoH pipe?


Whichever dns provider I choose to trust. So definitely not any DNS server operated by O2 (my provider). Aside from being slow; they hijack the dns erros for ads. Also, I simply don't trust them to do the right thing.


This is a bit silly,they're complaining about browsers supporting their own DoH resolution. You can configure DoH resolution at the OS level just like you would with legacy DNS,or you could use legacy DNS on the LAN and use DoH for upstream/Internet bound resolutions.

That said,I do agree that browsers being so presumptuous as to their role in assuring privacy and interoperability with users' environment is not a good thing for the internet. This is how you get regulated and this is one more thing that will force corporations to mandate IE/Edge!

DoT at the OS level sounds great.


404 File not found





Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: