prevent the pihole from being able to spoof itself as a legitimate DNS
Not to be pedantic, but a pihole is legitimate DNS. Being able to do your own DNS has always been a fundamental part of the Internet Protocol, and is used a lot in enterprise to handle name resolution for internal subnets and stuff like that.
FishFace@lemmy.world 6 months ago
SSL operates after name resolution. It’s one way that information about your browsing habits is not protected by application-layer encryption; the domains you’re visiting are available to your DNS server.
frongt@lemmy.zip 6 months ago
Unless you’re using DNS over TLS!
Or DNS over https, but that’s kind of gross.
Anivia@feddit.org 6 months ago
No, you misunderstood the parent comment. Your connection to the DNS server being encrypted doesn’t change the fact that the DNS server knows the domains you are resolving