Live data from Hacker News

DNS-over-HTTPS Policy Requirements for Resolvers

blog.mozilla.org

281–290 of 301 posts

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#281

Earlier quoted context omitted.

> you're being foolishly contrarian instead of trying to understand what the original commenter's actual situation is Perhaps because he's describing 2 different situations. One where "some schools" are removing Firefox, and one where it's not an option for him because of BYOD. Uninstalling Firefox is exactly the solution he can't apply. So I still maintain that the other schools that fully control the clients could…

this is getting really boring and repetitive, but you didn't give a "cheaper" solution, you gave an administratively more expensive solution (change files on machines rather than bulk remove an app which is out of the box functionality for many products IT like this would use), along with moving the goal posts; the goal is "keep my DNS filtering working," not "make sure no one ever gets to the porn site." of course,…

You didn't understand OP's comment and realized only after I pointed out that HE is the one with the BYOD problem where uninstall can't fix anything. I'm not the one moving the goalposts. His only option is applied outside of the client, at network level. As for the other schools, the effort they put in today bought them a week or two at most. More than enough time for the students to have "workarounds" in place and access anything they want since as you said the admin has no resources to control what's happening on the machine. But you know, it's unwise to pay too much, but it's worse to pay too little; buy cheap, buy twice; poor man pays twice.

They were better off uninstalling Chrome. Firefox at least can be controlled with a config file and a script to do bulk copy, Chrome wants GPOs and without lockdown you have a ton of extensions in the store to make your DNS filtering redundant. I believe the latter is the better option but if a config file is beyond the possibilities of the school admin I expect their browsers to be fully unmanaged and at the mercy of the user. It can't be both ways.

I appreciate that you finally confirm what I said from the beginning: It is a half assed job (because doing it properly "is a luxury"). Uninstalling just kicks the problem down the road and lets "future you" deal with it a few days or weeks later.

> an app which is out of the box functionality

Begs the question why put in effort to install then uninstall it when there was no need for either. I'm not in their head but one thing's for sure, your explanation relies on conflicting argumentation. We're talking about a hypothetical Schrödinger's admin that at the same time both has and hasn't got the resources to do the work.

Cheerio.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#282

Earlier quoted context omitted.

Nothing in the article says anything about that. The article talks about Firefox behavior when DoH is enabled. It's not enabled by default. The article doesn't say it's getting enabled by default, or under what conditions it might get enabled by default.

At the very start of the linked article, it says this: "Over the past few months, we’ve been experimenting with DNS-over-HTTPS (DoH), a protocol which uses encryption to protect DNS requests and responses, with the goal of deploying DoH by default for our users."

That's correct, but the requirements that need to be met for it to be enabled by default are still being determined.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#283

Earlier quoted context omitted.

Nothing in the article says anything about that. The article talks about Firefox behavior when DoH is enabled. It's not enabled by default. The article doesn't say it's getting enabled by default, or under what conditions it might get enabled by default.

They have already stated they will be switching it on by default: https://mailarchive.ietf.org/arch/msg/doh/po6GCAJ52BAKuyL-dZ... “4. The user will be informed that we have enabled use of a TRR and have the opportunity to turn it off at that time, but will not be required to opt-in to get DoH with a TRR.”

Yes, I'm aware. Again, the conditions that need to be met for this to happen are still being determined, including the timeframe and the exact behavior.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#284

Earlier quoted context omitted.

DNS-over-HTTPS in Firefox? Yes, it does, at the moment. See https://searchfox.org/mozilla-central/rev/dd7e27f4a805e4115d... -- 0 means it's off.

5 is "off by choice"

Yes, the difference is that 0 is the default value right now, so if you set it in about:config all Gecko remembers is "it's the default" and stores nothing in user.js; if the default then changes the value changes.

5 is not the default, so if you set it it will get stored in user.js and then even if the default changes the value will remain 5.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#285
post #280

Earlier quoted context omitted.

You would be correct if that were my attitude, but it's not. This is not a panacea, it's one component in a larger security posture.

If DNS-based access control is not sufficient on it's own, then is it really worth it to block DoH (which could have other significant security and privacy benefits) just to retain the possibility of using it? Why not focus on improving those other, already necessary access control technologies and forget about abusing DNS for this purpose, so we get the best of both worlds?

Because I believe in multilayered security. No one approach to security is sufficient, but combining as many approaches as possible can allow each approach to help cover the weaknesses of the other approaches.

Also, I disagree that denying the lookup of certain domain names is abusing DNS. If I were running a DNS server that was being used by the public, or that was being used by downstream DNS servers, that would be different.

Also, I'm not aware of a method that can accomplish the sort of coverage that blocking DNS lookups can. If you have an alternative, I'd be genuinely interested in hearing about it.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#286
post #7

Earlier quoted context omitted.

If an iot device in your home network is exfiltraring data about you, it becomes much harder to identify with dns over https. Dns over https creates more problems than it solves for 99% of end users.

The argument that because encryption can be used for nefarious purposes it should not be offered by DNS providers at all does not add up. ISPs can block, redirect and sell DNS traffic and many are already doing some or all of these.

I don't think anybody is arguing that DNS lookups shouldn't be encrypted. The issue is doing DNS lookups via HTTPS.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#287

Earlier quoted context omitted.

Don't worry. Soon Chrome will also implement DoH and ESNI, then you actually have to either forbid BYOD or actually start teaching students manners, how browsing porn is not okay in school context. I'm really quite annoyed by the connotation that kids should rather be helicopter-parented (by tech or by people) than actually taught what's okay and what's not. The very least the new tech provides is that any silent hel…

> Soon Chrome will also implement DoH and ESNI, then you actually have to either forbid BYOD or actually start teaching students manners... If you think that this is how it will go, you're very naive. If schools and parents can't block porn anymore, prepare for more legislation that blocks porn by default at the ISP unless you pay some kind of fee - like what the UK has proposed. Also look for a return of "content st…

Maybe they're not from the West, and are just ignorant of how ignorant we are, not naïve.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#288

Earlier quoted context omitted.

Yep. What happens when Chrome adds DoH support? And Safari? And whatever Gaming app the kids download? Suddenly it will become impossible to manage and maintain. Not even talking about the troubleshooting nightmare. DNS should be a system-level setting, not an App-level setting.

How far off are we from DoH being supported by common operating systems, DHCP, etc? It would be nice if these apps could detect whether the system is using DoH and only fall back to their own DoH resolver in the case they're using "legacy" DNS.

What's the point of using DoH over the local network? We can generally assume the local network is "secure".

If I want to use DoH when sending DNS queries to the outside world, I can setup my own forwarder to forward DNS queries via DoH.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#289
post #3

Earlier quoted context omitted.

After seeing every implementation of DoH giving a flying fuck about your actual network settings, I’ve decided it’s a technology I want nothing to do with. I’ve actually actively blocked DoH for the major providers on my router, by writing some custom iptables rules. Hopefully there will be a simple to use OpenWrt-package which you can install to do this automatically in the future.

Could you share those iptables rules please?

I'll have to correct myself. It seems I gave up on the iptables-approach due to having some correctness errors.

Instead I ended up with these lines in /etc/config/firewall:

    config rule
        option target 'ACCEPT'
        option name 'Allow router to perform DNS'
        option family 'ipv4'
        option src_ip '192.168.1.1'
        option dest_port '53'
        option src '*'
        option dest '*'
    
    config rule
        option src 'lan'
        option name 'Disallow Google DNS from LAN'
        option family 'ipv4'
        option dest_ip '8.8.8.8'
        option target 'REJECT'
        option dest 'wan'
    
    config rule
        option src 'lan'
        option name 'Disallow Google DNS from LAN (2)'
        option dest 'wan'
        option family 'ipv4'
        option dest_ip '8.8.4.4'
        option target 'REJECT'
    
    config rule
        option src 'lan'
        option name 'Disallow Cloudflare DOH from LAN'
        option dest_ip '1.1.1.1'
        option dest_port '443'
        option target 'REJECT'
        option proto 'tcp'
        option family 'ipv4'
        option dest 'wan'
    
    config rule
        option src 'lan'
        option name 'Disallow Cloudflare DOH from LAN (2)'
        option proto 'tcp'
        option dest 'wan'
        option dest_ip '1.0.0.1'
        option dest_port '443'
        option family 'ipv4'
        option target 'REJECT'
    
    config rule
        option src 'lan'
        option name 'Disallow Cloudflare DOH from LAN (3)'
        option dest_ip '104.16.249.249'
        option family 'ipv4'
        option dest 'wan'
        option target 'REJECT'

Pretty much as basic as you'd think.

Router itself acts as a DNS-server via dnsmasq, and is allowed to do anything I decide I want.

On my network I have a pi-hole instance which then forwards queries to the router, so it also intercepts/looks up local LAN names correctly.

All clients on the network are provided the pi-hole as the canonical DNS-server to use via DHCP options.

Works for me.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#290

I replied sub-thread, but adding here to give some more visibility to some of the issues DoH is causing and will cause: I work at a k12 school and I am involved on many k12 IT communities. Some schools already removed Firefox from the students computers because it was being used as a "VPN" by some elementary students to access porn - at school. Guess what this VPN was? Just DNS over HTTPS. There is a fine line betwee…

> I replied sub-thread, but adding here to give some more visibility > to some of the issues DoH is causing and will cause: > > I work at a k12 school and I am involved on many k12 IT communities. > > Some schools already removed Firefox from the students computers > because it was being used as a "VPN" by some elementary students > to access porn - at school. Guess what this VPN was? Just DNS over HTTPS.

Firefox now has enterprise support where the administrator can force all desktops to use certain Firefox settings including enabling/disabling/configuring DoH.

See https://www.mozilla.org/en-US/firefox/enterprise/

And here's a link to details for configuration DNS over HTTPs. https://github.com/mozilla/policy-templates/blob/master/READ...

(I work at Mozilla)

Post reply on HN