Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

251–260 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#251
post #247

Earlier quoted context omitted.

That wouldn't stop legal threats. Per Core Secrets leak, NSA/FBI both pay for and force backdoors in U.S. companies' products. They also share that information with other enforcement organizations per other leaks. Cloudfare are in a position to monitor lots of network activity. I'd be quie surprised if they weren't already backdoored. If NSA/FBI aren't in one's threat profile, one might also be concerned about a cour…

All of these involves cloudflare violating terms of service they've made to Mozilla. Ideally, this would be caught in an audit and ideally Mozilla would be in a position to sue on your behalf. How many users sue their ISPs over DNS logging, poisoning or other violations of trust.

"All of these involves cloudflare violating terms of service they've made to Mozilla."

Terms of service don't overrule federal law or court orders. That's assuming they'll turn down money. RSA told customers they were buying crypto with no mention of backdoors. Yet, they put one in for about $30 million.

So, a company might willingly violate ToS for a pile of cash or unwillingly do it via legal coercion that comes with secrecy order. Leaks indicated most took the bribes. Many more bribes or coercions might have happened since. So, we should just assume its true with companies in surveillance states with other security practices designed with that assumption baked in.

Also, it might not even matter if one isnt doing anything over those connections that's illegal. The backdoor becomes something probable but irrelevant for those users. From there, Cloudfare protdcts them from relevant-to-them threats like DDOS or delays causing lost sales.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#252
post #164

Earlier quoted context omitted.

The article doesn't suggest there's something sneaky going on. The article is suggesting that Mozilla are choosing to share your DNS queries with a third party service by default, which is exactly what they're doing. It's not about them choosing Cloudflare in particular, it's about them choosing any particular service by default. And the article's argument that, if you have to choose somebody to share this data with,…

So.. in some future Mozilla might select a default DNS provider on your behalf. Did you consider the upside? Mozilla can negotiate on your behalf. Mozilla can obtain favorable terms of service, concessions in privacy, third-party reviews. Things you would never be able to negotiate for. If you think of Mozilla as negotiating on your behalf, they have motive to protect you, and they have the leverage to get concession…

This replaces decentralised with centralised in the hope it would be a good idea if the choice is right. I'm sceptical, if nothing else because it would be easier to compromise or DoS one target than a lot of individual DNS providers.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#253
post #78

Earlier quoted context omitted.

Cloudfare can promise what they want, they can still be subject to warrantless spying by US agencies and not disclose anything about it.

And lets not forget that their CEO will arbitrarily censor and stop serving people he doesn't like. He's done it before. He'll do it again. Cloudflare has already lost my trust.

In his blog post on that, he said pretty clearly that he doesn't want and should not have this power. https://blog.cloudflare.com/why-we-terminated-daily-stormer/

(Disclosure: I work for Cloudflare.)

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#254

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

DNS over HTTPS might or might not be a great idea; but I'm critical whether centralised is better than the current decentralised approach. You're putting all your eggs in one basket, which might become an exceedingly interesting target.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#255
post #250

Earlier quoted context omitted.

Cloudfare engaged in censorship so they've already broken that promise.

But if they violate their promise to Mozilla, won't they be liable? And won't Mozilla have standing to sue? What do you think damages would be if you violate a contract with Mozilla that puts millions of users at risk? (I wouldn't want to test that) And won't they get caught during audits? Or at least risk it.

I don't really care about "promises" and contracts made between faceless corporations. I have no reason to trust Cloudflare or modern Mozilla, neither have I a reason to believe Mozilla would litigate against a breach of contract publicly instead of settling privately and secretly to prevent public outrage.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#256
post #68

Earlier quoted context omitted.

As I understand it that's even the default choice, and CloudFlare is just the provider they're currently testing this with for those who do choose and do not configure their own provider.

The point is though that users won't change their defaults. When Mozilla sets the default to Cloudflare, > 99.9% of the users will use it.

So the default is that this is off. If and when that changes, the question that should be relevant is whether the majority of those users is better served with CloudFlare than their ISP, given their threat model.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#257

Earlier quoted context omitted.

Harder to distinguish between DNS queries and other traffic. Since a lot of censorship is DNS based that’s significant.

This is really the main point. I support this but it has its downsides, for example flixbus blocks YouTube on their free WiFi. I think they have all the rights to do it as some site are heavier to support than others and they might be forced to shut it off if it became common (Also a lot of people don't have earphones on them an being beside someone watching "funny" YouTube videos at 3am is torture (end of personal r…

Wouldn't this be better served by bandwidth limiting/shaping?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#258
post #112

Earlier quoted context omitted.

Is there anything left, that's not on HTTP? Maybe NTP. I know about JMAP to replace IMAP. Here's another idea: other protocols are useful as well, sometimes more useful, than HTTP. > HTTPS stacks are battle tested and there are multiple of them. So is DNS. I wonder how the HTTP servers deal with DNS amplification attacks. > People running a DNS resolver likely have the ability to run a good HTTPS server already Your…

DNS over HTTPS is immune to amplification attacks. If the alternative to DNS over HTTPS is a DNS-over-TLS resolver being run by a company without a website (???) then I guess that's easier than DNS-over-HTTPS. Are you really going to use a resolver run by a mysterious nobody? There are probably more than a dozen HTTP stacks being widely used in production. It's not remotely a monoculture.

[deleted]

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#259

Earlier quoted context omitted.

right - but we're coming for cleartext sni too: https://tools.ietf.org/html/draft-rescorla-tls-esni-00 interestingly, something like DoH is a pre-requisite for pulling off esni.

that's great, but are you coming for the ip addresses too (probably the bigger challenge)?

wrt esni the anonymity pool is definitely the set of content that can share the same address pool. In a world with lots of CDNS (and several multi-CDN switching services) this covers a huge amount of content - but I agree - not everything.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#260

Earlier quoted context omitted.

that's great, but are you coming for the ip addresses too (probably the bigger challenge)?

wrt esni the anonymity pool is definitely the set of content that can share the same address pool. In a world with lots of CDNS (and several multi-CDN switching services) this covers a huge amount of content - but I agree - not everything.

If you think about the best/worst case scenario, would you be happy if one CDN would deliver everything? I think that we would be in a worst situation... ideally, I think that everyone would have their own servers and that your ISP would not even be able to see which IP addresses you are talking too (completely decentralized)
Post reply on HN