Hacker News new | ask | show | jobs
by randomperson_24 1424 days ago
You could already use nextdns.io for ad blocking on android phones via DNS over TLS.
1 comments

I doubt that just using nextdns could help in that. Couldn't they just hardcode and make requests to, say 8.8.8.8 or an unknown address, to resolve their DNS-over-HTTP domains?
Yes they can. You need to additionally run a firewall on your mobile device (and/or a firewall on your home network) and block all of the common DNS IP. Then only NextDNS or your choice of DNS is available (and encrypted)

Google just wants you to use them for DNS so they can still see where you are going :-)

Any app that really wants to can just make a request to a plain IP, or have their own DoT/DoH resolver.

DNS-based blocking will never block a determined tracker.