DOH is suppose to protect against DNS snooping from third parties but due to the inital host handshake which is unencrypted the DNS host is made visible to third parties. I am aware cloudflare is testing ODOH, obilivious DNS over HTTPs to correct for this security issue. https://developers.cloudflare.com/1.1.1.1/encryption/oblivious-dns-over-https/
What benefit does DOH today provide to users ?
submitted by /u/WheelPerfect3737 to r/CloudFlare
[link] [comments]
Source: r/CloudFlare · by /u/WheelPerfect3737