Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Regarding the Pi-Hole issues... a few days ago, I decided to set up firewall rules to block all outgoing DNS and DNS-over-HTTPS traffic, except one coming from my Raspberry Pi. I discovered two things:

My nVidia Shield TV was desperately trying to connect to Google's DNS. So yeah, I wasn't being paranoid!

My phone's Google Play Store refused to work without using Google's DoH. That's the troublesome side effect if DoH.



How do you block DNS-over-HTTPS?

Are you MitM’ing the calls? FQDN/IP blacklist?


No one except Cloudflare is really doing ESNI, so you can just block dns.google.


How would you know if another entity is using ESNI?


Generally to check I just use Wireshark, but if they're big enough (Google), they'd probably talk about it. Also, ESNI isn't even the default in Firefox, and it's just straight up not implemented in Chrome.


Sorry, I meant DNS-over-TLS. I blocked port 853.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: