Hacker News new | past | comments | ask | show | jobs | submit login

It resolves via DoH and also offers a DoH server, so the ISP cannot.



Technically yes. But when you connect to the server the browser is also sending the address in plain-text (see SNI).

This will eventually be fixed with an extension to TLS 1.3 (see ESNI), but right now every address you access is sent via plain-text, thus can be intercepted by ISP unless you're on a VPN.

That said, PiHole's main selling point isn't that, it's blocking ad domains and for that it's doing a might fine job (I've had it running in my home for 6+ years).


> unless you're on a VPN

Then the VPN can see it all, and many VPN's seem to exist purely to be data minining companies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: