DNS over HTTPS: things to consider when you go “private”

Currently reading
DNS over HTTPS: things to consider when you go “private”

What it means for privacy, security, and parental controls, and whether there’s a way to have them all. The term “DNS over HTTPS (DoH)” has been hitting the headlines in the past month: Google announced its general availability in June, and in July, Mozilla was nominated for “2019 Internet Villains” by the UK Internet Services […]

Continue reading...
- - -
Source: blog.synology.com
 
I hadn't heard of 'DNS over HTTPS' before.

I'm using AdGuard on my Synology via Docker, and my router (RT2600ac) now has 1.2.3 installed.

Does anyone know if enabling DNS over HTTPS on my router could cause problems when also run with AdGaurd? (Or vice versa)
 
I hadn't heard of 'DNS over HTTPS' before.

I'm using AdGuard on my Synology via Docker, and my router (RT2600ac) now has 1.2.3 installed.

Does anyone know if enabling DNS over HTTPS on my router could cause problems when also run with AdGaurd? (Or vice versa)
It won't. I have the same setup and there is no problem. ADGuard runs on DoH already anyways
 
Don't use DoH.

Use DoT.
Care to provide any reasoning for this?

its amusing how some people are getting worked up about this. If folk are pointing upstream to Google DNS, be that DOH or not, then Google already will have their browsing history.

Thats why I chose to trust Cloudflare (with DoH) over the folks at Mountain View.

Alternatively roll your own DNS server and point it to root servers. Less snooping, less protection, but no-one but you collecting your DNS request logs.
 
Correct! Apparently if DoH is enabled the DNS values in Internet settings will be ignored (see this reddit post).
Thanks

Oh gosh how distracted I am!
Not sure if it showed before but when you enable DOH there's a warning message that the DNS will change (please see pic attached) :)
 

Attachments

  • syno forum.png
    syno forum.png
    161.5 KB · Views: 190
The article seems to make two points:

1) For enterprises DoH is bad because it reduces monitoring visibility and makes control harder
2) It's not a magic bullet for security / anonymity

...well 'Duh' to both those points. but for the average home / SoHo user, the former isn't relevant, and the latter should be obvious, as there aren't any magic bullets where security is concerned - it's a constantly evolving battleground.

Making Requests - Cloudflare Resolver is the better article. I also notice that CloudFlare's DoH resolver supports DoT.

Definitely agree that DoT is a better solution than DoH, but only the latter is currently doable in SRM.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Thank you for the answers. It is runninig now without that one line. Will look later if I really need this.
Replies
28
Views
11,230
I guess it’s only Tomato and DD-WRT firmware then with such support at the moment! I’ve dabbled with them...
Replies
2
Views
4,111
I have a question. So this is network speed issue on your NAS or on your PC? Not sure I picked up what...
Replies
1
Views
1,852
Hi! Finally, Synology fix the issue. How? Disable PPPe acceleration. How? With a script that they do not...
Replies
15
Views
4,070
  • Question
User defined Destination NAT (DNAT) /Source NAT (SNAT) is what is needed. My last router had this and...
Replies
1
Views
1,901
  • Question
checkip.synology.com is forever present on the NAS as well where it runs every 3 minutes. I disabled QC...
Replies
2
Views
2,108
Replies
26
Views
6,308

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Back
Top