Hacker News new | ask | show | jobs
by Skunkleton 2536 days ago
DoH bypasses the normal resolver, and gives control over resolution to the browser. Not a big deal if your browser is from Mozilla. A little more concerning if your browser is from google.
2 comments

That's how it's done now, because browsers want to push the tech when nobody else has yet bothered; but it would make a lot more sense in the long term for DNS to stay an OS-level concern, so I would expect DoH to be implemented by the OS DNS resolvers.
DoH is just a protocol. Your appliance/application could choose to bypass the network specified resolver whether or not it uses DoH.