Skip to content

DNS Over HTTPS Walks Straight Past Your Controls

DNS over HTTPS encrypts your lookups, which is good, and sends them to a resolver of the client’s choosing on port 443, which is the problem. Your own resolver never sees the query, so the blocklist it would have failed, the threat feed it would have hit and the log line it would have written all vanish. This post walks the mechanism: why one encrypted web connection among thousands is invisible at the border, who on a machine can pick a resolver you never chose (the OS, the browser, any app, any script on any web page, and malware), and the documented cases, from a page’s own JavaScript querying a public DoH endpoint that allows cross-origin requests, to Godlua and PsiXBot hiding their command channel inside DoH, to the OilRig APT exfiltrating data over it. Then the case that the privacy story is a cover: DNS over TLS already encrypted DNS in 2016, on a port the network operator can still govern, so the only thing DoH adds over it is defeating the admin, which is why the browser vendors who wrote and shipped it, and the advertising firm that runs the biggest public DoH resolver, are the ones who gained. Then the fix, which is not to ban encryption. Run your own DoH and DoT resolver, advertise it with Discovery of Designated Resolvers, refuse port 53, port 853 and known public DoH resolvers at the border, and answer the Firefox canary so the browser stands down. Keep the encryption. Take back who chooses the resolver. It closes on the fallout: the same DNS-based enforcement runs across Europe and in Australia, and courts in Italy, France, Belgium and Germany are now ordering the public resolvers themselves to block, with Cloudflare fined and appealing, Google refusing in silence and OpenDNS switching itself off for whole countries. The pattern underneath is a US design imposed on the world, and a US government that casts other countries’ laws as extortion of American firms and warns them not to comply.

24th September 2026 · 38 min · 9567 words · Damien Dye

Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.

A protocol helper — SIP ALG, FTP helper, H.323 ALG, conntrack helper, call it what your vendor calls it — reads the payload of a connection, finds an address and a port written in the text, and opens an inbound pinhole for them. It cannot tell whether that text came from a real FTP client or from a hidden form on a web page, because there is nothing in it to tell. Samy Kamkar proved the browser case in 2010. NAT Slipstreaming proved it again in 2020, and Armis extended it in 2021 to reach any device on your network, not just the machine that clicked. The IETF asked for these off by default in 2007, Linux turned them off in 2016, and the browser vendors ended up shipping a blocked-port list that reads like a directory of conntrack modules. This post walks the mechanism diagram by diagram — the expectation table, the segment-alignment trick, H.323 call forwarding, the IRC helper that fires on somebody else’s message — takes in the IPsec pass-through helper, which cannot read ESP at all and steers inbound packets on an SPI it watched go past in the clear, sets the lot against the Cyber Essentials firewall control it plainly fails, and gives the commands to turn it all off on Linux, Cisco, Juniper, FortiGate and MikroTik.

14th September 2026 · 54 min · 12564 words · Damien Dye

Ping: The Diagnostic Tool That Opens a Whole Lot More

Ping, not the rest of ICMP, is the liability: echo is a channel every host must answer with your own bytes, so a network that ‘only allows ping’ already has a full VPN out. This walks the threat first — what it costs your egress, and how a visitor on your WiFi or an unlocked ethernet port can open one — then three working tunnels built on ping alone (Hans, icmptunnel, and a short Python one with AES-128), the MTU and IPv6 catches, and the rule that shuts it: drop echo, keep the errors, in nftables, pf, Cisco, Junos, MikroTik and Windows.

1st September 2026 · 36 min · 7657 words · Damien Dye

The Firewall Is Eleven Hops Away

“Port 445 is blocked somewhere” is not a diagnosis, and it is why firewall tickets bounce between you and your provider for a week. Every router on the path owes you an ICMP Time Exceeded when your hop budget runs out, and that turns a timeout into a distance. I walked the TTL up on my own line and found three faults I did not know I had: an SMB drop eleven hops out, forged SMTP resets one hop away, and an IPv4 rule with no IPv6 twin.

28th August 2026 · 38 min · 8038 words · Damien Dye