










Today’s #WASSUP tip:
Turn on DNS over HTTPS (DoH) in your Firefox Preferences. Advanced Settings.
Custom: Always use secure DNS with control over your provider and fallback behavior.
[x] Always warn me if secure DNS isn’t available.
There are both security and privacy reasons to use DoH.
Step-by-step instructions:
1. open Firefox Preferences ("Firefox" menu, "Preferences" item)
2. Type “DoH” in the auto-activated search box
3. Scroll down to where it says “DNS over HTTPS” under “Privacy and Security”
4. Click “Advanced Settings”
5. Choose the “(•) Custom” radio button that says “Always use secure DNS with control over your provider and fallback behavior” right under it
6. Check “[x] Always warn me if secure DNS isn’t available.”
Privacy: the domain name of every website you browse is sent to the local router (e.g. WiFi), and on up to whatever internet service provider you’re connected to. Everything along the way has the ability to track what domains / websites you are using, how often, and build a profile accordingly, perhaps even matching it with stored profiles.
The sites you use, how frequently, what time of day, may all be enough information to create a unique fingerprint of you, to uniquely identify you, and perhaps target you.
By using DoH exclusively, every one of those domain names is sent only to your DoH provider (e.g. Cloudflare or NextDNS) blocking your local router, WiFi, and internet service provider from making a list of which websites you visit, or at least making it much harder (and both privacy and security are about making it harder for adversaries). They can still track what IP addresses you access, but that‘s much less information, and much less reliable over time.
Security: if your local router, WiFi, or internet service provider is compromised by an attacker, they can theoretically pretend to be any website you are trying to access (DNS hijacking), and then capture your credential as you login (username, password, even 2FA), and instantly re-use them to pretend to be you (credential stuffing) and sign-in to that website. Once they do that, they usually get a "long-lived" session token (like a session cookie) that they can re-use to pretend to be you, repeatedly, until that session token expires. Some don't expire for months or even years.
For example, if you’re using public WiFi, at a cafe, or a hotel, or airport, you have no idea if their routers or internet service providers are secure, and increasingly, unfortunately, we know that they are often compromised by various network attackers.
We know this is actively happening from both frequent news reports:
* https://news.google.com/search?q=wifi+dns+hijack
And from Anthropic’s report published mere days ago:
* https://www.anthropic.com/threat-intelligence-report-september-2026
* full PDF: https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
E.g.:
“They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor (a technique known as DNS hijacking). Guests of hotels using the compromised vendors who connected to the hotel WiFi had their traffic, device identifier and IP address sent to the actor’s servers. At that point, ClickFix-style lures were staged to deliver Windows, Android and iOS malware to the victim’s device. The actor was able to use a combination of guest information stolen from the hotel management systems with the data stolen from individual guests’ devices to focus additional targeting efforts.”
And it only gets worse from there.
When you activate exclusive DoH use, Firefox skips using those local DNS services, and instead directly contacts the DoH provider for DNS queries (to connect to the websites you access).
For more about how DoH works in Firefox, see the FAQs:
* https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs
Glossary:
ClickFix
https://en.wikipedia.org/wiki/ClickFix
Credential stuffing
https://en.wikipedia.org/wiki/Credential_stuffing
DNS hijacking
https://en.wikipedia.org/wiki/DNS_hijacking
DNS over HTTPS (DoH)
https://en.wikipedia.org/wiki/DNS_over_HTTPS
Replay attack
https://en.wikipedia.org/wiki/Replay_attack
This is my seventh #WASSUP2026 post, and fifth useful web tip for September.
✨ Weekly Tipster (https://tantek.com/2026/244/t1/september-blogging-challenge-wassup)
#DoH #DNSoverHTTPS #Firefox #tip #webTip #browserTip #webBrowserTip #security #privacy #cyberSecurity #DNS #DNShijack #DNShijacking #hotelWifi
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。