Hacker News new | ask | show | jobs
by rsync 1491 days ago
Your browser (or your tv) can just skip your entire dns infra and make its own lookups over https- which you won’t see.

That’s the evil genius of doh- you can’t block 443 and their “dns server” could be the same hostname as the site you visit … and now we’re discussing mitm’ing ourselves…

Sigh.

1 comments

Could, but do? I have never seen DNS or DOH pinning. Seems fragile. Would likely fall back to host resolver anyway.