Hacker News new | ask | show | jobs
by judge2020 2353 days ago
You could, but DoH exists to provide a crypto-based guarantee that they can't even passively monitor the DNS requests you're sending to the alt. resolver.
1 comments

DoH only hides the domain name lookup. You still connect to the other server by IP. Even $2.50/mo VPS plans offer a unique IP these days, and building a database of IP:hostname is extremely trivial, especially for ISPs that already run DNS resolvers.

But let's be real: the internet is quickly becoming a walled garden, so having access to DNS requests is mostly only going to give you a billion facebook.com + twitter.com + youtube.com + google.com + google-analytics.com lookups anyway.