What's new

What's the point of DoH/DoT

N

nikr

Guest
I've been running Pihole with cloudflare doh proxy for sometime now. While it works ok, I've been considering ditching it for Asus-merlin built in dot with nextdns. But does DoH/DoT makes any difference. My ISP can still see the IPs i am communicating with and can do reverse dns lookup to see what I am doing if they want to and if they dont it does not really matter anyways. I understand it prevents alteration of reply but that can also be accomplished with dnssec.

I know I am missing something, but cannot figure out what..
 
Last edited by a moderator:
I've been running Pihole with cloudflare doh proxy for sometime now. While it works ok, I've been considering ditching it for Asus-merlin built in dot with nextdns. But does DoH/DoT makes any difference. My ISP can still see the IPs i am communicating with and can do reverse dns lookup to see what I am doing if they want to and if they dont it does not really matter anyways. I understand it prevents alteration of reply but that can also be accomplished with dnssec.

I know I am missing something, but cannot figure out what..
Much has been written on the topic. Boils down to what level of security or no security you are comfortable with.
This is a bit old but good: https://blog.apnic.net/2018/08/20/dnssec-and-dns-over-tls/
As for me I feel more comfortable using DoT (not DoH) with DNSSEC. We've gotten both built into the Merlin custom firmware for Asus routers.
 
An interview with Bill Woodcock (Quad 9 DNS) here.
He has quite the definite view of DoT vs DoH.
Well worth a read........

 
Similar threads
Thread starter Title Forum Replies Date
A DNS DoT, DNSSEC with Rebind Protection - Sanity Check. General Network Security 3

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Back
Top