What am I worried about is DNS based black-holing is trivial to workaround against (as an ad-provider, one could simply force use a custom DNS client and pin to a DNS resolver of choice) [2][3][4]. What's next for pi-hole and solutions like AdGuard DNS short of re-writing packets going through UDP/53? Not sure how one would intercept the DoTLS / DoHTTPS connections, to rewrite those.
I'd like to hear if anyone has some thoughts on this, or if this has been discussed elsewhere.
[0] https://simplednscrypt.org/
[1] https://news.ycombinator.com/item?id=18788410
[2] https://news.ycombinator.com/item?id=19170671
[3] https://news.ycombinator.com/item?id=19106023
[4] Firefox 64 for PC, by default, was configured to ignore OS/Network Interface provided DNS resolver and used CloudFlare's over HTTPS.