Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

221–230 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#221
First, I have to say that I love cloudflare, but the last thing we need is the centralization of all our DNS resolution to them. Please Mozilla, don't give anyone too much power.

And if DNS over HTTPS is the way to go (which might be), give the user a choice. There are 3 public resolvers already offering DNS over HTTPS:

  Google[1] (was the first one to support it) 
  CloudFlare[2]
  CleanBrowsing[3] (for security and/or adult filtering)
And hopefully Quad9 will join the list soon. I hope this doesn't become a "search engine" war that the company that pays more becomes the chosen DNS. Please Mozilla, don't do that.

* 1: https://developers.google.com/speed/public-dns/docs/dns-over...

* 2: https://developers.cloudflare.com/1.1.1.1/dns-over-https/

* 3: https://cleanbrowsing.org/dnsoverhttps

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#222
post #202

The article is incorrect. 1. TRR is not turned on by default. To turn it on, you need to go to about:config and set network.trr.mode to something other than 0 or 5. 2. Even if trr.mode is turned on, you need to go in and set the DOH server at network.trr.uri. The default is blank. You can set it to any publicly known DOH server ( https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-av... ), or even your own. 3.…

The first sentence of the article is about TRR/DOH being turned on by default in the next patch.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#224
post #214

Earlier quoted context omitted.

Why do you believe that this will be default on at any time in the near future without a reasonable configuration UI and without a reasonable set of DoH-capable nameservers? Especially given that this would break a substantial number of existing setupts? If you have this little faith into the FF/Mozilla folks, why do you keep using FF? If you’re not using Firefox, what are you concerned about?

If they don't turn it on by default, only a small number of people will use it. If only a small number of people use it, why bother implementing it?

The section of people that use it might benefit to a very large degree. Or they can make the switch prominent to push adoption. There are a lot of features implemented and hidden behind “about:config” where you could ask the same question. Many of them are for the security and privacy conscious but come with a few strings attached, for example some advanced cookie settings such as third party isolation.

That said: I fully expect that at some point Mozilla will want to push adoption of this feature, but not in its most extreme form. I’d expect that a default configuration would use soft fallback.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#225
post #219

Just because what you're doing is private doesn't mean it's secure. Just because what you're doing is secure doesn't mean it's private. No whistleblower should ever just expect that doing things the normal way is private or safe for them. If you wear a tinfoil hat, you need an entirely different operational language than typical users have, because your needs are totally different.

Privacy improves security for everybody. If an attacker can read all your DNS lookups then it's easier for them to target a spear-phishing attack against you.

Privacy may improve security, but usually not. It is a sometimes unintended consequence.

If I want to tell you a secret, I will bring you into a private room. Now we have privacy. If someone wants to listen in on our conversation, they will plant a bug in that room, or listen through the wall. To remain secure, I must add security countermeasures to prevent the bugs from transmitting, or extra noise to make being overheard difficult.

Your ISP's DNS might be more private, but if an attacker can poison your ISP's DNS cache (it has happened to me on my ISP) you won't be more secure. It's more secure to use a hardened DNS service, which is usually not local. But yes, this could be a minor privacy concern with a big enough attacker.

Just because you add privacy does not mean you added security. Just like because you add security does not mean you have privacy.

So please be honest about the motives for things like this. If you want more privacy, say so. Don't say it's a security problem when it's not.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#226

Earlier quoted context omitted.

Most Firefox users are absolutely unaffected by this. Literally all people that don’t explicitly enable this. All those who do might want to make up their mind if they want to participate in this and if they want CF to be their provider of trust. Keep in mind that CF will see a substantial chunk of the traffic anyways. Mozilla seems to be confident in that agreement and I have a certain amount of trust in Mozilla whi…

FF will turn this on for everybody and Cloudflare will be the default 2018? Don't know. 2019? For sure. All FF browsing meta data flows into the US, the country with the most spies and no legal framework to go to court. So your argument is an obvious straw man and one wonders about your motivations to support getting all the browsing meta data into the US by default. Moving my data from Germany to the US will not mak…

Why does so many people distrust every single step done by mozzilla!?

Sorry, this got me emotional, but since I started following tech news few years ago the amount of fake news on mozzilla I read is astounding.

And proper fake news. Many, as this article does, do no claim that a new feature dangerous per se, but falsely (I don't think with purpose, that is what I find astounding) quote mozzilla blogs to build an apocalyptic scenario

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#227
post #202

The article is incorrect. 1. TRR is not turned on by default. To turn it on, you need to go to about:config and set network.trr.mode to something other than 0 or 5. 2. Even if trr.mode is turned on, you need to go in and set the DOH server at network.trr.uri. The default is blank. You can set it to any publicly known DOH server ( https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-av... ), or even your own. 3.…

The first sentence of the article is about TRR/DOH being turned on by default in the next patch.

Yes, that's the big issue. Plus, changing to a different resolver is not very simple and most users won't even know.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#228

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Server_Name_Indication#Securit... Downvote me all you want, but domain names are still being sent to the ISP unencrypted, as of TLS 1.3... so it doesn't matter who processes your DNS queries, your ISP still knows everything about which sites you are accessing... but anyways, bare IP addresses still reveal a lot (metadata)

right - but we're coming for cleartext sni too: https://tools.ietf.org/html/draft-rescorla-tls-esni-00 interestingly, something like DoH is a pre-requisite for pulling off esni.

that's great, but are you coming for the ip addresses too (probably the bigger challenge)?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#229
post #214

Earlier quoted context omitted.

Why do you believe that this will be default on at any time in the near future without a reasonable configuration UI and without a reasonable set of DoH-capable nameservers? Especially given that this would break a substantial number of existing setupts? If you have this little faith into the FF/Mozilla folks, why do you keep using FF? If you’re not using Firefox, what are you concerned about?

If they don't turn it on by default, only a small number of people will use it. If only a small number of people use it, why bother implementing it?

Maybe to see if it works?

Which I think is the purpose of almost all experimental feature.

In the blog it is clearly stated that they hope DoH implementations will become standard and common, maybe that even some ISP start offering their own.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#230

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

> The article doesn't suggest there's something sneaky going on.

The article headline is "Mozilla's new DNS resolution is dangerous", so I guess you are right in saying they are not "suggesting", because they are down right accusing Mozilla of being sneaky.

Post reply on HN