zlacker

[parent] [thread] 2 comments
1. JohnFe+(OP)[view] [source] 2023-02-24 00:32:35
> force all 443 traffic though a proxy

That's insufficient. There's nothing stopping a web site (or ad on a website) from forming its own DoH request that bypasses the browser and the port. It can be done entirely within the HTTPS stream.

replies(1): >>tsimio+xK
2. tsimio+xK[view] [source] 2023-02-24 07:21:27
>>JohnFe+(OP)
If you're monitoring the HTTPS stream, you'll see it. The point of the proxy is exactly to inspect the content of HTTPS requests (that's why you need to install your own certificate).
replies(1): >>JohnFe+NL1
◧◩
3. JohnFe+NL1[view] [source] [discussion] 2023-02-24 15:56:45
>>tsimio+xK
Yes, exactly. That's what I do -- I MITM all HTTPS streams for this purpose.
[go to top]