Reply to post: Who do you want to hide from ?

Google rolls out pro-privacy DNS-over-HTTPS support in Chrome 83... with a handy kill switch for corporate IT

alain williams Silver badge

Who do you want to hide from ?

DoH needs a server to answer DNS queries - that server gets to know a lot about you.

Use normal DNS and your ISP/company can see what you are trying to resolve. Even if you do not use its DNS servers it can sniff the packets as they go by.

If you live in a repressive regime (eg Egypt, China, ...) they can make your ISP hand over your DNS history or change stuff on the fly; so DoH might be good, although they can still see where your IP packets go to.

What about the DoH provider - what does it gain ? Knowledge of all the sites that you visit - good meat to the advertising machine for Google & pals - even when those sites do not run google analytics (or you have blocked the javascript). These DoH providers are subject to the Patriot Act or local equivalent - so, for some, the security is a fig leaf.

Oh - just because you do not think that your regime is repressive does not mean that your government is not snooping on you. DNS over TOR might be an interesting idea.

If you do run DoH then you might be visited by shady men and told to change your browser options - packet sniffing via your ISP will make it obvious if you have taken their 'advice'. So: will you make yourself a target for future visits ?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon