test-lists icon indicating copy to clipboard operation
test-lists copied to clipboard

Re-add use-application-dns.net - explicit signal for DNS filtering

Open R6CG opened this issue 2 years ago • 1 comments

With the news that Firefox plans to start enabling ECH in the next releases, I wanted to suggest people check censorship measurements for use-application-dns.net, because that canary domain is meant to disable DoH, and ECH depends on DoH.

use-application-dns.net had originally been added in #504 2019-09-19, but then it was deleted in #727 (a dead-domain check) on 2021-02-23.

Maybe prune-dead-urls.py was run on a network that reported NXDOMAIN for use-application-dns.net, since that is the signal that is supposed to signal DNS filtering is in place?

R6CG avatar Aug 29 '23 00:08 R6CG

The canary domain only applies to users who have DoH enabled as the default option. It does not apply for users who have made the choice to turn on DoH by themselves. https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet

dnscrypt-proxy also blocks *.use-application-dns.net . https://github.com/DNSCrypt/dnscrypt-proxy/issues/1205 https://github.com/DNSCrypt/dnscrypt-proxy/blob/92e842126d40f6fcb919bce72983748ddb34dac9/dnscrypt-proxy/plugin_firefox.go

Lanius-collaris avatar Sep 05 '23 21:09 Lanius-collaris