Earlier quoted context omitted.
Why do you think that? My home router will happily resolve sites that only exist on my home server.
Your home router will. However, as the article made clear, you won't be able to open that site in Firefox. Even if you were, you won't be able to get a public TLS certificate for that site, making you unable to serve the site as HTTPS and locking you out of many current and all(!) futue JS and CSS features. Yes, you can solve both problems by installing overrides. However, this has to be done separately for every cli…
Firefox’s Trusted Recursive Resolver DNS feature is dangerous
31–40 of 306 posts
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#32I rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.
I hate this mentality of "our users are complete idiots and we know what's good for them" (I call it the "Gnome" mentality).
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#33> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#34What about if you have private DNS servers that has sites that cloudflare does not have? For example internal intranets etc? So mozilla will not work at all in that case?
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#35Earlier quoted context omitted.
Your home router will. However, as the article made clear, you won't be able to open that site in Firefox. Even if you were, you won't be able to get a public TLS certificate for that site, making you unable to serve the site as HTTPS and locking you out of many current and all(!) futue JS and CSS features. Yes, you can solve both problems by installing overrides. However, this has to be done separately for every cli…
Which is clearly bonkers. Why would Firefox deliberately break people who run Nextcloud on a Raspi at home? There must be something missing here.
>Set `network.trr.mode` to 2 to make DNS Over HTTPS the browser's first choice but use regular DNS as a fallback
So regular DNS entries will still resolve after the lookup over DoH failed.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#36What about if you have private DNS servers that has sites that cloudflare does not have? For example internal intranets etc? So mozilla will not work at all in that case?
I think as far as browsers are concerned, there are no private DNS names anymore for a good while already - either everyone on the internet knows your DNS or it doesn't exist. See the similar problem with TLS certificates... (edit) Ok, that was indeed put more dramatically than necessary. My point is that private DNS names seem to be heavily discouraged by browsers default configurations. You can change both the DNS…
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#37I use Cloudflare's resolver, but I actually agree with this. I don't want every device in my local network ignoring my Pi hole or my custom DNS entries, I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. If I recall correctly, this…
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#38I rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.
There are many public DNS providers those promise to not logs DNS queries. I don't know precisely but if Mozilla forces user to use Cloudflare DNS is the deal breaker.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#39> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…
You are forgetting that the author is from Switzerland.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#40Sigh. Mozilla had just made Firefox usable again... And now good reasons for leaving it again are coming up.