DoH question -- am I understanding this right?
It seems to me that Firefox's DoH implementation is not just pointless but actually harmful. It is security theater. Let me explain: There is no fine-grained control … (閱讀更多)
It seems to me that Firefox's DoH implementation is not just pointless but actually harmful. It is security theater. Let me explain:
- There is no fine-grained control
- There is no ability for the user to choose what level applies to what networks
- Default Protection provides no protection when there is a canary domain (trivial)
- Increased Protection provides no protection when the default provider fails (trivial)
- Max Protection requires manual intervention when the default provider fails
- Bonus: it's inconvenient or impossible to use on mobile
For DoH to be useful, the user has to invest effort they could better spend setting up a proper system-level solution.