Hacker News new | past | comments | ask | show | jobs | submit login

US ISPs are currently, actively, aggressively manipulating DNS. People shouldn't trust their ISP DNS. If they run normal DNS to a third-party resolver, their ISPs still see their queries. If they use DoH, they can't. If they use WireGuard, their ISP sees even less of their traffic, but WireGuard is harder to set up than DoH, which your browser will do for you.



Sure, but the post I was responding to was detailing how to set up your own DoH server, which is not so trivial.

I suppose you could set up an Internet-facing DoH server, and then point their routers (dhcp servers) at your new DoH server, rather than heavy-configuring their premise routers to use wireguard. (Of course then you're installing your server as a point of failure, which is probably not what you want to do!)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: