Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Mozilla may be kind enough to have those settings, but that doesn't mean other software will do the same thing.

It's nice that Mozilla may allow setting other DNS servers for DoH, and perhaps will eventually use OS-level settings, but what happens when some dumb ass developer does not?

Perhaps if they implemented DNS-over-TLS (DoT) instead/as well, then we could have encrypted DNS that is still monitorable.

I'm waiting for the day when malware will start using DoH and use Cloudflare as the DNS server. As someone who works in IT, will I have to block CF to prevent that possibility? How many bots have been taken down over the years because their C&C domains were taken over?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: