Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DoH only increases privacy if the DoH provider is demonstrably more honest and privacy concerned than the network you're on. Mozilla defaults to Cloudflare, and Cloudflare are deceptive, disingenuous, and scammer friendly. Plus, many of us who care about privacy believe Cloudflare would sell access to the data they collect (the DNS lookups) to the US government for the right price.

The argument for this is specious at best - people who don't care enough to change their own DNS servers on their own networks apparently have to be saved from themselves, which is why Firefox decided to turn it on without prompting the user, in spite of many people complaining about changing the default without asking.

Enabling this canary domain doesn't disable DoH, if you've explicitly turned it and/or configured DoH with your own settings. DoH still stays on.



> many of us who care about privacy believe Cloudflare would sell access to the data they collect

The Cloudflare DoH privacy policy is already one of the least privacy friendly, so anyone who remotely cares about their privacy should not be using Cloudflare DoH.

For example, "transactional and debug log data" is stored for 25 hours at Cloudflare.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: