Hacker News new | past | comments | ask | show | jobs | submit login

Split horizon was always a bad hack, there has always been alternatives. DoH could be used on the default DNS servers too, there is value of encrypted DNS on LAN as well.



> Split horizon was always a bad hack, there has always been alternatives.

I always see this repeated as a mantra, but never it's rationale. No company is going to advertise their internal infrastructure needlessly. There's no upside in the world knowing that your _kdc._tcp.company.com is 192.168.10.20; but there are downsides.

> DoH could be used on the default DNS servers too, there is value of encrypted DNS on LAN as well.

Sure, but hardcoding or statically-configuring the value is not the way. LANs need to have their DHCP tags respected. If one of them is "use this URL for DoH-server", that's fine.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: