Hacker News new | past | comments | ask | show | jobs | submit login

A solution here is like what Chrome is doing - a DoH upgrade list that only uses it when your OS/router specifies a service that also provides DoH[0].

https://github.com/chromium/chromium/blob/711b1ba2735f8af4bd...




This is a significant improvement over what Mozilla is doing, but still retains a big issue: It doesn't account for network requests sent outside the browser.

I'd far rather these developers focus on getting DNS-over-HTTPS support built directly into operating systems and then properly using the OS's network stack.


This is still very experimental. I think doing the experiments in applications makes more sense than potentially breaking every network request on the system at once.


in reality Chrome will(used to last time I looked into this) use DoH/hardcoded Google dns server when for example queried domain doesnt have A record.

https://www.reddit.com/r/vivaldibrowser/comments/a23071/how_...

https://techdows.com/2018/12/vivaldi-2-2-lets-you-disable-go...


So, let's be clear about this--if Chrome detects your DNS server is on one those lists, it will automatically switch to using DoH with the same provider?


Yes.

To add, this won't upgrade the encryption if the router is acting as a DNS proxy, as Google Wifi does.


Thank you. That is a sensible approach.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: