Factor in co-operation from CDN's and really that covers a vast array of data that the US Government could access.
Factor in co-operation from CDN's and really that covers a vast array of data that the US Government could access.
DoH pragmatically reduces their ability to conduct such global surveillance. "Pervasive Monitoring is An Attack".
We speak of man's laws and nature's as though they were the same kind of thing but they really, really aren't. I can no more magically replay the session keys from last week's Wikipedia visit in response to a court order, a warrant or the US Constitution itself than I could dance on the surface of the sun if they required that.
The idea here isn't that Public Enemy Number One today is protected from surveillance, but instead that you today are protected from the hypothetical surveillance of your past that might be authorised if some day you become Public Enemy Number One.
If gov tried to force CF to change that they would likely put up a huge public legal fight to prevent it whereas ATT / Verizon and Comcast would bend over backwards to secretly comply while also simultaneously seeing if they could inject some ads into the pages you visited.
In addition Mozilla put them through a rigorous process when selecting them as their default DoH provider which included them contractually agreeing to adhere to their stated policy. https://wiki.mozilla.org/Security/DOH-resolver-policy
Basically when you connect over https using TLS 1.2 to a site that is hosted on a shared server or behind a load balancer, your browser must tell it in clear text which host name it is trying to connect to. Encrypted SNI in TLS 1.3 also encrypts this info such that if you are also using DoH or DNS over TLS to encrypt DNS query then the ISP can only see the IP of server you connect to which is often going to be a huge cloud provider's load balancer that might serve hundreds or more different sites throughout the day / at the same time.