Earlier quoted context omitted.
Using an alternative DNS resolver like 8.8.8.8 (Google) or 1.1.1.1 (Cloudflare) could solve that already, and not only in Firefox.
Or Quad9, but this could be intercepted.
Inside Firefox’s DNS-over-HTTPS engine
51–60 of 134 posts
Re: Inside Firefox’s DNS-over-HTTPS engine
#52I am in Indonesia where Reddit, Vimeo, The Pirate Bay and other sites are blocked. I just enabled TRR in Firefox 60 (They mention best support is in 62) and now I have full unblocked access to all those sites. Awesome.
Re: Inside Firefox’s DNS-over-HTTPS engine
#53Encrypted DNS is great, but please also do something with SNI. I am sure other users don't want their ISP to peek at what sites they are visiting too.
Also I thought that IPv6 doesn't need SNI, because with it you can allocate a separate IPv6 address for each service.
Re: Inside Firefox’s DNS-over-HTTPS engine
#54I can see app developers wanting this, but as a user, I really hope, this doesn't happen. It's bad enough that many applications today manage their own certificate stores, making the next part of internet infrastructure app-specific seems to me a way to more fragmentation and less understanding or oversight I'd have over my own system.
Re: Inside Firefox’s DNS-over-HTTPS engine
#55Although I am not too comfortable with everything moving to HTTP. HTTP 2 was already complex enough, it seems we want to move everything into HTTP, everything away from TCP to UDP. What happen to QUIC anyway ?
Re: Inside Firefox’s DNS-over-HTTPS engine
#56Is there a particular reason a DNS resolver should be implemented in a web browser? Wouldn't it be better if it was a system-wide configuration?
It's been 30 years and DNS is still a major security and confidentiality flaw in all widely used OSes. I welcome my browser doing something about it. If in the future OSes and ISPs provide better alternatives, this feature can always be turned off.
Can we please go easy on the newspeak? Centralizing resolving to a handful of actors will not improve privacy for the most part of end users.
Re: Inside Firefox’s DNS-over-HTTPS engine
#57Nice job Daniel (again...)! While TRR only sounds very appealing for certain threat vectors the handling of captive portals is still a ‚nasty‘ thing. While certainly not in the realm of DNS over HTTPS the logic / UX on the browser side as well as interaction with the underlying OS definitely needs improvement.
Re: Inside Firefox’s DNS-over-HTTPS engine
#58Does anyone know how TLS over TCP can be faster than UDP?
Re: Inside Firefox’s DNS-over-HTTPS engine
#59Earlier quoted context omitted.
Of course it gets large number of complains, when it creates more problems than it solves, and it is papered over "but mainstream users do not need that". Mainstream users do not need most software ever made.
Did you see someone in this discussion suggesting "but mainstream users do not need that"? I just checked again and I don't see anyone making that suggestion.
Re: Inside Firefox’s DNS-over-HTTPS engine
#60Earlier quoted context omitted.
You might have noticed that Firefox runs in a lot of messed up environments, where, for example, bad installers downloaded by the user have done many bad things to the OS, including installing bogus hosts files which block known anti-virus and anti-malware websites. Firefox had a huge crackdown on malicious toolbars and extensions, and that was a good thing for most people. Do you have a clever suggestion for how Fir…
Also as other have pointed out you can run you own TRR locally as a daemon and have it look to /etc/hosts