Hacker News new | ask | show | jobs
by cryptica 2477 days ago
That's a very good point.

I'm not familiar with DoH. Would it allow CloudFlare to match domain names to IP addresses still? If so, then I don't see how it adds any value to the current solution. If anything, it creates a false sense of security which is worse than no security at all.

What's the point of encrypting the DNS lookup step if a middleman can still potentially see everything in plaintext?