

Xfinity/Comcast hijacks DNS, even if you use another DNS server (they just redirect DNS requests to them). I suspect that they’re using it for analytics data to sell while disguising it as “security”.
They also block access to root DNS servers, so you can’t use a full DNS Resolver run locally. It’s super f***Ed.
If you want to ensure they don’t do it, use your own modem and always force DNS over TLS.
I’m using a Ryzen Mini PC running Debian and Flex Launcher.
Works well as both a media consumption machine and light gaming rig.