And could you not circumvent this by either using another DNS provider?
And could you not circumvent this by either using another DNS provider?
They do not. As jonas-w points out, they would need a root certificate, which they don't have.
Much of the value of TLS is protection against untrustworthy ISPs.
You can allocate users to pools and provide contectivity based on the pool, ie allowing you to limit speeds of high usage users or have different filtering lists like this under 18s list.
With these devices you are able to block traffic to specific domains even if SSL is used with relative ease.
As it is done at network level, you can't bypass via different DNS provider, only vpns can bypass
Which is taking forever to be standardized.
Generally it’s a good idea to disable ISP content blocking if you can, because they can cause all kinds of problems (slowdowns, false positives).
But it doesn't go through your ISPs DNS infrastructure, it goes direct to the nameserver for the parent domain. And even that doesn't happen if your local resolver has the result cached. The easiest way to block DNS lookups is at the DNS server; using DPI to block DNS lookups is straying into sledgehammer/nut territory.