Currently the only mitigation is to constrain your browsing to properly configured https (SSL) web sites.
But it's very difficult to ensure that all the communications your device is making (background services, vendor apps...) go through that channel.
Reality is that DNS remains and will continue to remain a giant hole in TLS.