Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

61–70 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#61

Earlier quoted context omitted.

Not if one trusts more his/her ISP more than Cloudflare. At least, an ISP is a contractual partner and under the same jurisdiction, in Europe including GDPR.

Being in the same jurisdiction is bad: your ISP is THE place for your local law enforcement to get info on your browsing.

Yes. However with Cloudflare, now everyone would effectively be under the jurisdiction of the US which is not necessarily better.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#62
post #45
post #7

Earlier quoted context omitted.

That's exactly what their plan is -- and if you have experiments enabled, they may have already started sending your DNS queries to Cloudflare.

I guess thats Mozillas new monetizing strategy, sell user data to cloudflare, and market it as privacy. If you want privacy you better firewall everything your computer want to send to Cloudflare, Akamai, et.al.

>...sell user data to cloudflare...

Cloudflare claims they "will never sell your data or use it to target ads."

You can read their 1.1.1.1 privacy policies here:

https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...

https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#63
post #41

Earlier quoted context omitted.

1. The connection to the authoritative servers isn't encrypted, so the whole point of DoH is undermined. 2. There's plenty of networks that don't let arbitrary DNS traffic out, so this doesn't work without another fallbacks. Fallbacks for security features are bad. I see that there are legit controversies around DoH. But these "Why don't you just do X?" comments aren't helpful. Try to understand the problem they're t…

I disagree that the OP's comment isn't helpful. Mozilla could have taken a tack that would have increased decentralization and promoted privacy (DNS-over-TLS exists). Instead, they went the way of a centralized protocol that just trades one set of potentially bad actors (ISPs) for another. re: network policy - If you're paying to use a network with policy that you disagree with vote w/ your wallet. If you're using so…

I’d love to use DoT, but afaik it’s currently mostly only supported by DNS resolvers (Google, CloudFlare and other privacy-exploiting companies) rather than authoritative DNS servers.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#64
post #31

Why don't they rather include a resolver in Firefox ? This way, no privacy problems, you're directly contacting authoritarive servers. And you don't rely on a single dns-over-https provider. Is the latency a big problem there? I would say that with caching it is not too bad.

Besides what the other commenters have said, it also just seems like a bad idea to add 170 million extra recursive resolvers, I don't know how well the dns infrastructure would cope with that extra amount of traffic.

Each of which individually generates really limited traffic?

Besides, the number of domains and relatively short TTLs mean that even the big resolvers will not have most requests cached except for the most popular domains.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#65

I am wondering, does DNS-over-HTTPS really helps since the way I understand it, after the domain name is resolved to an IP address, the client contacts the IP address so the ISP could still know the website visited especially since many if not most websites have dedicated IP addresses. So ISP could simply crawl the web and map domain names to IP addresses. Is there anything in DoH mitigating this? Or maybe is this at…

DoH definitely doesn't mitigate against your upstream provider doing traffic inspection and siphoning the IPs your network is connecting to. Ultimately, they have to route your IP packets, so they'll always have that visibility.

But this 1) adds a technical hurdle, 2) reduces accuracy of the data captured, and 3) adds a potential legal barrier, as the data is not theirs anymore

(before ISPs could claim that the use of their DNS gave them right to use the data collected)

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#66

I am wondering, does DNS-over-HTTPS really helps since the way I understand it, after the domain name is resolved to an IP address, the client contacts the IP address so the ISP could still know the website visited especially since many if not most websites have dedicated IP addresses. So ISP could simply crawl the web and map domain names to IP addresses. Is there anything in DoH mitigating this? Or maybe is this at…

Yes, ISPs can know IP addresses and map domains to IP addresses, they can also know exact SNI names, all kinds of passive TCP-level information about your communications, can do active probing for all kinds of information on behalf of you, can use all that together to build a much more detailed profile of you, than available through DNS queries. There is an entire industry of commercial DPI solutions to do that. On top of that ISPs can always block DoH and force fallback to their own DNS servers. So, a minimum amount of privacy can only be achieved with a VPN (or a proxy), not DoH, DoH just leaks to and centralizes data on third parties, violating privacy, making it easier for state actors to spy on people, things like that, it might even give governments capabilities to do world wide censorship if all major browsers implement it. Mozilla, Cloudflare and everyone else involved are being very dishonest when it comes to DoH.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#67
post #55
post #52

Earlier quoted context omitted.

Or if you run your own resolver and don't want a completely unrelated third party like Cloudflare siphoning your traffic.

This. And I already have to deal with smart appliances that try to contact their own DNS (I’m looking at you, Samsung) and that break if I force their requests through my own resolver. This will just allow all applications and appliances to bypass my privacy measures.

who will write the article about the weird world we live in, where the person who is mitm'ing the network connection is me, and it's the non-mitm'ed connection that is untrusted and worrying.

at this point i expect to see talk of “the VPN”, a new network for hobbyists and academics, that's kinda like the old internet, and we only use devices that are wrapped in it.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#68
post #45

Earlier quoted context omitted.

I guess thats Mozillas new monetizing strategy, sell user data to cloudflare, and market it as privacy. If you want privacy you better firewall everything your computer want to send to Cloudflare, Akamai, et.al.

>...sell user data to cloudflare... Cloudflare claims they "will never sell your data or use it to target ads." You can read their 1.1.1.1 privacy policies here: https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...

That does not say they cannot use it for other purposes.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#69
post #19

There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…

> But this is a win overall for privacy.

> DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do.

It's not a win for privacy, ISPs will still have that data and now third parties will have that data, state actors will have that data in a nice convenient centralized locations, governments will have an ability to force those centralized providers to do censorship for them. As for oppressive regimes - they don't care about DNS data, if they want to spy on people, they will one way or another.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#70

I am wondering, does DNS-over-HTTPS really helps since the way I understand it, after the domain name is resolved to an IP address, the client contacts the IP address so the ISP could still know the website visited especially since many if not most websites have dedicated IP addresses. So ISP could simply crawl the web and map domain names to IP addresses. Is there anything in DoH mitigating this? Or maybe is this at…

SNI allows hosting multiple SSL Certificates on one IP, but is itself a privacy problem, because https requests have the domain in plain text.

ESNI can solve this, by encrypting the SNI header while still allowing serving multiple https domains on one IP. But it’s currently mainly implemented by cloudflare.

Post reply on HN