Hacker News new | past | comments | ask | show | jobs | submit login

Why they advised DoH and not DoT? DoT is simpler, no http cookies ambiguity. Easier to block counter argument does not really apply to businesses...



For non-malicious apps, generally speaking DoT is something you need to specifically enable, whereas certain major applications are working towards using DoH by default (or they already do [0]). DoH is also mixed with regular HTTPS traffic, so it is much harder to detect and act upon - so businesses need to spend more effort to counter it. As a bonus, most of the mitigations in use here also apply to DoT, so you are also getting it in the bargain...

[0] https://blog.mozilla.org/blog/2020/02/25/firefox-continues-p...




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: