Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

71–80 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#71

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

> (This is a gross simplification, but it’s broadly true enough in most countries.) Seems like you forget Europe and e.g. GDPR. It would be a big no-no in Denmark: My bank has one division for normal accounts and another for mastercard. The 2 divisions are separate companies, so I have to sign a paper to allow the MasterCard division to know about my normal account. So Danes have no hesitation giving out personal inf…

I wish that was the case. TDC (the largest danish telco) actually sold information about mobile users, including roaming users to VisitAarhus. Specifically, it was data about the locations of mobile users.

Danish article on the subject: https://www.version2.dk/artikel/tdc-saelger-data-mobilbruger...

So there is still plenty of reasons not to trust your ISP in Denmark and Europe in general.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#72
post #2

The Internet is not made for centralisation!

The internet has decentralized architecture underneath but the model is being abandoned because traffic volumes are too high for the naive decentralized architecture.

Today 60% of the global internet traffic goes trough CDN's. In 2021 it will be over 70% in 2021 (over 90% in North America). There is whole "internet cache" industry standing between clients and servers.

When you connect to some site in the internet, most of the data comes from some of these: Google CDN,,MaxCDN, Akamai, MS/Azure CDN, Limelight, EdgeCast, Amazon CDN, Coudfare,Rackspace, Incapsula, ...

The issue here is not decentralization vs centralization, it's about browser selecting something for a user as a default.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#73
post #65

I use Cloudflare's resolver, but I actually agree with this. I don't want every device in my local network ignoring my Pi hole or my custom DNS entries, I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. If I recall correctly, this…

> I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. Agreed that this introduces additional centralization. Maybe Mozilla could work to with other third parties in different jurisdictions to see if there's interest to spin up addit…

As always, it's not "the NSA is targeting me specifically", it's "they're doing dragnet surveillance for potentially 'interesting' data and who knows how they'll choose to harass me".

There is literally no single country in the world I would like my data sent to than the US. Even China is preferable.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#74
post #71

Earlier quoted context omitted.

> (This is a gross simplification, but it’s broadly true enough in most countries.) Seems like you forget Europe and e.g. GDPR. It would be a big no-no in Denmark: My bank has one division for normal accounts and another for mastercard. The 2 divisions are separate companies, so I have to sign a paper to allow the MasterCard division to know about my normal account. So Danes have no hesitation giving out personal inf…

I wish that was the case. TDC (the largest danish telco) actually sold information about mobile users, including roaming users to VisitAarhus. Specifically, it was data about the locations of mobile users. Danish article on the subject: https://www.version2.dk/artikel/tdc-saelger-data-mobilbruger... So there is still plenty of reasons not to trust your ISP in Denmark and Europe in general.

Telia did the same thing in Sweden some years ago. There are however ISPs who have a business model based on them having a very high profile in personal integrity politics (like Bahnhof), which I would feel more comfortable with thanany other DNSs

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#75
post #54
post #35

Earlier quoted context omitted.

https://wiki.mozilla.org/Trusted_Recursive_Resolver >Set `network.trr.mode` to 2 to make DNS Over HTTPS the browser's first choice but use regular DNS as a fallback So regular DNS entries will still resolve after the lookup over DoH failed.

But which user will be able to figure that out?

Maybe all the users that turn TRR on in the first place? It’s default off and you need to enable it in the expert configuration menu. I don’t expect it to be enabled by default without a reasonable config UI.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#76
post #66

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

> Cloudflare has at least promised not to be evil Remember when Google did so, too? Then they bid on military contracts and bought a military contractor.

Indeed. My choice of words there was deliberate and a subtle acknowledgement that such things can go awry over time.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#77

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

According to the article this is enabled by default to use Cloudflare. Are you saying that is not the case?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#78

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

Cloudfare can promise what they want, they can still be subject to warrantless spying by US agencies and not disclose anything about it.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#79

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

It's not a ISP vs Cloudflare issue though, the ISP will know where you are connecting to anyway...

This is such a toxic decision by Mozilla, but I'm not surprised since they have been leaking customer data to other companies (Google) that threw money at them in the past too.

Post reply on HN