nanog mailing list archives

Re: This DNS over HTTP thing


From: Frank Habicht <geier () geier ne tz>
Date: Wed, 2 Oct 2019 00:25:19 +0300

Hi,

On 01/10/2019 23:24, Warren Kumari wrote:
On Tue, Oct 1, 2019 at 3:42 PM K. Scott Helms <kscott.helms () gmail com> wrote:

They almost have to change the default since there are (comparatively) very few DoH providers compared to DNS 
providers.

From the link that Damian sent (emphasis mine):
"More concretely, the experiment in Chrome 78 will **check if the
user’s current DNS provider** is among a list of DoH-compatible
providers, and upgrade to the equivalent DoH service **from the same
provider**. If the DNS provider isn’t in the list, Chrome will
**continue to operate as it does today.**"

can we not also understand this as testing the waters in terms of
changes of browser behaviour without user knowledge?

and once one's browser uses DoH, how will we be sure that not half of
queries (DoH) are going to another server - maybe even google's?

slippery slope?

PS: in my opinion it would look a lot more not-evil-doing if the same
would be done with s/DoH/DoT/


Frank


Current thread: