Hacker News new | ask | show | jobs
by gsich 2042 days ago
If your ISP is running the DNS with DoH/DoT then those queries can still be modified. Encrypted DNS does not solve the problem of DNS record manipulation.

For the rest, encrypted SNI might help, but it's still a draft so not really in use. Also 95%+ of sites are identifiable by IP only.