Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

291–300 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#291

Earlier quoted context omitted.

Many already run their own resolvers, so providing DNS-over-HTTPS proxy is not a problem. What is THE problem, is configuring the browser. No one is going to reconfigure their browser after each connection to a different network. There's a reason why we moved from static configuration towards DHCP, which can configure network-specific settings. DNS is a network-specific setting, and Mozilla is breaking it.

Split horizon was always a bad hack, there has always been alternatives. DoH could be used on the default DNS servers too, there is value of encrypted DNS on LAN as well.

> Split horizon was always a bad hack, there has always been alternatives.

I always see this repeated as a mantra, but never it's rationale. No company is going to advertise their internal infrastructure needlessly. There's no upside in the world knowing that your _kdc._tcp.company.com is 192.168.10.20; but there are downsides.

> DoH could be used on the default DNS servers too, there is value of encrypted DNS on LAN as well.

Sure, but hardcoding or statically-configuring the value is not the way. LANs need to have their DHCP tags respected. If one of them is "use this URL for DoH-server", that's fine.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#292

Earlier quoted context omitted.

Great, all your data is stored for 24 hours and then collected in "anonymised" form for further processing and "internal research"! Also no mention of penalties, either for Cloudflare as a company or the responsible employees (starting with the CEO) in case of a violation. And no notice period of any time should Cloudflare decide to change those terms and have thousands of browsers still pointed at its resolvers. Why…

It's a legally binding contract between Cloudflare and Mozilla. If Cloudflare were to violate it, Mozilla could sue and a judge would determine the penalties for Cloudflare. There should be some rough guidelines written into law as well. And we're definitely not talking about small amounts. Cloudflare violating it would result in Mozilla violating the privacy of millions, which can be interpreted as significant damag…

Note also:

> Cloudflare will also collect and store the following information as part of its permanent logs. [...]

- Aggregate list of all domain names requested

So while they might not associate it with a person, they will collect all domain names they get and store them for their own purposes.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#293
post #292

Earlier quoted context omitted.

It's a legally binding contract between Cloudflare and Mozilla. If Cloudflare were to violate it, Mozilla could sue and a judge would determine the penalties for Cloudflare. There should be some rough guidelines written into law as well. And we're definitely not talking about small amounts. Cloudflare violating it would result in Mozilla violating the privacy of millions, which can be interpreted as significant damag…

Note also: > Cloudflare will also collect and store the following information as part of its permanent logs. [...] - Aggregate list of all domain names requested So while they might not associate it with a person, they will collect all domain names they get and store them for their own purposes.

restricted to: "solely to improve the performance of Cloudflare Resolver for Firefox and to assist us in debugging efforts if an issue arises"

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#294

Earlier quoted context omitted.

FF will turn this on for everybody and Cloudflare will be the default 2018? Don't know. 2019? For sure. All FF browsing meta data flows into the US, the country with the most spies and no legal framework to go to court. So your argument is an obvious straw man and one wonders about your motivations to support getting all the browsing meta data into the US by default. Moving my data from Germany to the US will not mak…

Why does so many people distrust every single step done by mozzilla!? Sorry, this got me emotional, but since I started following tech news few years ago the amount of fake news on mozzilla I read is astounding. And proper fake news. Many, as this article does, do no claim that a new feature dangerous per se, but falsely (I don't think with purpose, that is what I find astounding) quote mozzilla blogs to build an apo…

In today's world, it's important to remain skeptical of companies who are responsible for how our data and usage statistics are used or shared. Companies have generally shown themselves to be untrustworthy and it's not enough for a company to have been 'good' so far. We need to stay vigilant, even if it is Mozilla.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#296
post #145

Earlier quoted context omitted.

The internet has decentralized architecture underneath but the model is being abandoned because traffic volumes are too high for the naive decentralized architecture. Today 60% of the global internet traffic goes trough CDN's. In 2021 it will be over 70% in 2021 (over 90% in North America). There is whole "internet cache" industry standing between clients and servers. When you connect to some site in the internet, mo…

You cannot compare CDN with DNS which does not require high traffic volumes nor expensive servers. The issue is pervasive laying of trust into "benevolent" third parties, CA's apparently are not enough and we now must have Trusted Recursive Resolvers, too. And it's more and more difficult to set up alternative infrastructure which does not rely on them.

>You cannot compare CDN with DNS

I didn't compare them.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#297

DNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to…

> I have no reason whatsoever to trust [any ISP], at all.

You also have no reason to trust cloudflare, at all.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#298

> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so . Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I ha…

> Cloudflare has at least promised not to be evil

lol

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#299

Earlier quoted context omitted.

Which are almost zero home network of non technical users

I've never seen any marketing materials, where Mozilla limits themselves to non technical users with zero home network. Did you?

No, but they do exist and specifically in this case (since they mention public wifi) pro users capable of configuring their system dns might not be the only target audience

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#300

Earlier quoted context omitted.

This is really the main point. I support this but it has its downsides, for example flixbus blocks YouTube on their free WiFi. I think they have all the rights to do it as some site are heavier to support than others and they might be forced to shut it off if it became common (Also a lot of people don't have earphones on them an being beside someone watching "funny" YouTube videos at 3am is torture (end of personal r…

Wouldn't this be better served by bandwidth limiting/shaping?

that would mean that if many people used youtube they would all have terrible speed, which would make their wifi look of bad quality.

The primary purpose of their on board wifi is to buy tickets and check connections. In this case video streaming might really be more expensive than necessary

Post reply on HN