Hacker News new | ask | show | jobs
by Daho0n 1977 days ago
>thus bypassing the enterprise's ability

I think you could change it to read " bypassing the NSA's ability" and find the real reason behind this.

1 comments

They aren't recommending you don't use DoH. Just that you don't allow individual apps to bypass your enterprise resolver. In fact I use the same strategy at home (with DoT) to enforce ad and tracker blocking. It's just common sense really.

From the document: >[...] NSA recommends that the enterprise DNS resolver supports encrypted DNS, such as DoH, and that only that resolver be used in order to have the best DNS protections and visibility.