> Nearly 70% of smart TVs and 46% of game consoles were found to contain hardcoded DNS settings - allowing them to simply ignore your local network’s DNS server entirely.
> Nearly 70% of smart TVs and 46% of game consoles were found to contain hardcoded DNS settings - allowing them to simply ignore your local network’s DNS server entirely.
edit: method for this on pfSense: https://docs.netgate.com/pfsense/en/latest/recipes/dns-redir...
DNS over HTTP has got to be the most ill thought out "privacy" feature that has done more to HARM privacy then it could ever help
Whose privacy? DoH helps to protect billions in revenue for the ad network that funds Chrome, Firefox, Safari and web standards.
A better web will need a different revenue model.
In the meantime, here's a maintained guide to blocking DoH with pfsense, https://github.com/jpgpi250/piholemanual/blob/master/doc/Blo...
Says who? I think your data is very old considering that ECH replaced ESNI 2 years ago. IIRC it has ~50% adoption, same as TLS 1.3. Just about every company that cares about security supported ECH for years.
Moreover, someone has to move first. If DoH wasn’t widely deployed you’d be complaining that ECH is useless because DNS is unencrypted.
People really are gulible aren't they...
DoH is a not or a privacy feature. It simply changes who is collecting your data and makes it harder for responsibile network operators to protect their users under the guise that the big tech companies are really protecting the users from the network operators and "big bad ISPs".
Ironic given the billions big tech is making from that data.
In the case of cloudflare, it is going to be interesting how they continue to justify the free public services to institutional investors now that they are public. I have a feeling there is going to be some strong pressure to either cease the free services, or find away to monetize them which likely will involve some kind of usage of that data maybe not selling per say, but some other kind of targeting or something to add to the profitability of the company.
I am no more comfortable with cloudflare having my data than I am with google or verizion, I have never used any of their DNS services
> I am no more comfortable with cloudflare having my data than I am with google or verizion, I have never used any of their DNS services
It's not either/or. If you use Cloudflare or Google DNS and it isn't encrypted then Verizon has it too. With DoH they don't.
Web browsers are subsidized (free) by search (ad) revenue.
Authors' Addresses
Paul Hoffman
ICANN
Email: paul.hoffman@icann.org
Patrick McManus
Mozilla
Email: mcmanus@ducksong.com
* https://datatracker.ietf.org/doc/html/rfc8484DoH is the problem here, as it hides things from network operators making it harder to block ads, spam, and other items at the network level under the guise of privacy, when in reality DoH's actual goal is to further centralize the internet into approved gate keepers like CloudFlare and Google.
https://codeberg.org/unixsheikh/dohblockbuster https://openbsdrouterguide.net/#blocking-doh
Though in the case of a smart TV, you would want to block everything except for whichever streaming services you're subscribed to.