Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

11–20 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#11
post #5

I didn't see it mentioned in the article. Has Mozilla said whose servers they will be sending unsuspecting users queries to by default? (IIRC, it was Cloudflare previously. Any reason to believe this has changed?) --- If, like me, you already have a solution in place you are happy with and don't like the idea of others (deciding they know what's best for you and) circumventing it, simply ensure that your existing res…

If true that DoH can be disabled at network level, ad-blocking solutions like pihole should probably implement it by default.

Anyone have any idea if this is the case?

That would at least save me a lot of trouble and work.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#15

The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.

The article explicitly mentions the way to tell applications including Firefox not to disregard the OS DNS: blocking a canary domain. It even links to detailed instructions.

Frankly, given how much trouble I've had with systemd's DNS meddling, I look forward to applications taking DNS under their own control.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#16

The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.

Mozilla can only speak for their applications and they seem to eventually intend Firefox to use DoH as default and fallback to OS DNS under various failure conditions some of which are mentioned in the post. They also say:

"When DoH is enabled, users will be notified and given the opportunity to opt out."

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#18

So what will be « safer » ? Using a pi-hole or equivalent, or using this ? IIRC all DoH requests are sent to Cloudflare. Is there a way to host your own DNS server and use it with DoH instead ?

For now I'm blocking traffic to Google's and cloudflare's DNS and plan on also following the advice about that special domain from https://support.mozilla.org/en-US/kb/configuring-networks-di... that someone posted here.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#19
There's a lot of negativity here.

But this is a win overall for privacy.

DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do.

If you're technical enough to understand DNS then you are smart enough to change what the default is.

If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you want.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#20
Unfortunately, Mozilla are planning to leave DoH off by default for Firefox users in the UK. Almost certainly to avoid criticism from politicians and children’s charities about how DoH would interfere with the UK’s network level website blocking of ‘adult’ websites.
Post reply on HN