Temporarily using DoH from the Foundation for Applied Privacy.
Parameters :
network.trr.mode;2
network.trr.uri;https://doh.applied-privacy.net/query
network.security.esni.enabled;true
Don't use Chromium-based browsers !
https://github.com/bromite/bromite/wiki/Enabling-DNS-over-HTTPS
Test DoH and eSNI : https://www.cloudflare.com/ssl/encrypted-sni/
https://blog.plip.com/2018/04/22/stubby-pi-hole-quad9-lxd/
DoT : dot1.applied-privacy.net
Use Intra with DNS over HTTPS : Android : dot1.applied-privacy.net
security.tls.version.max;4
TLS 1.3 Early Data;Default
TLS 1.3 downgrade hardening;Default
Test TLS 1.3 : https://www.cloudflare.com/ssl/encrypted-sni/
media.av1.enabled;true
media.av1.use-dav1d;true
chrome://flags/#enable-av1-decoder
https://www.privacytools.io/ /!\ privacy.resistFingerprinting = true
breaks some web apps (e.g. Jitsi Meet).
https://vive-gnulinux.fr.cr/securiser-firefox/
https://textup.fr/277731WL (credits : LBD22)
https://github.com/arkenfox/user.js (user.js template for Firefox)