Reason against DNS over HTTPS (DoH)

Discussion in 'Chit Chat' started by CHEF-KOCH, Dec 1, 2019.

  1. CHEF-KOCH

    CHEF-KOCH MDL Expert

    Jan 7, 2008
    1,192
    1,185
    60
    #1 CHEF-KOCH, Dec 1, 2019
    Last edited: Dec 23, 2019
    What is DOH?

    Overview articles:

    What's wrong
    ?!

    While DNS-over-HTTPS (DOH) gets hyped here are some reasons against DOH.

    Browser support:
    • Firefox (US users only, as "test") but can be enabled via about:config
    • Chrome / Chromium via flags (same as Firefox, it's currently a test)
    OS support:
    Breakage & concerns:
    • HOSTS can't be blocked, it gets ignored.
    • VPN "leak protection" will cause problems due to the nature of how DOH works.
    • Firewall bypasses possible.
    • New tracking possibilities (encryption in general does not prevent or stops tracking)
    • Other concerns mentioned.

    Cracking TLS connection (example provided by Johannes B. Ullrich)

    What should you use instead?

    Reference
     
  2. Lobotox

    Lobotox MDL Novice

    Jan 10, 2019
    16
    2
    0
    It's still better for most ppl then plain DNS, thought.
     
  3. CHEF-KOCH

    CHEF-KOCH MDL Expert

    Jan 7, 2008
    1,192
    1,185
    60
    #3 CHEF-KOCH, Dec 2, 2019
    Last edited: Dec 23, 2019
    (OP)
    I updated opener, Johannes B. Ullrich cracked DOH (MITM + redirection). He provided two short examples.