Nextdns can be bypassed by... Nextdns!
Nextdns blocks every method to bypass the filter, except itself.
If you put a random Nextdns ID on your browser it will override the Nextdns ID of your system and even the ID of the Nextdns app.
On firedox you don't even need to put in another ID, if you choose NextDNS on the safe dns page it will also override the system ID.
I think it should be a way to avoid this and for Nextdns to follow the system/app ID, ignoring the one on the browser if it's diferrent.
6 replies
-
It's not a bug, it's a feature of DoH. Firefox specifically doesn't send user agent with DoH requests, so NextDNS can't tell if a request comes from Firefox or other apps (actually, most privacy-respecting app deliberately don't send any data except the URL and the DNS payload itself).
Thus, there's no way for NextDNS to tell which is the "authoritative" ID of a particular system. Imagine what happen if your ISP use CGNAT and other users of NextDNS shares your IP, would you like your config to randomly change just because of that? Or if someone in the house sends a Do53 request through IPv6, should the linked config become authoritative for the entire household just because the router and OS use DoH?
Now, the NextDNS *app* can be configured to override/lock browser's DoH settings, but while it's expected for a corporate/parental lock app, currently that's not the NextDNS app proposition, and moving towards that might sour the relationship between NextDNS & Firefox, also against users who might simply want the usability of the app without the baggage. -
""You misunderstood the point of DoH, there's no signal that says "hey, I'm the reigning setting for this network, you must ignore other configs". ""
=>Then how can they block evading methods like putting another DoH service? Because the pages don't load if you do that with that setting on.
"Tor can't be blocked by DNS, that's the point of Tor, evading censorship."
Of course it can, it's blocked by the same option I mentioned above, and it works, I test it.
"NextDNS is not a parental control app."
If it isn't, then why bother to put parental control in the settings? '-'
Content aside
- 1 yr agoLast active
- 6Replies
- 1034Views
-
2
Following