The DNS over HTTPS (DoH) Mess
ID: dc4ffa3f-2cda-5bab-9600-409064c12fe4
STIX ID: report--dc4ffa3f-2cda-5bab-9600-409064c12fe4
Feed Name: Black Hills Infosec Blog
This article critiques DNS over HTTPS for centralizing control and facilitating surveillance capitalism, advocating instead for DNS over TLS while running an internal DNS resolver. It provides step-by-step guidance to deploy Stubby on Ubuntu, configure Bind to forward queries to Stubby, and implement iptables/IPSet rules to allow TCP/853 to Quad9, block known DoH providers, and prevent endpoints from bypassing internal DNS. The author aims to balance encryption, privacy, visibility, and operational stability, recommending local caching and domain filtering (e.g., Pi-hole) while rejecting browser-enforced DoH.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
