DNS over HTTPS on by default is wrong.

The Internet is and was designed to be decentralized and open. This freedom is unequivocally how the Internet, and every other technology we love thrived and grew into what it is today. However, as time goes on the Internet is becoming radically centralized in the hands of a few companies (i.e., big tech in bed with the government – you know who they are). As more of our lives are spent online these big-tech companies, instead of trying to make the world a better place, are focused on monitoring and controlling us behind the curtain of “privacy” and “security for you”.

Enter DNS, one of the original Internet protocols that’s sole job is to map a server IP address to a friendly name. DNS happens before you do anything online and we cannot surf the Internet without it.  Example, Google.com is a friendly name that maps to thousands of server IPs behind the scenes around the world. No human can remember all the server IPs (ex:, but we can all remember ‘google.com’. 

This also makes DNS uniquely a powerful Internet content filter giving the DNS provider the ability to control what can be accessed by its users. DNS is probably the most widely used parental control / Internet security method in the world today.

DNS over HTTPS (DoH) is a new protocol for performing remote Domain Name System (DNS) resolution via the HTTPS protocol. DoH is essentially traditional DNS performed inside an encrypted HTTPS tunnel. DoH came out of nowhere about a year ago, by the big tech Google crowd, and is now being enabled by default (i.e., turned on without your approval) in Chrome & FireFox, two of the most popular browsers in the world. 

So why is DoH a problem?

The security aspect of DoH that we supposedly can’t live without is the HTTPS encrypted tunnel part which once made (i.e., once the HTTPS tunnel is made on either end) it cannot easily be broken or inspected. Therefor, he who controls the HTTPS encrypted tunnel, i.e., the DoH provider, controls what’s inside.

This means that:

  1. any browser with DoH turned on will tunnel through any existing DNS based parental controls / Internet security solutions.
  2. the DoH provider can see and control everything you do online.

DoH provides “privacy” at the expense of security. The big tech providers of DoH (Google, CloudFlair, etc) do NOT filter malicious websites, domains, and IP addresses. This has the effect of creating a mechanism by which the unwitting users of DoH bypass Internet security content filtering. The many millions of homes and businesses that use DNS to protect their users are directly harmed by DoH.

The notion that Google (one of the largest DoH providers) is interested in your DNS privacy flies in the face of their entire business model as a for-profit surveillance agency. Never forget this fact – if you are using anything online for free YOU are the product.

When one considers the impact this will have on the many young impressionable minds who suddenly find their misspelled search terms result in images no boy or girl should ever see in their lives, one wonders how these people live with themselves.

Furthermore, DoH is much more expensive to deliver than traditional DNS because of the added layer of encryption. For anyone to offer DoH they must be prepared to handle the massive increase of overhead costs (server + bandwidth + complexity + support). In other words, no one is giving DoH service away for free – they are getting something valuable to validate the effort. 

