Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

91–100 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#91
post #77

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

According to the article this is enabled by default to use Cloudflare. Are you saying that is not the case?

The article provides no source for this assertion and this Mozilla blog post is pretty clear that DNS-over-HTTPS is off by default and defaults to CF if you enable it or are part of the shield study (which requires nightly and opt-in to shield studies in the first place) https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr...

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#92

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

[deleted]

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#93
post #74
post #71

Earlier quoted context omitted.

I wish that was the case. TDC (the largest danish telco) actually sold information about mobile users, including roaming users to VisitAarhus. Specifically, it was data about the locations of mobile users. Danish article on the subject: https://www.version2.dk/artikel/tdc-saelger-data-mobilbruger... So there is still plenty of reasons not to trust your ISP in Denmark and Europe in general.

Telia did the same thing in Sweden some years ago. There are however ISPs who have a business model based on them having a very high profile in personal integrity politics (like Bahnhof), which I would feel more comfortable with thanany other DNSs

By wouldn’t you expect Bahnhof to offer a DoH-capable resolver for its customers then, that you could use in FF if you choose to enable the feature once it’s out of the experimental phase?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#94

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

>DNS over HTTPS is a great idea

Why is it better than DNS over TLS? All I can see here is increased overhead.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#95
post #77

Earlier quoted context omitted.

According to the article this is enabled by default to use Cloudflare. Are you saying that is not the case?

The article provides no source for this assertion and this Mozilla blog post is pretty clear that DNS-over-HTTPS is off by default and defaults to CF if you enable it or are part of the shield study (which requires nightly and opt-in to shield studies in the first place) https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr...

If this is true, then I'm okay with the feature being available if it is opt-in. Although I generally think this is a concern better left outside of the particular browser I'm using. If I want to route DNS queries through a third party then I'd like to do that for all my network traffic, not just my browser.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#96
post #6

> And your ISP knows where you connect to anyways. So the data or information generated by their DNS server provides no additional information to them. This is not correct. Your ISP only knows what IP you are connecting to and that is not enough in general. E.g. Cloudflare.

That might be true in the future if and when SNI encryption is widely implemented.

and the internet becomes sufficiently centralised that you only access a few IP addresses behind which most services are hosted. In other words, we can either

a) trust our ISP with DNS queries and IP addresses which fairly uniquely identify services or

b) trust Cloudflare with DNS queries and our ISP with IP addresses which fairly uniquely identify services or

c) move everything "behind Cloudflare" and solely trust Cloudflare

Given that I can cancel my ISP’s contract, I can hold them accountable if they spew my data into the internet and I have no idea who Cloudflare is or what their aims are, I’d much prefer a) over c). b) is just worse than a) or c).

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#97

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

> DNS over HTTPS is a great idea

Putting everything, even lower-than-http level things on top of HTTP is a horrible idea, introducing yet another layer of abstraction.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#98
post #77

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

According to the article this is enabled by default to use Cloudflare. Are you saying that is not the case?

It's currently an experimental feature not enabled by default and with no UI to change settings outwith about:config.

In the current release version of Firefox (61.0.1) the provider parameter (network.trr.uri) is blank and not set to Cloudfare out of the box.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#99

Earlier quoted context omitted.

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

The default applies currently if you enable an experimental feature. They hammered out a tight privacy agreement for one service and use that as default while this is stabilized. You can pick any other resolver if you prefer. Seems a legit way of handling this. > And the article's argument that, if you have to choose somebody to share this data with, it might as well be the people you already share it with, seems pre…

> The whole point of HTTPS and DNS-over-HTTPS is to not share any data at all with your provider. It’s not entirely working right now due to SNI being plaintext, but work is being done on that, too. So that’s really not a good argument.

If that was the whole point of https then we wouldn't have plaintext SNI. I can't even begin to understand why you think that there being a draft of an SNI encryption standard makes it 'really not a good argument'.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#100

Earlier quoted context omitted.

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

The default applies currently if you enable an experimental feature. They hammered out a tight privacy agreement for one service and use that as default while this is stabilized. You can pick any other resolver if you prefer. Seems a legit way of handling this. > And the article's argument that, if you have to choose somebody to share this data with, it might as well be the people you already share it with, seems pre…

> The whole point of HTTPS and DNS-over-HTTPS is to not share any data at all with your provider.

Won't they still see which website you then request?

Post reply on HN