Windows 10 will reach EOS (end of support) on October 14, 2025. For more information, see this article.

חיפוש בתמיכה

יש להימנע מהונאות תמיכה. לעולם לא נבקש ממך להתקשר או לשלוח הודעת טקסט למספר טלפון או לשתף מידע אישי. נא לדווח על כל פעילות חשודה באמצעות באפשרות ״דיווח על שימוש לרעה״.

מידע נוסף

DoH question -- am I understanding this right?

  • 2 תגובות
  • 0 have this problem
  • 27 views
  • תגובה אחרונה מאת markwarner22

more options

It seems to me that Firefox's DoH implementation is not just pointless but actually harmful. It is security theater. Let me explain:

  • There is no fine-grained control
  • There is no ability for the user to choose what level applies to what networks
  • Default Protection provides no protection when there is a canary domain (trivial)
  • Increased Protection provides no protection when the default provider fails (trivial)
  • Max Protection requires manual intervention when the default provider fails
  • Bonus: it's inconvenient or impossible to use on mobile

For DoH to be useful, the user has to invest effort they could better spend setting up a proper system-level solution.

It seems to me that Firefox's DoH implementation is not just pointless but actually harmful. It is security theater. Let me explain: * There is no fine-grained control * There is no ability for the user to choose what level applies to what networks * Default Protection provides no protection when there is a canary domain (trivial) * Increased Protection provides no protection when the default provider fails (trivial) * Max Protection requires manual intervention when the default provider fails * Bonus: it's inconvenient or impossible to use on mobile For DoH to be useful, the user has to invest effort they could better spend setting up a proper system-level solution.

כל התגובות (2)

more options

When I said "default provider", I meant the provider that is used by default, according to the user's preferences (or according to Mozilla's preferences in the case of Default Protection). Of course, if the user sets a lesser known DoH provider, some of the issues are less significant. It mainly applies to the major DoH providers.

more options