Hacker News new | ask | show | jobs
by sneak 3552 days ago
Comcast is the one sending you the (unsigned, unencrypted) response packets from 8.8.8.8.

You might as well use the Comcast ones.

1 comments

Politically it's a lot easier to stop Comcast from altering through-traffic DNS than it is to stop them from lying in DNS responses and calling it pro-user.
And if you use DNS-over-HTTPS to get your answers from Google, Comcast can't modify them.