back
1 comments
Ah, so users can choose to override the local network administration? I didn't realise that. No way to prevent my family browsing to undesirable and unsafe sites without personally admin-ing each device and/or directly monitoring use?

I realise this is currently all leaky, my attitude was to put controls in place (DNS based) and if they learnt to hack around it then they're probably old enough to handle what they find ... doesn't work for malware, etc., however.

Presumably enabling DoH makes malware, advertising, etc., impossible to block?

When is MS Windows going to use DoH to force access for monitoring, currently I block a few domains.

> When is MS Windows going to use DoH to force access for monitoring, currently I block a few domains.

Microsoft doesn’t need DoH to circumvent DNS-based blocking. They control the OS and can make it do anything.

Have you seen this, MS running network traffic tunneled secretly over other people's networks?

Seems like it would be a CMA/CFAA infringement?

Microsoft has over 125 billion cash on hand[0]. I think they could spare some Azure compute to simply VPN all Windows DNS requests if they wanted (regardless of rfc8484).

0: https://www.microsoft.com/en-us/Investor/earnings/FY-21-Q3/p... (ctrl f "total cash")

I’m not saying they do. They wouldn’t even need to - they control the resolver. They could hardcode IP addresses, use domain fronting, use a CDN to proxy, load a list of IP addresses on every update check, … There are so many ways to circumvent DNS based blocking for someone that controls the resolver and network stack that it’s not even funny any more.

The fact that no one has shown that they do any of this tells you that they’re not trying very hard to circumvent blocks. Why would that change with DoH?

> No way to prevent my family browsing to undesirable and unsafe sites without personally admin-ing each device

No there's not, for good reason. From a technical perspective, this is indistinguishable from an abusive spouse or oppressive government trying to block sites.

That argument is pretty lame, buying a knife to chop carrots is indistinguishable from buying a knife to murder people.

Oppressive governments just block the providers of DoH that won't fold to them, meanwhile I lose the ability to control traffic on my own network.

I don't think DoH is going to make any difference to spousal abuse.

It's making the comparison to illustrate that the OS/User has no way to differentiate between a trusted router doing the blocking and the ISP blocking certain domains/injecting ads.

If you want to block domains on your devices, doing it on your devices themselves will be more reliable and implicitly requires you actually own & have admin rights on the devices you want to block domains on.

> Ah, so users can choose to override the local network administration? ... Presumably enabling DoH makes malware, advertising, etc., impossible to block?

It was always trivially possible to bypass DNS-based access control. Even before the establishment of DoH as a standard, you could have just served a text file containing the IP over HTTPS.

I hope by family you mean your children? Because otherwise this feature is very much designed to you and what you do.