Hacker News new | ask | show | jobs
by egberts1 2019 days ago
I’m sticking with DNS over dual server/client certificate.

My home LAN gateway is blocking DoH because the hassle of issuing enterprise-based intermediate CA is not worth the effort to do a Squid TLS transparent proxy so that one can “Pi-hole” to block stray DNS/domains.

This means my own set of authoritative DNS servers.