Skip to content

Comment on An Exercise Program for the Fat Web

Comments

Doesn't DNS over HTTPS and HSTS bypass pihole?

(isn't it funny how every single "modern web security" feature, from DNS over HTTPS, to HSTS even to HTTPS itself always ends up with someone giving up control to 3rd parties yet this is always dismissed and pushed through insane amounts of peer pressure - usually by people who have vested interests in those 3rd parties - because 'security'?)

My network is setup so local dns goes to the pi-hole which uses dns over https.

DNS over HTTPS against a server you can't choose would do so, yes.

You could still shut down the initial DNS query for the dns-over-https provider and make it unreachable

Some people refuse devices that do not accept DHCP assigned DNS servers.[1]

[1] https://mailarchive.ietf.org/arch/msg/dnsop/WCVv57IizUSjNb2R...

You can also reroute port 53 traffic not from your internal dns server to your dns server...

So does simply using a different DNS server than the network supplies, unless you’re blocking port 53.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.