Live data from Hacker News

Firefox Nightly Secure DNS Experimental Results

blog.nightly.mozilla.org

11–15 of 15 posts

Re: Firefox Nightly Secure DNS Experimental Results

#11
post #10

To the Mozillians that follow these threads, Shame on you for making studies like this opt-out. Look, I get that making it opt-in would reduce your sample size but this kind of thing isn't acceptable for a browser that's supposed to respect the user -- you're literally using dark patterns. Expressed consent should be the standard. You're targeting Nightly users, the very people who know enough to make an informed dec…

The article specifies that only users on Nightly who opted in previously to Nightly _Experiments_ were targeted, and were in the dataset. The first experiment you join in Firefox usually has several steps of confirmations and opt-ins.

Re: Firefox Nightly Secure DNS Experimental Results

#12
post #7

It's quite dissapointing how much outraged the initial announcement of DoH generated and then the results are mostly ignored. I find it quite exiciting tbh, the improvements seem to be far on the good side, it might help mobile users a lot (my mISP interferes with DNS to block VPN and tries to show ads if it fails to resolve an address). Of course they'll have to work making sure that privacy is preserved and poeple…

I missed the initial announcement, what was all the outrage about?

Re: Firefox Nightly Secure DNS Experimental Results

#13
post #12
post #7

It's quite dissapointing how much outraged the initial announcement of DoH generated and then the results are mostly ignored. I find it quite exiciting tbh, the improvements seem to be far on the good side, it might help mobile users a lot (my mISP interferes with DNS to block VPN and tries to show ads if it fails to resolve an address). Of course they'll have to work making sure that privacy is preserved and poeple…

I missed the initial announcement, what was all the outrage about?

Mostly that Mozilla was selling out users to Cloudflare and they would enable the Cloudflare DNS per default for all users on release.

Re: Firefox Nightly Secure DNS Experimental Results

#14
post #8

As an individual,this is great news for me. But for corporate use,this means having to intercept https unless you can turn DoH off via GPO or something. These days,credential and PII theft phishing is a huge concern. Without intercepting https,the only way to know if a user went to a phishing site is by logging DNS or relying on SNI(SNI encryption is being developed as well).

I'm sure it'll end up in https://github.com/mozilla/policy-templates/blob/master/READ... if it gets officially added and released.

Though I will say inspecting DNS for phishing protection is like watching your front door to catch a burglar.

Re: Firefox Nightly Secure DNS Experimental Results

#15
post #8

As an individual,this is great news for me. But for corporate use,this means having to intercept https unless you can turn DoH off via GPO or something. These days,credential and PII theft phishing is a huge concern. Without intercepting https,the only way to know if a user went to a phishing site is by logging DNS or relying on SNI(SNI encryption is being developed as well).

I'm sure it'll end up in https://github.com/mozilla/policy-templates/blob/master/READ... if it gets officially added and released. Though I will say inspecting DNS for phishing protection is like watching your front door to catch a burglar.

Once you know of a phishing attack (or malware activity) you need to check what users fell for it. For prevention, your run of the mill phishing campaign blasts emails at a large number of recipients,you can block domains it uses to prevent infection or visits to malicious URLs.

In essence,defenders need to monitor for and block attacker infrastructure.

Post reply on HN