Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That’s now how DNS blocking work.

The default DNS servers used by ISPs reply with the government notice website’s IP address, instead of what other global authoritative resolvers are providing. HTTPS does not prevent this from happening.

Instead, I believe you are thinking of DNSSEC (1), which would prevent such dns rebinding.

(1) https://www.cloudflare.com/dns/dnssec/how-dnssec-works/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: