Live data from Hacker News

Encrypted SNI Comes to Firefox Nightly

blog.mozilla.org

131–140 of 155 posts

Re: Encrypted SNI Comes to Firefox Nightly

#131
post #82

As a cancer survivor, using the example of someone spying on your cancer.org visit as a motivation for encrypted SNI seems a bit excessive and insensitive. There are definitely more neutral ways of motivating eSNI than invoking the fear of a stranger finding out you or a loved one has cancer. Shame on Mozilla.

Cancer is something you may want to keep secret without being shameful. In privacy discussions, such examples are rare.

Yet, those examples are useful because they prevent people dismissing the arguments because `people shouldn't be doing that anyway`. That is, no-one wants to keep people from going to cancer-related websites. This is very different from e.g. porn or STDs. I guess perhaps the exception are the nut-cases that believe people getting cancer `deserve it` because otherwise it wouldn't be part of gods plan. But luckily very few people consider those opinions relevant.

Re: Encrypted SNI Comes to Firefox Nightly

#132
post #27

So what's the plan for when IPv6 gains more adoption and we don't need SNI as much since every site can have its own public IP address (thus making tracking easier, subverting the benefits of encrypted SNI). Do you think encrypted SNI and NAT will become preferred to using IPv6 for routing because of the privacy benefits of ESNI (either real or imagined, depending on who you trust, since this seems to be relying on c…

IPv6 will never gain universal adoption. Nobody wants their home or their datacenter machines exposed to the whole Internet all the time. NAT is a feature, not a bug.

You need state tracking to build a masquerading NAT (or it won't know which machine to route reply packets to), and if you have state tracking, you can also build a stateful firewall, which will achieve the same thing.

Stateful firewalls still work, have always worked, and work the same in IPv6 as they do in IPv4. Having a public, globally-routable, unique address on your internal machine, whether that's an IPv4 address or an IPv6 one, doesn't mean that anyone can connect to it. It still has to go through your router. That router can be running a stateful firewall.

NAT is awful.

Re: Encrypted SNI Comes to Firefox Nightly

#133
post #96

Earlier quoted context omitted.

That example does make a very strong case for the feature - which I guess was the point. But, the audience for the post already knows that encrypted SNI is and why it's important. And if they don't, a much more light-hearted example would do. And it's not like there is much of an anti-encrypted-SNI movement that warrants a powerful response. So, yeah, I'd agree it seemed both jarring and unnecessary.

Yeah not sure why I'm being downvoted. Imagine if the example was HIV.org or ebola.org, totally doesn't seem necessary.

You're being downvoted because your own statement contradicts itself. You're so touchy about the cancer thing that you're complaining about it.

Re: Encrypted SNI Comes to Firefox Nightly

#134

Earlier quoted context omitted.

Yeah not sure why I'm being downvoted. Imagine if the example was HIV.org or ebola.org, totally doesn't seem necessary.

You're being downvoted because your own statement contradicts itself. You're so touchy about the cancer thing that you're complaining about it.

I'm touchy about the cancer thing because I had my leg amputated and went through chemo for a year.

Re: Encrypted SNI Comes to Firefox Nightly

#135

Earlier quoted context omitted.

If your browser is talking to a DNS resolver wired to your OS, that doesn't change what any upstream network observer sees, since they can observe DNS requests generated by your OS-level DNS resolver exactly as they would observe DNS requests generated by your browser. DOH isn't about trust. It's about preventing network observers from figuring out what sites you visit by observing the DNS requests you make.

Not _only_ about trust. One of the things DoH gets you for free is that it means that your ISP doesn't get to touch DNS requests, which was not true previously. You can get Internet service from whatever bunch of money-grabbing assholes are available where you live, and get DNS from somebody else without that being tampered with since it's encrypted on the wire. You do still have to trust the DoH provider (outside of…

Conventiently, the same will also apply to me trying to block apps from talking over the network with things they should not talk to.

Re: Encrypted SNI Comes to Firefox Nightly

#136
post #92

Earlier quoted context omitted.

And definitely read the post by Thomas Ptacek linked to from that article: https://sockpuppet.org/blog/2015/01/15/against-dnssec/ . He makes the excellent point that DNSSEC (and thus DANE) doesn't get rid of CAs at all - it just makes whoever controls the domain into a defacto CA. Yeah, Comodo behaved badly as a CA - so, the browsers are in the process of no longer trusting it; imagine if DANE were in widespread use…

Thomas Ptacek (the guy whose blog post you've linked) agrees with Thomas Ptacek (tptacek, the guy whose sub-thread you're replying to)? Not exactly a revelation. Also Thomas has rejected the suggestion that the parts of his post that are now hopelessly wrong should be mentioned in the FAQ he prominently links. So, that post is wrong and explicitly won't be fixed, you should not rely on the "facts" in it unless you wa…

> Thomas Ptacek (the guy whose blog post you've linked) agrees with Thomas Ptacek (tptacek, the guy whose sub-thread you're replying to)? Not exactly a revelation.

Lol, I didn't read the username.

> So, that post is wrong and explicitly won't be fixed, you should not rely on the "facts" in it unless you want to get laughed at.

I haven't analyzed everything in that blog post. However, the case it makes against DANE I think is convincing. I linked to that blog post since it was the one that made me realized that DANE was a bad idea when I was briefly a DANE enthusiast a few years ago.

> Your mention of Comodo suggests you're badly confused.

I accidentally slipped and used the wrong CA - I think "badly confused" is a bit strong for a slip of the tounge.

> Don't put new things in .com unless you're comfortable with for-profit companies screwing you over whenever it suits them.

It sound like you are also arguing that DANE is a bad idea.

> DNSSEC can't make that worse, it's already terrible.

I don't think I said anything to the contrary.

I'm real confused by the aggressive tone - it seems like you agree with everything of substance I wrote and the things you don't agree with are things that I didn't actually say.

Re: Encrypted SNI Comes to Firefox Nightly

#137

Earlier quoted context omitted.

Yeah not sure why I'm being downvoted. Imagine if the example was HIV.org or ebola.org, totally doesn't seem necessary.

You're being downvoted because your own statement contradicts itself. You're so touchy about the cancer thing that you're complaining about it.

> touchy about the cancer thing

Wow. That is technically a valid English phrase. What boggles the mind is that someone could be so out of touch with societal norms and basic human decency that they would actually use it.

Re: Encrypted SNI Comes to Firefox Nightly

#138
post #92

Earlier quoted context omitted.

And definitely read the post by Thomas Ptacek linked to from that article: https://sockpuppet.org/blog/2015/01/15/against-dnssec/ . He makes the excellent point that DNSSEC (and thus DANE) doesn't get rid of CAs at all - it just makes whoever controls the domain into a defacto CA. Yeah, Comodo behaved badly as a CA - so, the browsers are in the process of no longer trusting it; imagine if DANE were in widespread use…

Thomas Ptacek (the guy whose blog post you've linked) agrees with Thomas Ptacek (tptacek, the guy whose sub-thread you're replying to)? Not exactly a revelation. Also Thomas has rejected the suggestion that the parts of his post that are now hopelessly wrong should be mentioned in the FAQ he prominently links. So, that post is wrong and explicitly won't be fixed, you should not rely on the "facts" in it unless you wa…

You keep alluding to parts of that post that are outdated, but you never provide specifics.

I appreciate and will remember the concession that security for .COM is hopeless.

Re: Encrypted SNI Comes to Firefox Nightly

#139
post #49

Earlier quoted context omitted.

> (and, separately, pick from any DNS provider that supports DOH). But why do I have to? I already have a trusted DNS resolver operated by myself wired to my OS. Why require the whole DoH rube goldberg machinery to let me try ESNI?

DNS is plaintext, like HTTP, so running your own resolves does nothing to protect your internet provider from selling your domains resolved list - in aggregate or in specific - to other companies for revenue. There are three well-known trusted public DNS resolvers, run by Cloudflare, Verizon, and Google. Which of those three would you encrypt your DNS traffic to, if those were the only three options available other t…

DNS does not need to be plaintext and DoH is not the only alternative. It's the alternative that the advertising engines and CDNs prefer because it extends control. The privacy of DNS argument is a major red herring.

DNSCrypt (or DNS over TLS or DTLS) is a wonderful alternative that works in-band and works with DNSSEC.

People are also ignoring the consequences of the switch from UDP to TCP.

Re: Encrypted SNI Comes to Firefox Nightly

#140
post #129

Earlier quoted context omitted.

DNS is plaintext, like HTTP, so running your own resolves does nothing to protect your internet provider from selling your domains resolved list - in aggregate or in specific - to other companies for revenue. There are three well-known trusted public DNS resolvers, run by Cloudflare, Verizon, and Google. Which of those three would you encrypt your DNS traffic to, if those were the only three options available other t…

I think the specific question is: Why prefer `DNS over HTTPS` over e.g. `DNS over TLS`. The relevant matter is that DNS requests are encrypted. How exactly it is encrypted should not matter.

AFAIK it doesn't matter. DNS over TLS would work fine too (though I'm not sure if Firefox supports it). The important thing is that you're not using plaintext DNS, as that would defeat the purpose of using ESNI in the first place.
Post reply on HN