And when malware gets on your network and starts using DoH to get around your home resolvers, what will you do?
* https://www.zdnet.com/article/first-ever-malware-strain-spot...
* https://www.zdnet.com/article/psixbot-malware-upgraded-with-...
As someone who works in IT, this is my problem with DoH.
And even when they did, creating various C&C servers, the lack of ESNI would allow for detecting activity once the daily domain creation algorithm was reverse-engineered:
* https://blog.malwarebytes.com/security-world/2016/12/explain...
Except using other ports would cause network monitoring software to throw red flags because of the "strange" traffic on non-standard ports.
> they wouldn't want to block [for example] all of Cloudflare or the GCP load balancers
If your only defense against blocking by your ISP is to centralize web server hosting, then you’re just moving the problem to there instead. Cloudflare also blocks, or “deplatforms”, those they deem unseemly. And once someone is taken off the centralized web server hosts, they can be blocked by your ISP again. You’re not solving the problem in the long term.
DoH is fighting yesterday’s war.
Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy. I don't want my traffic to bounce from Chile to Norway and then back to Chile when I do online banking. I run a VPN endpoint in Chile for my own traffic, but I don't need to push all of my home traffic through it....yet.
All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites, but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries.
That was true years ago, but nowadays I rarely percieve any speed difference at all when comparing browsing using Tor and non-Tor.
> Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy.
But, and here’s the crucial difference: with VPNs you have a choice. A wide variety of choice. With ISPs, especially in the US, not so much.
> All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites,
That’s due to be fixed with ESNI. Just wait for a technical fix.
> but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries.
That is true today, but when DoH and/or DoT happens, the ISPs will certainly switch to doing whatever still works. They are merely sniffing and proxying DNS traffic today because it still works, but the second it no longer works, they will switch to whatever does work. You can’t just work around the current mechanisms, you have to look a few more moves ahead.