Live data from Hacker News

DNS-over-HTTPS Policy Requirements for Resolvers

blog.mozilla.org

141–150 of 301 posts

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#141

Earlier quoted context omitted.

What advantages do you see DNSCurve as having over DoT or DoH? (or DNS-over-Quic as that starts rolling out)

Securely contacting the authoritative servers from a recursive resolver under my control instead of relying on some big corporation. Currently DoH or DoT are only used and designed with the goal[0] to secure stub resolver recursive resolver traffic. Someone has to operate that recursive resolver and you have to trust them. So you only shift the problem from having to trust your ISP to having to trust cloudflare/googl…

Maybe I'm misunderstanding something, but aren't you talking about running a stub/recursive resolver with DNSCurve? You could do the same with DoT, or DoH.

It sounds like DNSCurve might be easier to configure and setup from your perspective?

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#142

I replied sub-thread, but adding here to give some more visibility to some of the issues DoH is causing and will cause: I work at a k12 school and I am involved on many k12 IT communities. Some schools already removed Firefox from the students computers because it was being used as a "VPN" by some elementary students to access porn - at school. Guess what this VPN was? Just DNS over HTTPS. There is a fine line betwee…

Don't worry. Soon Chrome will also implement DoH and ESNI, then you actually have to either forbid BYOD or actually start teaching students manners, how browsing porn is not okay in school context. I'm really quite annoyed by the connotation that kids should rather be helicopter-parented (by tech or by people) than actually taught what's okay and what's not. The very least the new tech provides is that any silent hel…

It's not "manners" that's the problem. It's liability (and not just for students-- think "hostile work environment" issues).

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#143

Earlier quoted context omitted.

Yep. What happens when Chrome adds DoH support? And Safari? And whatever Gaming app the kids download? Suddenly it will become impossible to manage and maintain. Not even talking about the troubleshooting nightmare. DNS should be a system-level setting, not an App-level setting.

How far off are we from DoH being supported by common operating systems, DHCP, etc? It would be nice if these apps could detect whether the system is using DoH and only fall back to their own DoH resolver in the case they're using "legacy" DNS.

> How far off are we from DoH being supported by common operating systems, DHCP, etc?

To my knowledge none. Nobody is doing this, because it subverts how DNS is supposed to operate.

> It would be nice if these apps could detect whether the system is using DoH and only fall back to their own DoH resolver in the case they're using "legacy" DNS.

Yeah. Good luck diagnosing that when something stops working as expected.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#144

Earlier quoted context omitted.

Curious, how does your school solve this with students' phones? Have y'all considered requiring mandatory monitoring apps? Or cell phone data jammers and requiring them use y'all's wifi and require a CA cert install?

Reading these comments I'm more and more disgusted really, how is it okay (to even suggest) that personal devices of kids are so invasively monitored? They deserve their internet privacy just as much as grown ups do even more so actually given their higher trust in others, if schools are scared of internet's dangers then schools should educate, not wrap kids into digital bubble wrap that will disappear when they leav…

> how is it okay (to even suggest) that personal devices of kids are so invasively monitored?

It isn't. Sorry my sarcasm didn't come through clear enough, but what you're saying and disagreeing with is my point.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#145
post #52

Earlier quoted context omitted.

To add to this issue from a personal level: for those who use a Pihole or operate other internal services from within their own home network will now have to change the settings for _every application_ using DoH on that network. This could become a major hassle if the number of devices and owners become large. There's not even a work around for this because I do not directly manage family members' devices (nor would…

Having a pihole still doesn't prevent applications from using another resolver - for example dig example.com @8.8.8.8 You'd also need to block all other DNS traffic. And even after that, it's tricky, as applications that are not a browser might be doing this with a hardcoded DoH provider.

> It would be nice if these apps could detect whether the system is using DoH and only fall back to their own DoH resolver in the case they're using "legacy" DNS.

In which case these applications are either broken or malware.

The application needs to fix that by using DNS supplied by the OS, as everyone should do.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#146

Earlier quoted context omitted.

> His main argument seems to be that the network operator should have control over DNS requests And why is that an unreasonable position for a network operator to hold?

The issue comes from network operators wanting to control DNS from being a middleman in the connection, but there is no way to ensure the people acting as middlemen in the connection are authorized to be in the middle or authorized to change those DNS requests. If a network operator can change DNS, then the ISP, network hops, or a malicious twin AP can as well.

> If a network operator can change DNS

The network operator provides an IP through the DHCP response, which also includes proper DNS-settings for that network.

How is this malicious or replacing “your” DNS? The DNS belongs to the network.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#147

Earlier quoted context omitted.

Securely contacting the authoritative servers from a recursive resolver under my control instead of relying on some big corporation. Currently DoH or DoT are only used and designed with the goal[0] to secure stub resolver recursive resolver traffic. Someone has to operate that recursive resolver and you have to trust them. So you only shift the problem from having to trust your ISP to having to trust cloudflare/googl…

Maybe I'm misunderstanding something, but aren't you talking about running a stub/recursive resolver with DNSCurve? You could do the same with DoT, or DoH. It sounds like DNSCurve might be easier to configure and setup from your perspective?

No, the traffic from individual machines to my recursive resolver is already secured or trusted, either because it's a trusted network or going through a tunnel.

What I am missing is a way to secure the traffic from the recursive resolver to all the authoritative name servers in the world, i.e. to achieve end-to-end encryption for lookups.

Yes I am aware that this would require dnscurve support in most authoritative servers around the world and that the rollout would take many years. But DoH provides a false sense of security, to me it's a distraction that just shifts us from ISPs saying "trust us" to google&co doing it.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#149

Earlier quoted context omitted.

So, the internal domain names leak to Mozilla unless I disable this totally?

Not to Mozilla, but to whichever DoH service Firefox is configured to use, by default or by the user. Mozilla isn't running a DoH service.

What is the default?

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#150
post #122

Earlier quoted context omitted.

I definitely don't want my six year old to be able to use their school-provided, Internet-connected iPad any way they please, with plenty of privacy. And yeah the actual solution is "don't fucking give a six year old an Internet-connected device of any sort, obviously, you idiots" but they do, so monitoring and blocking are absolutely necessary.

The original commenter talked about BYOD though, maybe school-given devices are set-up so that they don't let kids do whatever they want. In the case of BYOD, if you're not okay with your kid having an Internet-connected device and that they're going to use it responsibly then don't give him/her one or only allow it under parental supervision. If we're carefully watching and teaching kids kids when they're handling k…

If your child is supervised on the internet and doesn't have a tablet, and mine isn't and does, and my child showed your child stuff you disapproved of while in school, would you complain to the school?

Because some parents would.

Post reply on HN