Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

151–160 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#151
post #36
post #11

Earlier quoted context omitted.

I think as far as browsers are concerned, there are no private DNS names anymore for a good while already - either everyone on the internet knows your DNS or it doesn't exist. See the similar problem with TLS certificates... (edit) Ok, that was indeed put more dramatically than necessary. My point is that private DNS names seem to be heavily discouraged by browsers default configurations. You can change both the DNS…

Can only heavily disagree with this one. The reason why BIND has views is because bigger organisation (like universities) employ different views depending on whether you are internal or external.

But this is the exact point. With DoH active by default (and no custom configuration set), every instance of Firefox will appear to be querying your DNS from outside, no matter if the machine is inside the LAN or not.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#152
I'm not looking forward to this.

I use internal DNS for stuff I'm running at home (e.g., a NAS, Home Assistant, etc). I don't want to go back to the bad old days of having to remember what IP addresses go with what service.

My girlfriend is not going to like it when Pi-Hole magically stops working because Firefox doesn't respect the DNS settings that are served by DHCP.

My employer uses internal DNS for internal services. The helpdesk is going to have a fun time as Firefoxes across the organization get updated. It also doesn't help that a large number of users are BYOD users, so enforcing certain Firefox settings is a no-go.

Sure, there's instructions to fix it, but it should never be broken like this in the first place.

EDIT:

The article has been updated - it now shows a screenshot from Mozilla's blog[0] which says:

> We’ll use the default resolver, as we do now, but we’ll also send the request to Cloudflare’s DoH resolver. Then we’ll compare the two to make sure that everything is working as we expect.

Cloudflare is going to have a huge list of internal stuff used by Firefox Nightly users, and Mozilla is going to have huge insights into how many people use things like Pi-Hole, internal DNS servers, split DNS servers (e.g., BIND Views), etc. And they're going to be analyzing this data in order to determine how well DNS-over-HTTPS works.

I'm not sure if this is better or worse than I initially thought it was.

[0] https://hacks.mozilla.org/2018/05/a-cartoon-intro-to-dns-ove...

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#153
post #66

Earlier quoted context omitted.

> Cloudflare has at least promised not to be evil Remember when Google did so, too? Then they bid on military contracts and bought a military contractor.

It may surprise you, but not everyone believes the military is evil, and thus working with them is evil.

Speaking for the US now (this is an outside view) but to me it looks like institutions such as the CIA or the NSA are indeed seen as evil by the majority of the public. Now, both the NSA and the CIA would mean nothing in the medium and long span of time if it weren’t for the power projected and often times actually exercised by the US military. As such, one can be forgiven for looking at the military as “bad”, if only for the fact that it “supports” bad institutions. Or, in other words, you cannot pick the “good guys” out of the military-industrial complex, to think otherwise is just self-delusion.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#154
post #7

What about if you have private DNS servers that has sites that cloudflare does not have? For example internal intranets etc? So mozilla will not work at all in that case?

The expected common deployment mode is soft fallback - using traditional DNS if connections cannot be made via the DoH resolved address. Captive portal provides the most common use case.

There is a hard failure mode available that you can use for better security if you're in a vanilla Internet environment - but we don't see a way to broadly offer that choice other than in technical documentation.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#156

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

but your ISP will still be able to see all your connections even if you don't use its DNS servers unless you use a VPN... this just spreads the information to a third party.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#157

Earlier quoted context omitted.

But that’s a different argument you’re making. For many people, routing the browsers DNS via a secure channel is a substantial improvement. You’re still free to route all your network DNS via DoH, there’s software for that. But until DoH is the operating systems default (or at least a non-expert option), this can be a viable improvement.

For many it is, but for billions it isn't. For those where it is an improvement they can opt in.

I think you substantially overestimate the number of providers that behave ethically with regards to DNS and substantially underestimate how many people have shitty ISPs. You seem to have a very skewed view of how the number of internet users distributes across the world. Even in Europe, providers are not refraining from hijacking DNS and using DNS blocks for certain sites.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#158
post #126

Earlier quoted context omitted.

Just to be clear, the authors are wrong? There will not be a September patch that overrides my network DNS settings? "With the next Mozilla patch in September any DNS change you configure in your network won't have any effect anymore, at least for browsing with Firefox, because Mozilla has partnered up with Cloudflare and will resolve the domain names from the application itself via a DNS server from Cloudflare based…

Do you seriously believe that Mozilla is issuing a patch in September that will somehow force you to use Cloudflare as a DNS provider? That 'any DNS change you configure in your network won't have any effect anymore'? Do you know many setups that would break? Of course the article is wrong. Classic FUD.

Actually, yes, I do. From their blog:

> We believe that negotiating a privacy first operating agreement is something that Firefox can do for people that is just impractical to ask them to do for themselves. Imagine calling up your residential ISP and asking them to agree to an audit that demonstrates they do not log your IP address on their DNS server. And then repeating the process for your favorite coffee shop, library, friend’s house — anywhere you and your browser go to connect.

Firefox improves user privacy by default by finding good partners, establishing legal agreements that put privacy first, and eventually shipping a default configuration we believe is best.

They know about the power of default settings - and with the current default, they will be unable to roll-out this feature to a meaningful number of users. So at some point, the default will probably change to activate DoH.

Technically, this isn't "force" as you'll probably be able to turn it back off via about:config - if you know which options to change, what to change them to and if you are willing to click past the "if you proceed, you may damage your computer" warning.

Not every random guest that wants to access your local Nexcloud instance will be willing to do this.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#159
post #54

Earlier quoted context omitted.

But which user will be able to figure that out?

Maybe all the users that turn TRR on in the first place? It’s default off and you need to enable it in the expert configuration menu. I don’t expect it to be enabled by default without a reasonable config UI.

The article states that DoH will become on-by-default in september.

In general, I find it highly unlikely that it will stay off-by-default forever, because there is no way to have any meaningful adoption of it as an expert-only feature.

Post reply on HN