← Back to context

Comment by Ayesh

3 years ago

> On Android:

Most phones nowadays should have DoT support built-in nowadays.

> Most phones nowadays should have DoT support built-in nowadays.

DoT does help even if it can be trivially blocked (more than one way to do so, but blocking TCP on port 853 would do the trick)... DoT cannot help bypass SNI-based censorship (unless apps implement domain-fronting).

  • > DoT does help even if it can be trivially blocked (more than one way to do so, but blocking TCP on port 853 would do the trick)...

    Indeed, and this is exactly why DoH is better than DoT.

    > DoT cannot help bypass SNI-based censorship (unless apps implement domain-fronting).

    TLS ECH will. I can't wait for it to become mainstream.

I don't know what "DoH" or "DoT" are.

  • DNS over TLS.

    Android calls it "Secure DNS". It's in the connection settings, I believe starting from Android 9 or 10.

  • I'm not a big fan of jargon either, but if you clicked on one of those links, you'd see that it stands for DNS over HTTP or DNS over Tor.

    • Not sure what you mean, I clicked on the first link before commenting, for "GoodbyeDPI", and learned that it was a "Deep Packet Inspection circumvention utility (for Windows)", I still didn't know what DoT or DoH was, sorry.

      Most Android phones... have DNS over Tor... built in? This can't be, can it? I'm pretty confused.

      1 reply →