Live data from Hacker News

Improving DNS Privacy in Firefox

blog.nightly.mozilla.org

111–120 of 126 posts

Re: Improving DNS Privacy in Firefox

#111
post #39

Earlier quoted context omitted.

> but I refuse to let anybody know that I want to communicate with Bob That's not the problem though. You're not trying to stop an eavesdropper knowing you're communicating with a particular server, but rather which hostname you're talking to them as. To extend the Bob analogy; you're not trying to hide that you're communicating with Bob, but that you're speaking to each other as members of Fight Club. It's certainly…

You say "difficulty", the evidence seems to suggest impossibility. I am 100% certain that if you have an actual plan for how to do this without an extra round trip the TLS WG wants to hear about it (but please read the draft with the problem statement first so that you don't embarrass yourself and propose something that doesn't actually solve the problem) In order to be sure we're talking to Bob, so that it's OK if B…

Forgive me if there's some flaw I've overlooked in this approach, but couldn't you use DNS to aid in this? I.e. add Bob's public key to the DNS for fight.club which you get for free in round trips, as you're resolving the A & AAAA records anyway. You then encrypt the SNI asking for fight.club (along with a random nonce) with Bob's pubkey.

Of course, this approach would require the DNS record is authenticated, so DNSSEC is a must, added to which the DNS resolution must be encrypted, so DNS over HTTPS, DNSCurve, etc.

Re: Improving DNS Privacy in Firefox

#112
post #101

Earlier quoted context omitted.

I can hear the product managers at cloudflare maniacally laughing their heads off right now. A side-effect if you're being generous, or primary motive if you're being cynical, of 1.1.1.1 is that CF acquires all the geo info at the expense of everyone else. This puts CF in a particularly advantageous position over DIY GSLB (pushing content providers into using CF), as well as other CDNs of course. Not only that, the p…

Please do your research. “Any data Cloudflare handles as a result of its resolver for Firefox is as a date processor acting pursuant to Firefox’s data processing instructions. Therefore, the data Cloudflare collects and processes pursuant to its agreement with Firefox is not covered by the Cloudflare Privacy Policy. As part of its agreement with Firefox, Cloudflare has agreed to collect only a limited amount of data…

> ... DNS requests that are sent to the Cloudflare Resolver for Firefox via the Firefox browser.

Is this Firefox specific (via HTTP headers or EDNS options) or is this just the general policy of the 1.1.1.1 resolver for all users?

Re: Improving DNS Privacy in Firefox

#113

No, no no and no. It does not improve privacy, it just puts all your DNS history in the hands of one provider. Not only that it adds latency for no real gain. HTTP is a terrible protocol for anything time sensitive. (its a fairly bad protocol for anything fast or efficient full stop.) The better way to do this is encourage/provide DNSsec (so we know that a provider is who they say they are) and then encrypt dns queri…

I can hear the product managers at cloudflare maniacally laughing their heads off right now. A side-effect if you're being generous, or primary motive if you're being cynical, of 1.1.1.1 is that CF acquires all the geo info at the expense of everyone else. This puts CF in a particularly advantageous position over DIY GSLB (pushing content providers into using CF), as well as other CDNs of course. Not only that, the p…

This is surely anycast-based geo for dns, not dns-based geo (which couldnt work for dns)

Re: Improving DNS Privacy in Firefox

#114
post #105

The New Cabal of the Web: 1) CloudFlare, 2) Google, 3) Mozilla, 4) Let's Encrypt, 5) a smattering of contributing vendors, 6) internet-related standards bodies, and a few other orgs I'm forgetting or not familiar with. Pretty much the entire WWW is being shaped and controlled by this group. "Open Web" my ass. The really insane thing to me is that a lot of this tech is being pushed with the argument that they need to…

> They could get everyone to open up a god damn firewall port if they wanted. No. They couldn’t. That’s the paradox. Together they control the client software running on just about everyone’s computers and phones… but they have very little control or influence over your random IT administrator running a corporate firewall or middleware box, who’s decided to block everything but 80 and 443 for “security” reasons. They…

I don't buy this line for one minute. The fact that these organizations are either too weak or incompetent to roll out difficult changes in no way means it can't be done. This is just the path of least resistance. Rather than design something good, we just slap a layer of crap on top of another layer of crap and call it an improvement. But dressing up a turd doesn't make it smell like roses.

The fact is that half (if not more) of the world depends on Google, Mozilla and CloudFlare. If they actually committed to breaking networks with a new standard, the vendors and network admins would have no choice but to slowly but surely roll out fixes, because the users need it. Maybe they should actually roll out a product that would update networks to fit an application's needs, like Kubernetes for SDN.

This feature is literally "Oh, we're having problems with DNS, but changing the protocol could be hard, so let's hide a new version of it inside some other protocol." They should stop screwing around and just release a Google Chrome VPN, which you just know they're going to release. AMP was just the amuse bouche.

Let's be real here, an advertising company does not care about privacy. Chrome implemented DNS over HTTPS a long time ago because it was a technical fix for a browser issue, not for privacy. Mozilla was slow to adopt but it got on the bandwagon. And let's not pretend that "hiding" a port number is a security feature, security by obscurity is a joke.

Re: Improving DNS Privacy in Firefox

#115
I don't understand why everyone is so down on this. I see this as a big win for average non-techie computer users in terms of privacy. Unlike many of us here, they're not going to take the time to set up a resolver or even click a checkbox hidden in preferences. Someone needs to take the first step in making encrypted DNS on _by default_. Once more people use it, other organizations that are in a more ideal position will follow and improve on it.

Re: Improving DNS Privacy in Firefox

#116

I'm not sure how it's supposed to work through captive portals. I guess if you can't get to the DNS-over-HTTPS page, use the system resolver? But then networks will just block the DNS-over-HTTPS page implicitly to force the system resolver when they need it. Another thing this will break: corporate intranet sites. Suddenly you can't browse to your intranet site because Mozilla never checked the DNS server that your c…

Yes, you can just block cloudflare-dns.com and this will stop working. As the article mentions, Firefox will fall back to normal DNS unless you set a hard-fail flag.

[Edit: firefox says they're using a different endpoint, but I'm assuming you can just block that too.]

Corporate intranets are used to configuring user desktops already. This is just another switch to flip.

Re: Improving DNS Privacy in Firefox

#117
post #105

Earlier quoted context omitted.

> They could get everyone to open up a god damn firewall port if they wanted. No. They couldn’t. That’s the paradox. Together they control the client software running on just about everyone’s computers and phones… but they have very little control or influence over your random IT administrator running a corporate firewall or middleware box, who’s decided to block everything but 80 and 443 for “security” reasons. They…

I don't buy this line for one minute. The fact that these organizations are either too weak or incompetent to roll out difficult changes in no way means it can't be done. This is just the path of least resistance. Rather than design something good, we just slap a layer of crap on top of another layer of crap and call it an improvement. But dressing up a turd doesn't make it smell like roses. The fact is that half (if…

Well, an advertising company doesn't care about protecting your privacy from themselves as the threat. But protecting you from rival data-miners like unscrupulous ISPs could actually help their business model, if you want to look at things cynically.

And protecting DNS queries from local poisoning or outright censorship is the security feature. Having to resort to the 'easy,' non-boat-rocking encryption port of 443 is an implementation detail.

Re: Improving DNS Privacy in Firefox

#118
post #101

Earlier quoted context omitted.

Please do your research. “Any data Cloudflare handles as a result of its resolver for Firefox is as a date processor acting pursuant to Firefox’s data processing instructions. Therefore, the data Cloudflare collects and processes pursuant to its agreement with Firefox is not covered by the Cloudflare Privacy Policy. As part of its agreement with Firefox, Cloudflare has agreed to collect only a limited amount of data…

> ... DNS requests that are sent to the Cloudflare Resolver for Firefox via the Firefox browser. Is this Firefox specific (via HTTP headers or EDNS options) or is this just the general policy of the 1.1.1.1 resolver for all users?

The original article says they're not using CloudFlare's normal DNS-over-HTTPS endpoint, so this is probably specific to Firefox.

Edit: according to https://www.cloudflare.com/privacypolicy/ the normal privacy policy applies to users of CloudFlare's DNS.

Re: Improving DNS Privacy in Firefox

#120

Earlier quoted context omitted.

I don't buy this line for one minute. The fact that these organizations are either too weak or incompetent to roll out difficult changes in no way means it can't be done. This is just the path of least resistance. Rather than design something good, we just slap a layer of crap on top of another layer of crap and call it an improvement. But dressing up a turd doesn't make it smell like roses. The fact is that half (if…

Well, an advertising company doesn't care about protecting your privacy from themselves as the threat. But protecting you from rival data-miners like unscrupulous ISPs could actually help their business model, if you want to look at things cynically. And protecting DNS queries from local poisoning or outright censorship is the security feature. Having to resort to the 'easy,' non-boat-rocking encryption port of 443 i…

First of all, censorship is censorship. It's not an exploit or a bug, it's a purposeful set of laws, policies or regulations meant to restrict the use of something. DNS over HTTPS "improving security" in a censorship context is the same as saying that when a corporate web proxy prevents you from going to PornHub, circumventing that proxy is "improving security". And btw, circumventing censorship may be illegal, or at the very least against official policies.

It's also not a security feature because you don't need this to protect against cache poisoning, as DNSSEC already does that.

Post reply on HN