> It takes control away from the owner of networks, even when we're the owner of those networks.
My point is that even when you are the owner of a network, you shouldn't have control of traffic on it between endpoints that you don't own either of.
> what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS?
The Trojans could just hardcode the IP instead, so blocking DoH wouldn't magically guarantee you could catch them with DNS.
> So yes, your statement about control residing with the endpoints is correct, but DoH removes control, doesn't add it.
Which programs specifically don't let the user disable DoH? If none, then how does its presence remove control?
> For the case of "can't, because even if you change the setting, $evil_isp will hijack the queries anyway", that's FUD. There are many, many better ways to deal with evil ISPs.
Such as? How would you solve the specific problem of an evil ISP hijacking DNS?
> centralized entity like Cloudflare (who, by every right, are precisely in a position to be an evil ISP)
ISPs tend to have regional monopolies, but DoH servers don't. If Cloudflare becomes evil, you can just switch to some other DoH server.
> If you care to learn, consider things without DoH: you can edit your hosts file. You can choose your DNS servers. You can run a local recursive resolving DNS server. You can block ads and advertisingware using your DNS server and/or something like Pihole. You can block all DNS queries to the outside world on your network so that they all go through your own resolvers.
All but the last thing is still possible with DoH, and it's a good thing that it breaks the last thing, since doing that would affect other people's endpoints too.
> Next, consider a world where DoH is commonplace: you have no control over DNS lookups on your own system.
How do you figure? DoH is still configurable.
> Your only choice is to not run binaries that might do things you don't like.
I already don't.
> Want to block ads or adware, or adult sites, or conspiracy sites, or any of a number of other things on the Windows system that your child uses? Now Edge doesn't let you. Want to block the Trojans and phishing sites that Google serves through their ad network? Chrome doesn't let you.
Those are still easy: just point at a DoH server that does those blocks, the same way you'd point at an insecure DNS server that does them today.
> You can block common DoH servers, until Cloudflare puts them on the same address as the endpoints for their millions of hosting customers. But what happens when apps do DoH lookups using random Amazon AWS or Google Cloud servers? How do you block them? Do you block ALL https?
It's a good thing that network-level blocking of DoH is hard.
> You see, you'd give up freedom, and have everyone else give up their freedom, for some abstract "safety" from ISPs that use your DNS data. You'd apply a shitty fix for 1% of the people to 100% of the people, rather than create tools for the 1% to circumvent their evil ISPs.
What freedom am I giving up? What harm does DoH do to regular people?