[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Mozilla Firefox DoH to CloudFlare by default (for US users)?



On 9/13/19 7:05 AM, Simon Richter wrote:

Mandatory Encrypted SNI with no fallback option -- everything else can be
circumvented easily.

This is a game that we should not play, really. It raises the cost of
running a service on the Internet so only big players can afford to do so.

Does it? I haven't personally deployed it yet anywhere, but when I briefly looked into it, it appears to require adding a DNS record & some web server config. If anything, it appears to be harder to do if you're a big player (e.g., making sure your DNS servers always return matching ESNI and A/AAAA records, even when you have geo-targeted DNS — so much easier when you only have one server.)


Reply to: