Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

31–40 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#31
Why don't they rather include a resolver in Firefox ?

This way, no privacy problems, you're directly contacting authoritarive servers. And you don't rely on a single dns-over-https provider.

Is the latency a big problem there? I would say that with caching it is not too bad.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#32
post #19

There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…

Well, DoH effectively bypass DNS-filters set up by countries. While some are questionable, I believe it won't take long until Mozilla ends up with some bad press, and being an underdog it doesn't need that.

To me that is good press, and it's something I personally would like. Seeing a state and/or adjunct corporations throwing a tantrum over this is only a measure of success.

After all privacy is the goal, isn't it?

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#33
post #31

Why don't they rather include a resolver in Firefox ? This way, no privacy problems, you're directly contacting authoritarive servers. And you don't rely on a single dns-over-https provider. Is the latency a big problem there? I would say that with caching it is not too bad.

[deleted]

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#34
post #19

There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…

Well, DoH effectively bypass DNS-filters set up by countries. While some are questionable, I believe it won't take long until Mozilla ends up with some bad press, and being an underdog it doesn't need that.

In other words, Mozilla shouldn't do something good for its users because it could bring bad press.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#35
post #5

I didn't see it mentioned in the article. Has Mozilla said whose servers they will be sending unsuspecting users queries to by default? (IIRC, it was Cloudflare previously. Any reason to believe this has changed?) --- If, like me, you already have a solution in place you are happy with and don't like the idea of others (deciding they know what's best for you and) circumventing it, simply ensure that your existing res…

If true that DoH can be disabled at network level, ad-blocking solutions like pihole should probably implement it by default. Anyone have any idea if this is the case? That would at least save me a lot of trouble and work.

Pihole is great because it can do all your non-browser activity.

But for a browser, an ad-blocking extension works better and is less than a minute to set up. Why force it to use the same DNS blocking?

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#38
post #31

Why don't they rather include a resolver in Firefox ? This way, no privacy problems, you're directly contacting authoritarive servers. And you don't rely on a single dns-over-https provider. Is the latency a big problem there? I would say that with caching it is not too bad.

A local resolver using root hints and DNS-over-TLS would be a win for privacy and, at the same time, would not promote centralization of the Internet to DNS-over-HTTPS providers. It still suffers from the problem of overriding local network policy but it's better than just handing all the queries over to a single DoH provider.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#39
post #19

There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…

Not if one trusts more his/her ISP more than Cloudflare. At least, an ISP is a contractual partner and under the same jurisdiction, in Europe including GDPR.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#40
post #5

I didn't see it mentioned in the article. Has Mozilla said whose servers they will be sending unsuspecting users queries to by default? (IIRC, it was Cloudflare previously. Any reason to believe this has changed?) --- If, like me, you already have a solution in place you are happy with and don't like the idea of others (deciding they know what's best for you and) circumventing it, simply ensure that your existing res…

If true that DoH can be disabled at network level, ad-blocking solutions like pihole should probably implement it by default. Anyone have any idea if this is the case? That would at least save me a lot of trouble and work.

Already proposed: https://discourse.pi-hole.net/t/support-for-returning-nxdoma...
Post reply on HN