📝 Correction | DNS page doesn't mention DNS-over-TLS profiles, particularly opportunistic mode #2060
Loading…
x
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
In https://www.privacytools.io/providers/dns/#dns-definitions, there are definitions which don't include DNS-over-TLS having two modes, opportunistic/automatic and manual. In opportunistic mode DoT is attempted with DNS server provided by DHCP and wihle it is vulnerable for downgrade and MITM (due to certificate validation skipping), it doen't have the issue of centralising everything to a single encrypted DNS provider that is hardcoded in apps (which is often said about Firefox).
Why I am making the suggestion
This is an important difference between DoT and DoH, and I view PrivacyTools as being in a good position to inform users about it.
My connection with the software
I was one of the original authors of the DNS page and I think this information was removed as a part of some cleanup (or maybe it never got past draft). I have no connection to the RFCs or their authors that I know of.