> If you don't like the fact that DoH is centralized in the hands of Cloudflare, all you have to do is offer a competing service.
You seem to be presuming that a single "service" is necessary. "Alternative" centralized services are still a centralized service. The solution to Cloudflare being able to log everything isn't to hand that same power to someone else.
I run my own recursive resolver. Only the first request for a domain's NS record goes to a centralized service; every other request goes to the domain specific nameserver. Asking ns.example.com for the A/AAAA record for www.example.com doesn't tell example.com (collectively) much more than they will learn from the HTTPS request that usually follows.
Yes, ".com" can log that I asked for the authoritative nameserver for "example.com", but this is usually cached. The centralized nameservice doesn't see most of the DNS traffic.
Yes, the communication with each domain's authoritative nameserver is often unencrypted. This is unfortunate, and I strongly support an encrypted replacement protocol for all communication with nameservers.
Using DoH sends all of the above to one entity... which then likely sends it unencrypted to the authoritative nameservers. The ISP learns about the result regardless right after the domain name has been resolved to an A/AAAA record, when the browser sends the TCP+SYN packet to start HTTPS.
> for a lot of people in a lot of countries, a choice to use any resolver that isn't controlled by their ISP/government is a step in the right direction
Providing this as an option for people in those situations is great. That doesn't mean it will be a benefit for everyone. For many people, DoH is a significant loss of privacy.
> So please stop trying to drag down other people who are doing their best to make progress.
Please stop using this cheap appeal to emotion that presumes one solution will help everyone.
> Show us the code or GTFO.
We don't need to when the existing DNS situation was already a better option. Please learn about the diverse way that DNS is actually used in practice. Also, please consider the damage that is done by encouraging apps to bypass OS-control of DNS. This takes a lot of control away from the user, and will piss off a lot of people that use DNS-based adblocking.