Mozilla for example is going to force everyone to use CloudFlare as a Resolver
Mozilla for example is going to force everyone to use CloudFlare as a Resolver
Do you have any evidence that they're going to force anyone to do that?
I should not have to dig deep into the internals of Firefox to opt-out of sending all my traffic to CloudFlare, a company proven time and time again to be pro-censorship and anti-competitive
Firefox's choice isn't the best but you can disable it. Set network.trr.mode to 5 in about: config, which means disabled and deliberately configured as such. Then Firefox won't ever try to use DoH.
As others have pointed out, you can also use other resolvers than cloudflare's, through network.trr options.
Shameless plug: https://GitHub.com/yegle/your-dns
Even still filtering based on SNI will work for a long time yet. Yes, ESNI is on track to becoming to a standard but support for legacy devices/browsers means it to will rely on network tests for support - so it can also be disabled.
At least a browser might have a user setting to disable it.
Keep in mind you're on HN-- we tend to be a more technical population :). If you're interested I found this on StackOverflow via Google: https://unix.stackexchange.com/questions/144482/iptables-to-...
You'll have to Google how to set up iptables/telnet or ssh on your router yourself, assuming it supports it.
The next game will probably be mitming these devices by flashing a new CA store.
There is no general solution to running an openly adversarial app/device in your network.
https://twitter.com/selenamarie/status/1175092910200483840?s...