• 𝘋𝘪𝘳𝘬@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    So … people misusing DoH – a system that makes it impossible to block or see the traffic because you cannot block port 443 nowadays and where it is by design that the individual clients and not the operating system handle DNS requests?

    DoH was a mistake.

    • nani8ot@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Yes, it isn’t great how DoH traffic can’t be controlled well. Apps using DoH makes blocking ads unnecessarily more difficult. (DoT solves DNS encryption better imo.) HTTPS is already often unblocked and also difficult to analyze, but DNS is already used enough for malware communication.