I hope we'll be given the opportunity to disable this, or at the very least show a warning (similar to cert warnings?) that something's off.
What’s Next in Making Encrypted DNS-over-HTTPS the Default
21–30 of 191 posts
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#22The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.
The article explicitly mentions the way to tell applications including Firefox not to disregard the OS DNS: blocking a canary domain. It even links to detailed instructions. Frankly, given how much trouble I've had with systemd's DNS meddling, I look forward to applications taking DNS under their own control.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#23There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#24At first, I was sceptical of DNS over HTTPS and thought that it gave Cloudflare, who already control too much access over the internet, even more control. However, other DNS providers are available. For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. [1] https://developers.google.com/speed/public-dns/docs/doh/ [2] https://www.quad9.net/doh-quad9-dns-servers/
> For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. Using Google is giving your browsing history to an Ad company, why? At least Quad9 is non-profit. It also provides DNS over TLS, DoT service, which I'm using.
Quad9 is a conglomorate of "Threat Intelligence Partners" and three founding organizations: IBM, Packet Clearing House and Global Cyber Alliance https://www.quad9.net/about/ . What's that third one? I don't know, but it's founded by The City of London Police, NY District Attorney and the Center for Internet Security https://www.globalcyberalliance.org/who-we-are/ that third one is like a hundred "Partners", with such privacy champions as The US Secret Service. Over 100 organizations. What are their incentives? What role do all these organization play and how much access do they have? Who knows.
Compare their privacy policies. They're strikingly similar because Quad9 largely lifted theirs from Google's (I'm assuming, since theirs came later)
https://developers.google.com/speed/public-dns/privacy
Google's policy states they collect private information for 24-48 hours, keep "anonymized" information for 2 weeks and then randomly samples that data for permanent storage:
> Google Public DNS stores two sets of logs: temporary and permanent. The temporary logs store the full IP address of the machine you're using. We have to do this so that we can spot potentially bad things like DDoS attacks and so we can fix problems, such as particular domains not showing up for specific users.
> We delete these temporary logs within 24 to 48 hours.
> In the permanent logs, we don't keep personally identifiable information or IP information. We do keep some location information (at the city/metro level) so that we can conduct debugging, analyze abuse phenomena. After keeping this data for two weeks, we randomly sample a small subset for permanent storage.
Quad9 collects effectively the same information (except AS) as Google's 2 week logs and says
> All the above data may be kept in full or partial form in permanent archives.
If you want a game theoretic, capitalist analysis, Google has an incentive to keep the web running and keeping it an awesome platform, to make sure humanity's information is created and shared in an open format that they know how to index and that they can freely index, instead of apps or some alternative web or some other walled garden.
But we're bombarded daily with "goog bad" by politicians and journalists, so Google must obviously be just brazenly lying and you should give your DNS history to an organization founded by The City of London Police instead that "share anonymized data on specific domains queried [...] with its threat intelligence partners".
Please double check my work, I didn't read the privacy policies too carefully (I think notably Google stores the AS number and Quad9 doesn't) because I don't actually care, I (along with roughly 100% of internet users) just give all my DNS history in plain text to my ISP.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#25The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.
The article explicitly mentions the way to tell applications including Firefox not to disregard the OS DNS: blocking a canary domain. It even links to detailed instructions. Frankly, given how much trouble I've had with systemd's DNS meddling, I look forward to applications taking DNS under their own control.
And how long will it take for most ISPs to block this domain when they realize that their DNS servers are not being used anymore? Some of them sell this data so they see it as a source of revenue.
At this point this canary domain will have the same fate as Do Not Track.
> I look forward to applications taking DNS under their own control.
I am sure I can find a hundred applications/programs resolving domains on my machine. It is unrealistic to configure all of them separately. At this point we are back to the OS providing the configuration for all of them.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#26What is the latency for DoH compared to traditional UDP DNS?
They test various network conditions with some results showing DoH and DoT loading webpages faster than udp dns (due to tcp timing out faster than udp on lossy connections )
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#27Unfortunately, Mozilla are planning to leave DoH off by default for Firefox users in the UK. Almost certainly to avoid criticism from politicians and children’s charities about how DoH would interfere with the UK’s network level website blocking of ‘adult’ websites.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#28Earlier quoted context omitted.
> For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. Using Google is giving your browsing history to an Ad company, why? At least Quad9 is non-profit. It also provides DNS over TLS, DoT service, which I'm using.
Because with Google you only have to trust one organization that flat out says in the FAQ that they do not "correlate or combine information from temporary or permanent logs with any personal information that [you] have provided Google for other services". Quad9 is a conglomorate of "Threat Intelligence Partners" and three founding organizations: IBM, Packet Clearing House and Global Cyber Alliance https://www.quad9.…
And I wouldn't spend much time analysing policies, they are all "we pinky swear". Its is there a business incentive in using my data or not.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#29At first, I was sceptical of DNS over HTTPS and thought that it gave Cloudflare, who already control too much access over the internet, even more control. However, other DNS providers are available. For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. [1] https://developers.google.com/speed/public-dns/docs/doh/ [2] https://www.quad9.net/doh-quad9-dns-servers/
So it’s clearly an upgrade for Google.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#30Earlier quoted context omitted.
Because with Google you only have to trust one organization that flat out says in the FAQ that they do not "correlate or combine information from temporary or permanent logs with any personal information that [you] have provided Google for other services". Quad9 is a conglomorate of "Threat Intelligence Partners" and three founding organizations: IBM, Packet Clearing House and Global Cyber Alliance https://www.quad9.…
My history goes mostly to my carefully chosen, overseas VPN provider. Yes, there are no good choices, best you can do is to split your data between several parties, so its hard to correlate. Google has data on most people on the planet, unlike London Police, so giving Google your data is way more dangerous than other parties combined. And user data is Google primary business model. And I wouldn't spend much time anal…
Anything else like a "VPN" (which is really just a proxy under a cooler name) is somewhere between a half measure, a snake oil hobby or self-sabotage (if you picked the wrong VPN).
You don't trust a large multi national that works on encryption and tries to deny frivolous law enforcement requests when it outright says it samples a small amount of "anonymized" data and doesn't correlate it with anything else it has on you or sell it
>> Is any of the information collected stored with my Google account?
> No.
>> Does Google share the information it collects from the Google Public DNS service with anyone outside Google?
> No, except in the limited circumstances described in Google's privacy policy, such as legal processes and enforceable governmental requests. (See also Google's Transparency Report on user data requests.)
>> Does Google correlate or combine information from temporary or permanent logs with any personal information that I have provided Google for other services?
> No.
https://developers.google.com/speed/public-dns/faq
yet trust some small, anonymous group of people that set up a proxy that's netting them like $5/month of revenue per user in a highly competitive market?
> [policies] are all "we pinky swear"
Are they not legally binding? But yea, like I said, obviously they're just brazenly lying because of course they are. "goog bad" has been established. I'm not sure how or where... but everyone knows that.
Better be safe and give your data to an organization that lists the US Secret Service as a "Partner".