Skip to content

DNS Over HTTPS Walks Straight Past Your Controls

DNS over HTTPS encrypts your lookups, which is good, and sends them to a resolver of the client’s choosing on port 443, which is the problem. Your own resolver never sees the query, so the blocklist it would have failed, the threat feed it would have hit and the log line it would have written all vanish. This post walks the mechanism: why one encrypted web connection among thousands is invisible at the border, who on a machine can pick a resolver you never chose (the OS, the browser, any app, any script on any web page, and malware), and the documented cases, from a page’s own JavaScript querying a public DoH endpoint that allows cross-origin requests, to Godlua and PsiXBot hiding their command channel inside DoH, to the OilRig APT exfiltrating data over it. Then the case that the privacy story is a cover: DNS over TLS already encrypted DNS in 2016, on a port the network operator can still govern, so the only thing DoH adds over it is defeating the admin, which is why the browser vendors who wrote and shipped it, and the advertising firm that runs the biggest public DoH resolver, are the ones who gained. Then the fix, which is not to ban encryption. Run your own DoH and DoT resolver, advertise it with Discovery of Designated Resolvers, refuse port 53, port 853 and known public DoH resolvers at the border, and answer the Firefox canary so the browser stands down. Keep the encryption. Take back who chooses the resolver. It closes on the fallout: the same DNS-based enforcement runs across Europe and in Australia, and courts in Italy, France, Belgium and Germany are now ordering the public resolvers themselves to block, with Cloudflare fined and appealing, Google refusing in silence and OpenDNS switching itself off for whole countries. The pattern underneath is a US design imposed on the world, and a US government that casts other countries’ laws as extortion of American firms and warns them not to comply.

24th September 2026 Â· 38 min Â· 9567 words Â· Damien Dye

The News Site Sent Me The Article, Then Deleted It

Newsquest, National World, Reach and others send your browser the complete article with its stylesheets, then run commercial anti-adblock and consent code that blanks the page, deletes every stylesheet every 100ms or covers it with a choice between 1,467 tracking partners and £2.99 a month. This walks through what that code does, the four reasons I call it malware, and the Chrome extension I built over one day to keep the page: pinning Newsquest’s adLight flag before the wall builds, dropping the timers scheduled from eval, killing the stylesheet stripper at schedule time, and refusing consent properly by answering the TCF API with no, pressing the vendor’s own reject button and never storing the record. Then the fixes that made things worse, the probe that said a broken page was fine, share buttons and the MSN feed, and what the extension will not do.

22nd September 2026 Â· 24 min Â· 5625 words Â· Damien Dye

What Renting Your Technology Costs

Once moving supplier is hard, the costs change shape. The price follows your exit cost. Profit is declared in one country and earned in another. The law follows who owns the company, not where the building stands. Part 2 of 8, in plain language.

25th August 2026 Â· 7 min Â· 1386 words Â· Damien Dye

Backdoors, and Who Gets Accused of Them

Shutting a supplier out on security grounds needs a standard, applied evenly. Part 6 of 8 sets out what has been established about weakened products and interception, including a Swiss parliamentary inquiry, and shows why a built-in way in belongs to whoever reaches it.

25th August 2026 Â· 6 min Â· 1099 words Â· Damien Dye