Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

121–130 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#121

Earlier quoted context omitted.

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

That’s simply not true. Mozilla is not sharing DNS queries with Cloudfare by default, nor are they overriding your configured DNS servers per default. This is an experimental opt-in feature, and they are also running an opt-in study. There has been no announcement of an ”on by default” for DOH. If you enable the experimental feature there is no default provided and you have to set your own server, but if you opt in t…

Just to be clear, the authors are wrong? There will not be a September patch that overrides my network DNS settings?

"With the next Mozilla patch in September any DNS change you configure in your network won't have any effect anymore, at least for browsing with Firefox, because Mozilla has partnered up with Cloudflare and will resolve the domain names from the application itself via a DNS server from Cloudflare based in the United States."

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#122
post #112

Earlier quoted context omitted.

It's important to understand the advantages of HTTPS via other protocols or custom crypto: * HTTPS stacks are battle tested and there are multiple of them. Browsers in particular already ship a heavily maintained one that performs great, so using DNS on top of it gets all those benefits. Because there are multiple stacks the risk of people settling on a monoculture is a lot lower. * People running a DNS resolver like…

Is there anything left, that's not on HTTP? Maybe NTP. I know about JMAP to replace IMAP. Here's another idea: other protocols are useful as well, sometimes more useful, than HTTP. > HTTPS stacks are battle tested and there are multiple of them. So is DNS. I wonder how the HTTP servers deal with DNS amplification attacks. > People running a DNS resolver likely have the ability to run a good HTTPS server already Your…

> I wonder how the HTTP servers deal with DNS amplification attacks.

They don't have to since http(s) is TCP and not UDP?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#123
post #94

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

>DNS over HTTPS is a great idea Why is it better than DNS over TLS? All I can see here is increased overhead.

Since HTTP(S) basically works everywhere and a new port (DNS over TLS on standard port 853) is guaranteed not to work everywhere.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#124

Earlier quoted context omitted.

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

The default applies currently if you enable an experimental feature. They hammered out a tight privacy agreement for one service and use that as default while this is stabilized. You can pick any other resolver if you prefer. Seems a legit way of handling this. > And the article's argument that, if you have to choose somebody to share this data with, it might as well be the people you already share it with, seems pre…

Cloudflare is an US company, their privacy statement is worth zero to most Firefox users.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#126

Earlier quoted context omitted.

That’s simply not true. Mozilla is not sharing DNS queries with Cloudfare by default, nor are they overriding your configured DNS servers per default. This is an experimental opt-in feature, and they are also running an opt-in study. There has been no announcement of an ”on by default” for DOH. If you enable the experimental feature there is no default provided and you have to set your own server, but if you opt in t…

Just to be clear, the authors are wrong? There will not be a September patch that overrides my network DNS settings? "With the next Mozilla patch in September any DNS change you configure in your network won't have any effect anymore, at least for browsing with Firefox, because Mozilla has partnered up with Cloudflare and will resolve the domain names from the application itself via a DNS server from Cloudflare based…

Do you seriously believe that Mozilla is issuing a patch in September that will somehow force you to use Cloudflare as a DNS provider? That 'any DNS change you configure in your network won't have any effect anymore'? Do you know many setups that would break?

Of course the article is wrong. Classic FUD.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#127

Earlier quoted context omitted.

The default applies currently if you enable an experimental feature. They hammered out a tight privacy agreement for one service and use that as default while this is stabilized. You can pick any other resolver if you prefer. Seems a legit way of handling this. > And the article's argument that, if you have to choose somebody to share this data with, it might as well be the people you already share it with, seems pre…

Cloudflare is an US company, their privacy statement is worth zero to most Firefox users.

Most Firefox users are absolutely unaffected by this. Literally all people that don’t explicitly enable this. All those who do might want to make up their mind if they want to participate in this and if they want CF to be their provider of trust. Keep in mind that CF will see a substantial chunk of the traffic anyways.

Mozilla seems to be confident in that agreement and I have a certain amount of trust in Mozilla which factors into my decision. Yours might be different, so don’t enable that feature or use a different provider.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#128

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

"Cloudflare has at least promised not to be evil"

I have a bridge to sell!

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#129
post #41
post #10

As a man in a country where constant censoring is performed by the government this movement at least make it harder for the gov censor/monitor people.

Which country is that?

VHVya2V5IGhhcyBsZWdhbGlzZWQgY2Vuc29yc2hpcCBvZiBhbGwgcmFkaW8sIFRWIGFuZCBJbnRl cm5ldCBhcyBhbiAiYWRtaW5pc3RyYXRpdmUgbWVhc3VyZSIgaW4gbWlkIDIwMTcgKGxhd2xpa2Ug ZGVjcmVlIDY5MCkuIEFsbCByYWRpbyBhbmQgVFYgdHJhbnNtaXR0ZXJzIChldmVuIG9uZXMgdHJh bnNtaXR0aW5nIHByaXZhdGUgY2hhbm5lbHMpIGFyZSBvd25lZCBieSBhIGdvdmVybm1lbnQtbWFq b3JpdHkgY29tcGFueSBhbmQgYWxsIG5vbi1MQU4gbmV0d29yayB0cmFmZmljIGdvZXMgdGhyb3Vn aCBjZW50cmFsIGdhdGV3YXlzLiBFcmRvxJ9hbiBjYW4gZWFzaWx5IHJlcGxhY2Ugb3IgY2Vuc29y IGNvbW11bmljYXRpb24uCg==

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#130
post #34
post #7

What about if you have private DNS servers that has sites that cloudflare does not have? For example internal intranets etc? So mozilla will not work at all in that case?

That one actually breaks in the new release :-/

Wow.

Firefox, out of the box, is going to be perfectly useless to me.

At home, I have an internal DNS resolver which is used for internal stuff (e.g., Home Assistant, a friendly name for my NAS, etc). This will be broken. Likewise, I've got Pi-Hole set up for my girlfriend, but that's going to stop working as soon as her Firefox updates itself to this version.

At work, we have an internal DNS resolver for obvious reasons. All of the users who use Firefox will suddenly be unable to access internal sites. That's going to be a fun time for the helpdesk as 3000+ staff start receiving updates.

I know it can be turned off, but having to track down a hidden setting to make the browser actually function correctly is insane.

Post reply on HN