Hacker News new | ask | show | jobs
by jeroenhd 104 days ago
> you just need to trust the resolver you're DoH'ing to

I don't trust the public DoH resolvers that much, actually, and neither do I trust my own ISP. I know for a fact that they mess with DNS records because of court orders, and I want to know when that happens.

DoH and DoT are not the modern DNSSEC alternatives we need. They naively assume that the DNS resolver always speaks the truth.