Remix.run Logo
slau 3 hours ago

This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).

This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.

TeMPOraL 27 minutes ago | parent | next [-]

That's why I'm not a fan of DoH or certificate pinning. Those are tools of control.

tkel 3 hours ago | parent | prev [-]

I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.

lodovic an hour ago | parent [-]

I have a separate lan for untrusted devices, I only use whitelisting. No public DNS for these devices.