Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

41–50 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#42
post #33

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

I wonder what kind of ISPs you use? Here in .ch, ISPs can be rather small and you even know the operators personally. So trust ISP >> cloudflare.

I live in Australia; ISPs are basically all big entities, altogether unworthy of trust. The US is broadly similar. In both countries, you do get some obscure tiny ISPs, but they’re fairly rare overall.

I’ve also spent time in India with a small ISP, and I hated their DNS: they actively intercepted all DNS and replaced it with their own OpenDNS arrangement, involving the horrible NXDOMAIN replacement that was still a thing at the time, and in such a way that you couldn’t opt out of it! I don’t know how trustworthy they might or might not have been (I didn’t personally know them), but I do know that I loathed their technical decisions and would fain have bypassed them.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#44
Nothing against Cloudflare, but I don’t think it is good in general for the Internet that they are getting so critical.

For them this sounds like a good deal (is money involved here?). Having more control of DNS should mean they can provide better service for their customers.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#45
post #21

Earlier quoted context omitted.

Your home router will. However, as the article made clear, you won't be able to open that site in Firefox. Even if you were, you won't be able to get a public TLS certificate for that site, making you unable to serve the site as HTTPS and locking you out of many current and all(!) futue JS and CSS features. Yes, you can solve both problems by installing overrides. However, this has to be done separately for every cli…

That's my point. My parent said that private DNS names have been dead for a while, and I said they aren't.

Updated my parent comment to more precisely say what I meant.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#46
post #33

Earlier quoted context omitted.

I wonder what kind of ISPs you use? Here in .ch, ISPs can be rather small and you even know the operators personally. So trust ISP >> cloudflare.

I live in Australia; ISPs are basically all big entities, altogether unworthy of trust. The US is broadly similar. In both countries, you do get some obscure tiny ISPs, but they’re fairly rare overall. I’ve also spent time in India with a small ISP, and I hated their DNS: they actively intercepted all DNS and replaced it with their own OpenDNS arrangement, involving the horrible NXDOMAIN replacement that was still a…

I get the point. If your ISP is also not trustworthy, the situation probably does not change much for you. Then again, maybe the right solution is to look at how to get back trustworthy ISPs.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#47

Nothing against Cloudflare, but I don’t think it is good in general for the Internet that they are getting so critical. For them this sounds like a good deal (is money involved here?). Having more control of DNS should mean they can provide better service for their customers.

Agree - cloudflare probably does a good job here, but again: centralisation is making the Internet weaker. Also hands even more control into one entity's hands

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#48

More information: https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr... According to this page: - you can already test this right now - you can provide your own server And some more: https://en.wikipedia.org/wiki/DNS_over_HTTPS

> - you can provide your own server

Nobody will do this except for maybe 5 individuals and a few dozen cooperations simply because there are no other public DoH servers around.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#49

This feature will break dns-based geo-lookup, so as a user I might get directed to services that are 130ms away from me instead of 1-5ms. For any client application, this will likely have strong negative effects on user experience.

I somewhat doubt cloudflare have overlooked that

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#50
post #26

Sigh. Mozilla had just made Firefox usable again... And now good reasons for leaving it again are coming up.

Firefox is still great. You can turn this off trivially or provide your own server. This is, however, an excellent step towards securing the web.
Post reply on HN