Hacker News new | ask | show | jobs
by PappaPatat 2943 days ago
Now just wait for your browser (or any other random application) to stop using your OS's resolve completely (at least Chrome does at times already by simply accessing DNS services via port 53 when it considers the configured OS DNS 'not good'. I have no idea about the exact criteria) by accessing its desired DNS-over-HTTPS server and bypass your carefully setup DNS filtering / monitoring.

Notes 1: I have NO idea if Chrome (or any other random application) accesses DNS-over-HTTPS already since I have not paid too much attention to it.

2: At least Chrome (on OSX) likes to access 8.8.8.8 & 8.8.4.4 & your configured DNS server on port 53 (happy eyeball protocol). This might only be on flaky networks like mine, where I tend to make all sorts of configuration experiments.