Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

131–140 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#132

There are many countries where ISPs are obliged by law to spy on users, and retain logs for many years. DNS manipulation also used as a cheap censorship mechanism. So Cloudflare easily can be a better option for hundreds of millions if not billions of people. As a rule, local actors present way more serious threat compared to US agencies for majority of the planet's population. That said, Mozilla, of course, must be…

So data is safest in the country with the largest spying budget and the most spies. Not convinced.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#133
post #112

Earlier quoted context omitted.

It's important to understand the advantages of HTTPS via other protocols or custom crypto: * HTTPS stacks are battle tested and there are multiple of them. Browsers in particular already ship a heavily maintained one that performs great, so using DNS on top of it gets all those benefits. Because there are multiple stacks the risk of people settling on a monoculture is a lot lower. * People running a DNS resolver like…

Is there anything left, that's not on HTTP? Maybe NTP. I know about JMAP to replace IMAP. Here's another idea: other protocols are useful as well, sometimes more useful, than HTTP. > HTTPS stacks are battle tested and there are multiple of them. So is DNS. I wonder how the HTTP servers deal with DNS amplification attacks. > People running a DNS resolver likely have the ability to run a good HTTPS server already Your…

DNS over HTTPS is immune to amplification attacks.

If the alternative to DNS over HTTPS is a DNS-over-TLS resolver being run by a company without a website (???) then I guess that's easier than DNS-over-HTTPS. Are you really going to use a resolver run by a mysterious nobody?

There are probably more than a dozen HTTP stacks being widely used in production. It's not remotely a monoculture.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#135
post #95

Earlier quoted context omitted.

If this is true, then I'm okay with the feature being available if it is opt-in. Although I generally think this is a concern better left outside of the particular browser I'm using. If I want to route DNS queries through a third party then I'd like to do that for all my network traffic, not just my browser.

But that’s a different argument you’re making. For many people, routing the browsers DNS via a secure channel is a substantial improvement. You’re still free to route all your network DNS via DoH, there’s software for that. But until DoH is the operating systems default (or at least a non-expert option), this can be a viable improvement.

Yes. If it's opt-in, then I can certainly live with it and I understand why people might use it. I'm just pointing out that features like these, while well intentioned, still add bloat to the browser. Sometimes saying no to feature inclusion is the right thing to do in the long term even if it has a use in the short term. I'm a big believer of the Unix philosophy of do one thing and do it well.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#136

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

> There's nothing sneaky going on here;

It bloody is. Egregiously so. If they are deviating from expected behaviour[1] they should obtain informed consent and even then it's unethical. Half of Mozilla is screaming decentralisation[2], the other is centralising the web as fast as they can. I still haven't forgiven Linux Mint for similar shenanigans[3].

[1] Users understand instinctively the principle behind reverse dns lookup. If ISPs can resolve at least portion of domain names then it doesn't make sense to then introduce another completely random third party that isn't strictly necessary for the process.

[2] https://hacks.mozilla.org/2018/07/introducing-the-d-web/

[3] https://bugs.launchpad.net/linuxmint/+bug/1133777

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#137
post #56

For reference, the privacy agreement between Cloudflare and Mozilla: https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...

Great, all your data is stored for 24 hours and then collected in "anonymised" form for further processing and "internal research"! Also no mention of penalties, either for Cloudflare as a company or the responsible employees (starting with the CEO) in case of a violation. And no notice period of any time should Cloudflare decide to change those terms and have thousands of browsers still pointed at its resolvers. Why…

It's a legally binding contract between Cloudflare and Mozilla. If Cloudflare were to violate it, Mozilla could sue and a judge would determine the penalties for Cloudflare. There should be some rough guidelines written into law as well.

And we're definitely not talking about small amounts. Cloudflare violating it would result in Mozilla violating the privacy of millions, which can be interpreted as significant damages to the citizens. They're also both situated in California, so privacy will be valued by a judge. Given Mozilla's public image as a privacy-friendly organization, they could also push charges for damaging that image.

That penalty + the damage to Cloudflare's own reputation, I cannot imagine they would survive.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#138

Earlier quoted context omitted.

That’s simply not true. Mozilla is not sharing DNS queries with Cloudfare by default, nor are they overriding your configured DNS servers per default. This is an experimental opt-in feature, and they are also running an opt-in study. There has been no announcement of an ”on by default” for DOH. If you enable the experimental feature there is no default provided and you have to set your own server, but if you opt in t…

Just to be clear, the authors are wrong? There will not be a September patch that overrides my network DNS settings? "With the next Mozilla patch in September any DNS change you configure in your network won't have any effect anymore, at least for browsing with Firefox, because Mozilla has partnered up with Cloudflare and will resolve the domain names from the application itself via a DNS server from Cloudflare based…

This is the relevant post from the Mozilla nightly blog: https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr... It confirms that the default is off. It also gives a much more nuanced view of the level of partnership. CF is currently the partner for a study regarding that feature. That study still requires opt-in (and currently nightly) The patch in September will bring the feature to mainline FF, but it’s still default off and hidden behind “about:config”

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#139
post #33

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

I wonder what kind of ISPs you use? Here in .ch, ISPs can be rather small and you even know the operators personally. So trust ISP >> cloudflare.

There are (privacy) pro's and con's to having a small(-ish) ISP. 1: you have a payment relation with your ISP so your identity is 100% known. 2: Operators you know personally might turn against you, as it happens between people.

I use Swisscom (larger ISP here in Switzerland, both for mobile & home connectivity) but damn if I do not encrypt /hide as much traffic (DNS first) as possible to prevent exactly them from being able to see exactly what I do.

I have worked for far larger providers and I have personally investigated 10's of cases where a "roque" operator has fired for "abusing" access to very privacy sensitive data (being it internet access or mobile phone locations etc). As [most of the time|always] in these cases, the offender gets offered a decent exit to prevent (public exposure via) lawsuits so little gets known to the outside world.

In the end it is up to you, but my advice would always be: do not put all your eggs in one basket.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#140

More information: https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr... According to this page: - you can already test this right now - you can provide your own server And some more: https://en.wikipedia.org/wiki/DNS_over_HTTPS

> - you can provide your own server

How do I RUN my own server? A few minutes of Googling hasn't revealed any DNS-over-HTTPS server that appears production-ready.

Post reply on HN