130

Context: A local movie app have this warning to me as I have this domain blocked with NextDNS ๐Ÿ‘Œ

all 8 comments
sorted by: hot top controversial new old
[-] TrickDacy@lemmy.world 16 points 11 months ago

This is actually great design.. you are being warned about a breach in privacy. How's the bad design?

[-] candybrie@lemmy.world 12 points 11 months ago

The two options are both "No". If you aren't going to give an option, don't give an option. It's confusing to have two options that are the same thing.

[-] 0x0@lemmy.dbzer0.com 13 points 11 months ago

If you blocked it at the DNS level, I'm surprised the error wasn't a resolution failure. Who's on the other side of this connection pretending to be Google Analytics??

[-] still@sh.itjust.works 2 points 11 months ago

next DNs probably redirects it to a landing page or something

[-] 0x0@lemmy.dbzer0.com 1 points 11 months ago

You're probably right. Rather than responding with NXDOMAIN, they're probably synthesizing A or AAAA records that point to their own server. IMO, this is super weird behavior in the era of HTTPS. I'm also pretty sure there's an IETF RFC that says recursive resolvers "MUST NOT" synthesize address records, but I can't seem to dig it up on my phone (pun intended ;).

[-] PoolloverNathan@programming.dev 1 points 4 months ago

It's an option, default off. If you enable it it prompts you to install the CA for the block page.

[-] 0x0@lemmy.dbzer0.com 1 points 4 months ago

They ask you to install a root CA? That would enable your DNS provider to MITM your TLS traffic. Yikes.

this post was submitted on 20 Oct 2023
130 points (94.5% liked)

Crappy Design

2830 readers
1 users here now

Noticed that theres no equivalent to r/crappydesign here yet so i made one

founded 1 year ago
MODERATORS