If Google actually cared about this, why bother going through the faff of making and standardising a new protocol?
You don't need a "DNS Standard" to be able to do name resolution between a client and a server you control. Just make up your own, pick a network transport (HTTPS works in most places!) and deploy it without telling anyone.
I don't follow what connection that has to Firefox. Seems like Google already comfortably solved their problem with Chromecast without needing a standard or anyone else to implement it.
Like IBM patenting everything that any of their employees ever stumbled upon there is value to controlling and defining standards (both inside and outside of tech).
But if every application and hardware appliance is using its own DoH settings, instead of doing the expected thing and getting its DNS settings from the system, using a PiHole becomes increasingly difficult.
Sounds like what I need is a VPN or Tor in these cases. To such regimes if FF provides a way to bypass their restrictions FF would end up being classed contraband similarly.
Tor is actually worse in this regard. E.g in Russia public Tor bridges are blocked, so you can't connect to it without extra steps. Some public VPNs are blocked too.
But DoH makes the price of blocking a single domain too high, for example, if Cloudflare were to use it, the only way would be to block every service that uses CF.
Okay, so I’m an oppressive state that has the wherewithal to block Tor but I’m not going to block DoH, because “the cost is too high” when I could previously mine DNS for free? I think I’d be blocking it and my citizens use a fork of FF that doesn’t force DoH.
You misunderstand what making the cost too high means. The goal is to make it so the only way to block DoH is to block all of Cloudflare and Google, and maybe eventually all of AWS and Azure too.
No that’s what I understood you meant by cost alright, and notwithstanding many regimes being able to pay just that, it’s hardly the case that prohibiting the use of DOH you’re going to be blocking those sites.
Perhaps, but the idea is to take the lead- and thus when all other browsers ,or most of them ,adopt this, that will be a little trickier to classify every browser in this manner.
Overall, this will have an impact in the many regimes- and perhaps is one of the best methods of doing so.
While it is still ...having faith in Cloudflare(one could audit them, but of course the question is how by-nature are they built to resist threats from APTs to the US gov coming knocking for info on Snowden or a similar person, looking for possibilities of compromise) -
I think of the Ukraine Starlink situation-
Overall, the Starlink terminals can be targeted by their signals, - but there's so many ,that Russia would need to do a massive ASAT campaign, or start spam detonating kiloton/megaton warheads in space to really try to disable Ukraine's ability to communicate even when all other networks get cut off, or isolated. And they mgiht be one of the very few capable of that type of escalation, but right now they're getting stymied by groups that are en - masse, accessing something that makes it harder to control, deny info, influence and crush them.
Overall a net positive, but with drawbacks- but their overall situation and ability to choose how they want to operate is increased.
VPNs and TOR are gaining popularity, but this covers those who wouldn't be able to use or figure out those for whatever reason, but who can use a web browser.
I think i've seen the Cloudflare CEO around - i wonder if any cloudflare employees will comment on the risks i mentioned before(centralized source providing availability, US GOV deciding to take interest...)
Firefox actually can solve this- by attempting to pursue deals with more than Cloudflare and NextDNS
> people are throwing it away
It is not meant to replace DNS or make it impossible to work.