Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How does DoH make DNS any more centralized than DoT does?


When Google embed their DNS and their certificate into every Google product you have to use, you can't effectively block it.


If your goal isn't to censor or surveil other people, then why do you need to block Google's DNS rather than just not using it yourself?


Unfortunately, people are now often fighting with their own devices for control over which 3rd party services they access. This sometimes means that you have reasons to MITM or block traffic your own devices generate if you want to control aspects of who you actually send data to, or what data you actually send.


Not just block. I run split-horizon DNS at home for a few of my services. Without being able to control the DNS for devices on my LAN, they can't use those services.

Now you might argue that's a bit silly, but it is a use-case.


Chromecast will use Google DNS and there is nothing you can do about it on the device. Guarantee this will happen to Chrome eventually.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: