Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

231–240 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#231
post #164

Earlier quoted context omitted.

So.. in some future Mozilla might select a default DNS provider on your behalf. Did you consider the upside? Mozilla can negotiate on your behalf. Mozilla can obtain favorable terms of service, concessions in privacy, third-party reviews. Things you would never be able to negotiate for. If you think of Mozilla as negotiating on your behalf, they have motive to protect you, and they have the leverage to get concession…

It’s already happening: the DoH endpoint that Mozilla defaults to on the CF-Side has a stronger privacy agreement as per https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr...

CF is not a default. There is no default.

CF is a partner in studying an experimental feature

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#232
post #113

Earlier quoted context omitted.

You forgot the more pragmatic reason: middleboxes. HTTPS works everywhere, and introducing a new(2 years old) protocol (DNS over TLS) working on a new port (853) is a sure way to make sure it does not work in many places.

That mostly applies to corporate environments which already want to use their own resolvers anyway. For most people DNS over dTLS should work fine and if anything should be implemented on the OS level. Your browser is not special, everything could benefit from secure DNS.

Well, once OS starts doing it maybe mozzilla will switch to that as default...

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#233
post #94

Earlier quoted context omitted.

>DNS over HTTPS is a great idea Why is it better than DNS over TLS? All I can see here is increased overhead.

Harder to distinguish between DNS queries and other traffic. Since a lot of censorship is DNS based that’s significant.

This is really the main point.

I support this but it has its downsides, for example flixbus blocks YouTube on their free WiFi. I think they have all the rights to do it as some site are heavier to support than others and they might be forced to shut it off if it became common

(Also a lot of people don't have earphones on them an being beside someone watching "funny" YouTube videos at 3am is torture (end of personal rant...))

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#234

Earlier quoted context omitted.

The feature is opt-in. Firefox will use your system configured DNS servers unless you explicitly enable DOH. In that case you can still change Cloudfare for some other server if you’d like.

The impression I got from TFA is that the feature will be on by default and you have to dig into about:config to disable it.

They retracted it

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#235
post #202

The article is incorrect. 1. TRR is not turned on by default. To turn it on, you need to go to about:config and set network.trr.mode to something other than 0 or 5. 2. Even if trr.mode is turned on, you need to go in and set the DOH server at network.trr.uri. The default is blank. You can set it to any publicly known DOH server ( https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-av... ), or even your own. 3.…

The first sentence of the article is about TRR/DOH being turned on by default in the next patch.

Can you point to a Mozilla announcement that says they'll turn on DOH by default in a regular non-experimental non-nightly release?

This is what Mozilla says in their DOH blog:

Our second effort focuses on building a default configuration for DoH servers that puts privacy first.

We are running a shield study where some Nightly users will participate in one or more experiments to help us build out a secure, cloud-based service that handles DoH requests. All Nightly users will receive an in-product notification about these studies.

Cloudflare is our partner for these experiments. When a shield study is active, Nightly Firefox will automatically use Cloudflare’s secure DNS over HTTPS service (though we aren’t using the famous 1.1.1.1 address). The first study will test whether DoH’s performance is up to the task.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#236
post #165

Earlier quoted context omitted.

Cloudflare is an US company, their privacy statement is worth zero to most Firefox users.

I believe Mozillas goal is to use the collective bargaining power of it's user-base to get favorable terms and conditions from vendors like cloudflare. This could include 3rd party reviews, etc.. Who knows?

That wouldn't stop legal threats. Per Core Secrets leak, NSA/FBI both pay for and force backdoors in U.S. companies' products. They also share that information with other enforcement organizations per other leaks. Cloudfare are in a position to monitor lots of network activity. I'd be quie surprised if they weren't already backdoored.

If NSA/FBI aren't in one's threat profile, one might also be concerned about a court order over something having to do with copyright or patents. Damages for those can be huge. There's both legal and technical firms dedicated to pouring through data for evidence of patent infringements. Many licensing "agreements" start with evidence they find. I don't know much more about this. My wild guess is that they often start with tips from disgruntled workers or maybe those leaving for competitors.

These are main, three threats I'd be concerned about if sharing what I did with a U.S.-based provider. Double true for me given I'm in the jurisdiction of the enforcement agencies.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#237
post #135

Earlier quoted context omitted.

But that’s a different argument you’re making. For many people, routing the browsers DNS via a secure channel is a substantial improvement. You’re still free to route all your network DNS via DoH, there’s software for that. But until DoH is the operating systems default (or at least a non-expert option), this can be a viable improvement.

Yes. If it's opt-in, then I can certainly live with it and I understand why people might use it. I'm just pointing out that features like these, while well intentioned, still add bloat to the browser. Sometimes saying no to feature inclusion is the right thing to do in the long term even if it has a use in the short term. I'm a big believer of the Unix philosophy of do one thing and do it well.

Modern browser are basically OSes not by coincidence but because they are basically used as OS replacement. I think Tanenbaum (citation needed) wrote that an OS basically does two things: abstracting the HW and managing resources. Browsers do the latter as much as an OS

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#238

Earlier quoted context omitted.

I think you substantially overestimate the number of providers that behave ethically with regards to DNS and substantially underestimate how many people have shitty ISPs. You seem to have a very skewed view of how the number of internet users distributes across the world. Even in Europe, providers are not refraining from hijacking DNS and using DNS blocks for certain sites.

I think you substantially underestimate the number of networks that use split-horizon DNS for their functioning, and where hijacking the DNS is going to cause significant breakage.

Which are almost zero home network of non technical users

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#239
post #202

The article is incorrect. 1. TRR is not turned on by default. To turn it on, you need to go to about:config and set network.trr.mode to something other than 0 or 5. 2. Even if trr.mode is turned on, you need to go in and set the DOH server at network.trr.uri. The default is blank. You can set it to any publicly known DOH server ( https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-av... ), or even your own. 3.…

The first sentence of the article is about TRR/DOH being turned on by default in the next patch.

Which is false.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#240
post #66

Earlier quoted context omitted.

> Cloudflare has at least promised not to be evil Remember when Google did so, too? Then they bid on military contracts and bought a military contractor.

It may surprise you, but not everyone believes the military is evil, and thus working with them is evil.

Well, military's purpose is killing people. Now if that is evil or not of course depends on your beliefs.
Post reply on HN