Pushing DOH sounds like a bad idea

This is in reference to the latest episode of Security Now @philodygmn. I think @pinter understood perfectly, and he is right, it doesn’t sound like a great idea to me.

@pinter What will make it “safe” will be the implementation of signed DNS entries via DNSSEC. Although I don’t know enough about DNSSEC to know if the entries are also time stamped… because you wouldn’t want it to be serving obsolete entries that should have aged out.