← Back to context

Comment by unethical_ban

18 hours ago

A decent corporate policy will block or decrypt DoH, same as it blocks direct outbound DNS.

The hope is we eventually get enough things like DoH and ECH that it stops being feasible for corporate policies to block things.

  • Ah, are you a data exfiltrator or a ransomware operator? I jest.

    I think the network as a chokepoint will slowly go away due to improvements in cryptography, and we'll need the endpoint to do all the inspection and enforcement.

    • > I think the network as a chokepoint will slowly go away due to improvements in cryptography, and we'll need the endpoint to do all the inspection and enforcement.

      That's exactly what I want, because any solution other than that one would allow network operators to snoop on other people's endpoints.

      1 reply →