Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

301–306 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#301

Earlier quoted context omitted.

Why does so many people distrust every single step done by mozzilla!? Sorry, this got me emotional, but since I started following tech news few years ago the amount of fake news on mozzilla I read is astounding. And proper fake news. Many, as this article does, do no claim that a new feature dangerous per se, but falsely (I don't think with purpose, that is what I find astounding) quote mozzilla blogs to build an apo…

In today's world, it's important to remain skeptical of companies who are responsible for how our data and usage statistics are used or shared. Companies have generally shown themselves to be untrustworthy and it's not enough for a company to have been 'good' so far. We need to stay vigilant, even if it is Mozilla.

Totally agree! it is also important to mozzilla to know the won't be easily forgiven bad choices.

I'm wondering why the constant and maybe not even ill-intentioned misinformation about the word they say.

I don't want to accuse anyone, I believe that both side value the truth, but it really looks like as if there was a fake news factory against mozzilla

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#302

I'm not looking forward to this. I use internal DNS for stuff I'm running at home (e.g., a NAS, Home Assistant, etc). I don't want to go back to the bad old days of having to remember what IP addresses go with what service. My girlfriend is not going to like it when Pi-Hole magically stops working because Firefox doesn't respect the DNS settings that are served by DHCP. My employer uses internal DNS for internal serv…

> Cloudflare is going to have a huge list of internal stuff used by Firefox Nightly users

By Firefox Nightly users who agree to be in the study, yes?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#303

Earlier quoted context omitted.

Wouldn't this be better served by bandwidth limiting/shaping?

that would mean that if many people used youtube they would all have terrible speed, which would make their wifi look of bad quality. The primary purpose of their on board wifi is to buy tickets and check connections. In this case video streaming might really be more expensive than necessary

I mean limiting per-user bandwidth. So if you try to watch youtube on your personal 1Mb slice, good luck, but you won't drag down anyone else, and for the stated goals of buying tickets and such it's fine.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#304

Earlier quoted context omitted.

HTTPS gives you the packet ordering costs of TCP and the handshake costs of TLS. With an SSH-like key setup - i.e. just getting the server's pubkey on first use and rolling it over when it advertises a new one - you could asymmetrically encrypt every request in a single UDP packet and thus gain the same security and lower 99'tile latency.

HTTPS gives you clear upgrade path to QUIC and handshake costs of TLS 1.2-3 as well. This is the very goal of this study - to determine how feasible is it in the real world and what's the performance impact.

You still don't need HTTP(S) for that. You could still use dTLS and later experiment with raw QUIC, sans HTTP.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#305
post #60

Earlier quoted context omitted.

With SNI they also know the domain you're connecting to.

There are people working on encrypted SNI: https://huitema.wordpress.com/2017/09/12/cracking-the-sni-en... it'll take some time, but we'll get there hopefull soon.

Good point, but it's not here now. It is however better than the old days where you needed your own IP address to do TLS/HTTPS.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#306

Earlier quoted context omitted.

I've never seen any marketing materials, where Mozilla limits themselves to non technical users with zero home network. Did you?

No, but they do exist and specifically in this case (since they mention public wifi) pro users capable of configuring their system dns might not be the only target audience

So make it active only for public wifi, or whatever is labeled as public network by the operating system or firewall? Certainly not all networks.
Post reply on HN