Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

241–250 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#241
To be honest I think it's great news. I would much rather trust Cloudflare to handle my (encrypted) DNS than my ISP. I'm based in the U.K and there are very few ISPs that have private DNS - you often hear stories of (U.K) ISPs selling data out the backdoor to comply with things like the Investigatory Powers Act[1].

[1] https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016

But besides Mozilla's efforts, I am careful not to browse anything political using a vanilla ISP. Anything sensitive is browsed with Tor for anonymity. I only use a VPN for routing traffic over hostile networks like public wifi hotspots / Starbucks wifi. A VPN is not inherently private but a VPN does have its uses, like for viewing geo-locked content (Like the 'This video is unavailable in your country' scenario).

Also for further research if you want to know more about 'trusted' Internet: https://www.youtube.com/watch?v=a4UXnZaunJQ

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#242
post #235

Earlier quoted context omitted.

The first sentence of the article is about TRR/DOH being turned on by default in the next patch.

Can you point to a Mozilla announcement that says they'll turn on DOH by default in a regular non-experimental non-nightly release? This is what Mozilla says in their DOH blog: Our second effort focuses on building a default configuration for DoH servers that puts privacy first. We are running a shield study where some Nightly users will participate in one or more experiments to help us build out a secure, cloud-base…

> Can you point to a Mozilla announcement that says they'll turn on DOH by default in a regular non-experimental non-nightly release?

Right on their blog (https://hacks.mozilla.org/2018/05/a-cartoon-intro-to-dns-ove...), quoted by the article:

"We’d like to turn this on as the default for all of our users. We believe that every one of our users deserves this privacy and security, no matter if they understand DNS leaks or not."

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#243

Earlier quoted context omitted.

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

> The article doesn't suggest there's something sneaky going on. The article headline is "Mozilla's new DNS resolution is dangerous", so I guess you are right in saying they are not "suggesting", because they are down right accusing Mozilla of being sneaky.

Sneaky and dangerous are not the same thing

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#244
post #165

Earlier quoted context omitted.

I believe Mozillas goal is to use the collective bargaining power of it's user-base to get favorable terms and conditions from vendors like cloudflare. This could include 3rd party reviews, etc.. Who knows?

That wouldn't stop legal threats. Per Core Secrets leak, NSA/FBI both pay for and force backdoors in U.S. companies' products. They also share that information with other enforcement organizations per other leaks. Cloudfare are in a position to monitor lots of network activity. I'd be quie surprised if they weren't already backdoored. If NSA/FBI aren't in one's threat profile, one might also be concerned about a cour…

Cloudflare publishes transparency reports https://www.cloudflare.com/transparency/

It also promises not to store your IP associated with the DNS requests https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... so the law enforcement would have to ask Cloudflare to install a wiretap device.

If you're this worried about being traced, it's probably best not to disclose your IP address at all https://blog.cloudflare.com/welcome-hidden-resolver/

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#245
post #164

Earlier quoted context omitted.

So.. in some future Mozilla might select a default DNS provider on your behalf. Did you consider the upside? Mozilla can negotiate on your behalf. Mozilla can obtain favorable terms of service, concessions in privacy, third-party reviews. Things you would never be able to negotiate for. If you think of Mozilla as negotiating on your behalf, they have motive to protect you, and they have the leverage to get concession…

I can't see myself ever supporting this as opt-out rather than opt-in.

Will it not improve security for the majority of Firefox users?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#246

Earlier quoted context omitted.

That wouldn't stop legal threats. Per Core Secrets leak, NSA/FBI both pay for and force backdoors in U.S. companies' products. They also share that information with other enforcement organizations per other leaks. Cloudfare are in a position to monitor lots of network activity. I'd be quie surprised if they weren't already backdoored. If NSA/FBI aren't in one's threat profile, one might also be concerned about a cour…

Cloudflare publishes transparency reports https://www.cloudflare.com/transparency/ It also promises not to store your IP associated with the DNS requests https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... so the law enforcement would have to ask Cloudflare to install a wiretap device. If you're this worried about being traced, it's probably best not to disclose your IP address at all https://blog.cloudfl…

And they would have to hide such a wiretap device from auditors.

Moreover, cloudflare would be in a legal minefield since Mozilla would likely have standing to sue, if cloudflare violates its own terms of service.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#247
post #165

Earlier quoted context omitted.

I believe Mozillas goal is to use the collective bargaining power of it's user-base to get favorable terms and conditions from vendors like cloudflare. This could include 3rd party reviews, etc.. Who knows?

That wouldn't stop legal threats. Per Core Secrets leak, NSA/FBI both pay for and force backdoors in U.S. companies' products. They also share that information with other enforcement organizations per other leaks. Cloudfare are in a position to monitor lots of network activity. I'd be quie surprised if they weren't already backdoored. If NSA/FBI aren't in one's threat profile, one might also be concerned about a cour…

All of these involves cloudflare violating terms of service they've made to Mozilla.

Ideally, this would be caught in an audit and ideally Mozilla would be in a position to sue on your behalf.

How many users sue their ISPs over DNS logging, poisoning or other violations of trust.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#248
post #78

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

Cloudfare can promise what they want, they can still be subject to warrantless spying by US agencies and not disclose anything about it.

But in agreeing to spy they would violate their contract with Mozilla.

Presumably, that would make them liable to damages.

Moreover, they will be subject to audits, where such spying is at risk of getting caught.

This is a lot better than everyone trusting their own ISP.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#249

Earlier quoted context omitted.

That wouldn't stop legal threats. Per Core Secrets leak, NSA/FBI both pay for and force backdoors in U.S. companies' products. They also share that information with other enforcement organizations per other leaks. Cloudfare are in a position to monitor lots of network activity. I'd be quie surprised if they weren't already backdoored. If NSA/FBI aren't in one's threat profile, one might also be concerned about a cour…

Cloudflare publishes transparency reports https://www.cloudflare.com/transparency/ It also promises not to store your IP associated with the DNS requests https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... so the law enforcement would have to ask Cloudflare to install a wiretap device. If you're this worried about being traced, it's probably best not to disclose your IP address at all https://blog.cloudfl…

Let me be more specific: they might be fined out of existence and/or executives do prison time if they don't comply. They'll also be told to lie to preserve both the collection method and their businesses' success. Read the Lavabit case records to see FBI doing that. So, they'd be forced to comply and lie to you about it in that scenario. In such a scenario, faking transparency reports would support the lie and/or do some good showing they're stopping other threats. It's not all or nothing despite forced backdoors.

So, you basically have to believe the US-based company you trust won't take 8-9 digit bribe, will accept bankruptcy, and/or has people who will do time for your privacy. I don't trust anybody running for-profit companies to do that except for maybe Levison. Even he might change after weighing damage he received vs probably no benefit of principled stand. Maybe he'll stay in the fight, too. Who knows. I do know Cloudfare has financial incentives to take massive investments and/or avoid massive losses. Might work against users at some point.

To be clear, Im a big fan of Cloudfare. They're awesome. There's just upper limit of trust since they're profit-motivated operating in a quasi-police state (ie a Dual State).

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#250
post #66

Earlier quoted context omitted.

> Cloudflare has at least promised not to be evil Remember when Google did so, too? Then they bid on military contracts and bought a military contractor.

Cloudfare engaged in censorship so they've already broken that promise.

But if they violate their promise to Mozilla, won't they be liable? And won't Mozilla have standing to sue?

What do you think damages would be if you violate a contract with Mozilla that puts millions of users at risk? (I wouldn't want to test that)

And won't they get caught during audits? Or at least risk it.

Post reply on HN