Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNS-adblocking in a router can be complemented by the router's firewall blocking outbound to all DoH provider IPs.

(It'll need to be a constantly-updating blocklist, but the DNS-adblock lists are also that already.)



I can't vouch for these since I haven't tried them yet, but it can apparently also be complemented by configuring your local DNS server to return NXDOMAIN for use-application-dns.net [1] and using a DoH proxy to protect upstream requests from snooping [2].

[1] https://support.mozilla.org/en-US/kb/canary-domain-use-appli...

[2] https://github.com/aarond10/https_dns_proxy




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: