Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

31–40 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#31
post #21

Earlier quoted context omitted.

Why do you think that? My home router will happily resolve sites that only exist on my home server.

Your home router will. However, as the article made clear, you won't be able to open that site in Firefox. Even if you were, you won't be able to get a public TLS certificate for that site, making you unable to serve the site as HTTPS and locking you out of many current and all(!) futue JS and CSS features. Yes, you can solve both problems by installing overrides. However, this has to be done separately for every cli…

That's my point. My parent said that private DNS names have been dead for a while, and I said they aren't.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#32
post #3

I rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.

I host my own DNS resolver on a dedicated server, Firefox hijacking my DNS traffic without telling me is definitely not an improvement. It can be a nice feature in some situations but having it activated by default without explicit consent should be a big no-no.

I hate this mentality of "our users are complete idiots and we know what's good for them" (I call it the "Gnome" mentality).

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#33

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

I wonder what kind of ISPs you use? Here in .ch, ISPs can be rather small and you even know the operators personally. So trust ISP >> cloudflare.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#35
post #21

Earlier quoted context omitted.

Your home router will. However, as the article made clear, you won't be able to open that site in Firefox. Even if you were, you won't be able to get a public TLS certificate for that site, making you unable to serve the site as HTTPS and locking you out of many current and all(!) futue JS and CSS features. Yes, you can solve both problems by installing overrides. However, this has to be done separately for every cli…

Which is clearly bonkers. Why would Firefox deliberately break people who run Nextcloud on a Raspi at home? There must be something missing here.

https://wiki.mozilla.org/Trusted_Recursive_Resolver

>Set `network.trr.mode` to 2 to make DNS Over HTTPS the browser's first choice but use regular DNS as a fallback

So regular DNS entries will still resolve after the lookup over DoH failed.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#36
post #11
post #7

What about if you have private DNS servers that has sites that cloudflare does not have? For example internal intranets etc? So mozilla will not work at all in that case?

I think as far as browsers are concerned, there are no private DNS names anymore for a good while already - either everyone on the internet knows your DNS or it doesn't exist. See the similar problem with TLS certificates... (edit) Ok, that was indeed put more dramatically than necessary. My point is that private DNS names seem to be heavily discouraged by browsers default configurations. You can change both the DNS…

Can only heavily disagree with this one. The reason why BIND has views is because bigger organisation (like universities) employ different views depending on whether you are internal or external.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#37

I use Cloudflare's resolver, but I actually agree with this. I don't want every device in my local network ignoring my Pi hole or my custom DNS entries, I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. If I recall correctly, this…

That depends. Cloudflare probably (did not check) uses anycast and thus their DNS servers are actually in the specfic region. This however does not change the problem of the legal authority still being in the US, as you pointed out.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#38
post #5
post #3

I rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.

There are many public DNS providers those promise to not logs DNS queries. I don't know precisely but if Mozilla forces user to use Cloudflare DNS is the deal breaker.

It is especially surprising, because so far Mozilla could always be trusted.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#39

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

> I have never trusted any local ISP.

You are forgetting that the author is from Switzerland.

Post reply on HN