[0]: https://github.com/mozilla/policy-templates/blob/master/READ...
[1]: https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
[0]: https://github.com/mozilla/policy-templates/blob/master/READ...
[1]: https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
I realise this is currently all leaky, my attitude was to put controls in place (DNS based) and if they learnt to hack around it then they're probably old enough to handle what they find ... doesn't work for malware, etc., however.
Presumably enabling DoH makes malware, advertising, etc., impossible to block?
When is MS Windows going to use DoH to force access for monitoring, currently I block a few domains.
Microsoft doesn’t need DoH to circumvent DNS-based blocking. They control the OS and can make it do anything.
Seems like it would be a CMA/CFAA infringement?
0: https://www.microsoft.com/en-us/Investor/earnings/FY-21-Q3/p... (ctrl f "total cash")
The fact that no one has shown that they do any of this tells you that they’re not trying very hard to circumvent blocks. Why would that change with DoH?
No there's not, for good reason. From a technical perspective, this is indistinguishable from an abusive spouse or oppressive government trying to block sites.
Oppressive governments just block the providers of DoH that won't fold to them, meanwhile I lose the ability to control traffic on my own network.
I don't think DoH is going to make any difference to spousal abuse.
If you want to block domains on your devices, doing it on your devices themselves will be more reliable and implicitly requires you actually own & have admin rights on the devices you want to block domains on.
It was always trivially possible to bypass DNS-based access control. Even before the establishment of DoH as a standard, you could have just served a text file containing the IP over HTTPS.