But I strongly suspect we're in the minority and that something like this is the easiest -- and quite possibly the only -- way for many users to avoid DNS poisoning by ISPs.
One more thing to remember to turn off in Firefox, if you're running your own DNS over TLS with more elaborate config than what will be in Firefox.
One thing I like about this DNS over TLS is that now it should be possible to route DNS requests over tor safely to a more trusted DNS resolving endpoint. Though I haven't yet checked how it would work with Cloudflare.
Will I have to solve google captacha per handful of DNS requests if I try to access 1.1.1.1 from tor? Anyone tried?
What's the way to circumvent this problem? I'm frequently on public wifi's, so I need to access AP login pages without issue.
Unfortunately that has turned into an arms race: some operating systems switch to a different browser when they detect a captive portal. So captive portals try to avoid detection, etc.
Basically what you want is package that tries to detect a captive portal and when it detects one alerts the user and offer to start a browser that uses the DHCP-supplied DNS resolvers to interact with the portal.
Sure, would be nice for the OS to support it, but until that future point why wait.
Because with the current system I can configure my DNS to my liking at my router and it propagates to all devices. Replacing that with a system where after every Firefox update I have to double check whether Firefox is still doing what I want on all devices is a total pain in the ass by comparison.