Hacker News new | ask | show | jobs
by egyptiankarim 2229 days ago
"Important" in the sense that many IT organizations have predicated their data forensics and incident response capabilities on being able to intercept and analyze traffic at arbitrary points within their corporate networks.

That's not to say that those choices reflect good architectural design, to be sure quite the opposite. But like many things in enterprise IT risk management, it comes down to where you spent your money, and things like DoH/DoT force will force certain organizations to admit "a lot in the wrong place".

2 comments

To be clear, I'm not asking for the ability to intercept DNS requests, or encrypted traffic, at all. I'm fine (and encourage) encryption on the wire. I'm just as happy to get the logs on the local system, and ship them off.
Much of this comes from regulatory oversight of specific industries. DoH isn't going to fly in the banking sector for example.