Understanding the Controversy Surrounding DNS over HTTPS (DoH)
By
Bogdanp
Kettled twice. Extra chewy, extra trustworthy.
Summary
The article discusses the concept of DNS over HTTPS (DoH) and argues against its use, stating that it does not protect DNS queries from surveillance but rather centralizes them to one entity. It provides a tip to disable DoH in Firefox by changing a configuration setting.
Key quotes
· 2 pulledDoH is not about protecting your DNS queries from peepers. That is a big lie. It is about making sure only one peeper can see all of your queries.
Refuse to use it today: Open about:config in Firefox and set network.trr.mode to 5. This will prevent Firefox from using DoH under all circumstances.
You might also wanna read
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·37m agoSecurity Flaw in ChatGPT for Google Sheets Enables Data Exfiltration via Prompt Injection
OpenAI's ChatGPT extension for Google Sheets, which has over 185,000 downloads in less than a month, is vulnerable to indirect prompt inject
promptarmor.com·3h agoPrompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
Quantum computing's security threats demand urgent preparation from IT professionals
The article discusses the impending quantum computing revolution and its dual nature: promising transformative advances while simultaneously
zdnet.com·7h agoInvestigator discovers unauthorized vote.gov domain registered to White House
The article describes an investigative journalist's discovery of a second, unauthorized vote.gov website registered to the White House, unco
CISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ
