Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> but at the same time it hides application requests from the user, renders user's own DNS-based filtering (pihole and such) useless

Can't you proxy it over a local DNS-over-https server that will provide filtering/caching and then have it query the upstream server?



I cannot trust non-free software to use OS DNS settings (Chrome taught me that).

I wouldn't want to proxy all HTTPS traffic (may not be possible if software ignores system-wide TLS CAs and uses bundled trust chain).

DoH introduces bunch new problems without solving any that I had.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: