Menu

📰
0

Reddit - Please wait for verification

Technical Information Security Content & Discussion·/u/AnywhereOk3723·4 days ago
#U937JVWp
Reading 0:00
15s threshold

The security angle on encrypted DNS is often oversimplified. DoH prevents ISP-level snooping and basic DNS hijacking, but doesn't protect against a compromised resolver. DoT is easier to detect and block, which has real implications for threat actors trying to exfiltrate via DNS. DoQ is interesting from a security perspective because QUIC's connection ID migration makes traffic correlation harder. Article includes benchmark data and practical server config — but mostly written for the "which threat model does each protocol address" question. submitted by /u/AnywhereOk3723 [link] [comments]

Read More