I rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.
Great! And you can already choose to do so. But it seems pretty likely that Firefox will be making that decision on behalf of all its users (except those with the wherewithal to know how to opt out), without effectively communicating the risks of that decision to them (based upon their communication about this feature so far).
Firefox’s Trusted Recursive Resolver DNS feature is dangerous
81–90 of 306 posts
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#82I rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.
There are many public DNS providers those promise to not logs DNS queries. I don't know precisely but if Mozilla forces user to use Cloudflare DNS is the deal breaker.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#83Sigh. Mozilla had just made Firefox usable again... And now good reasons for leaving it again are coming up.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#84I use Cloudflare's resolver, but I actually agree with this. I don't want every device in my local network ignoring my Pi hole or my custom DNS entries, I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. If I recall correctly, this…
> I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. Agreed that this introduces additional centralization. Maybe Mozilla could work to with other third parties in different jurisdictions to see if there's interest to spin up addit…
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#85DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#86Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#87More information: https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr... According to this page: - you can already test this right now - you can provide your own server And some more: https://en.wikipedia.org/wiki/DNS_over_HTTPS
> - you can provide your own server Nobody will do this except for maybe 5 individuals and a few dozen cooperations simply because there are no other public DoH servers around.
https://developers.google.com/speed/public-dns/docs/dns-over... https://ripe76.ripe.net/on-site/technical-information/dns-ov...
The DNScrypt project has a longer list here:
https://download.dnscrypt.info/resolvers-list/v2/public-reso...
Keep in mind that this is currently all pretty much experimental.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#88> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…
> Cloudflare has at least promised not to be evil Remember when Google did so, too? Then they bid on military contracts and bought a military contractor.
Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous
#89DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…
The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…
> And the article's argument that, if you have to choose somebody to share this data with, it might as well be the people you already share it with, seems pretty valid to me.
The whole point of HTTPS and DNS-over-HTTPS is to not share any data at all with your provider. It’s not entirely working right now due to SNI being plaintext, but work is being done on that, too. So that’s really not a good argument.