|
|
|
|
|
by labcomputer
646 days ago
|
|
They only need a certificate signed by an authority trusted by your resolver. And, unlike for the website itself, your browser does not show certificate information for the DoH server. DoH also does not solve the problem of where the DNS server you use gets its information from: A government can compromise the other side as well. |
|
Do your program language _show_ you the certificate information when you use an http library to connect to an HTTPS service?
Sure the other end of the DNS query may not be encrypted, but I can easily decide which government to trust, and run my DoH server there.