Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

101–110 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#101
post #97
post #93

Earlier quoted context omitted.

This attitude always amazes me. You have obviously mastered a set of system administration skills over several years, and you are comfortable with a particular way of doing things. When somebody points out a weakness with the status quo and tries to offer something better, though, you react with hostility. Why do you think that is? I understand that their solution is not perfect (nothing ever starts out that way), bu…

I think the underlying issue is absolutely a power struggle. Until recently, the general understanding was that each network operator was responsible for the clients inside their network - and therefore also had the ability to set the network's configuration. In 99.99% of the cases, this included access to nonlocal sites on other, public network's, aka "the web", but this was nowhere technically required. Browsers an…

Wow, I had not considered the deeper power shifts from this perspective.

The root the problem, I suppose, lies with public-key cryptography. We all know encryption is a good thing (unless you want to broadcast private information to the world), but encryption is useless unless you know who you are talking to. When someone comes to you in a ski mask and says, "It's me, your best friend", you probably want to see their face before you tell them any secrets - they could be anybody.

Online, though, how do we know who anybody is? The current answer, for better or worse, is TLS with pay-to-play domain registration and certificate authorities. Decentralized, peer-to-peer systems like PGP have never been easy for consumers to use. You can "off-road" encrypted DNS by running your own DoH server & installing self-signed certificates on your client devices, but that's not an easy option.

"My LAN is my castle" may work for some cases, but most of us conduct business with people all over the world, thanks to the internet. This is the primary use-case for most networks & computer systems.

I'm afraid individuals will continue losing the power struggle as long as decentralized identity systems remain obscure. We need something that's as easy and compelling to use as our current centralized systems. It needs to be something consumers can use it to secure their every-day communications, as easy as visiting an HTTPS web site or chatting with a friend on Facebook. I just don't know how we get from here to there.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#102
post #78

Earlier quoted context omitted.

> Firefox decided to stop using my DNS server In an ideal world, your probably want some sort of encrypted connection to your own DNS server (unless your LAN is 100% trusted). Maybe something like HTTPS would work... oh wait. Most people don't have their own DNS server, so their DNS traffic is already who-knows-what server with who-knows-what monetization in place (plus its in plaintext, so the rest of the internet g…

And how the hell is split-horizon DNS supposed to work if resolve.conf is ignored? This may be "fine" for (some) home users, but most organizations have a whole bunch of internal-only records. And even a lot of residences have things like printers and such that live under .local: how is the browser supposed to connect to those? Who the fsck is Mozilla that they get to dictate policy in my IT organization about how DN…

It's amazing that you have such strong opinions about an article you didn't even bother to read.

First, they detect split horizon situations and explain how.

Second, if you as an admin want to force disable DoH across the network, they've provided a DNS-based way to do so.

Third, if this really bothers you, Mozilla provides GPO templates (and JSON based methods for other OSes) to configure all of these settings at an application level.

Maybe focus that outrage energy on reading the article before posting?

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#103

The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.

The article explicitly mentions the way to tell applications including Firefox not to disregard the OS DNS: blocking a canary domain. It even links to detailed instructions. Frankly, given how much trouble I've had with systemd's DNS meddling, I look forward to applications taking DNS under their own control.

Do you mean Network manager? AFAIK systemD does not meddle with dns.

And there's a rather short conf.d stub you can create that disables NM's meddling with resolv.conf.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#104
post #19

There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…

Not if one trusts more his/her ISP more than Cloudflare. At least, an ISP is a contractual partner and under the same jurisdiction, in Europe including GDPR.

Cloudflare would also be under GDPR as it serves customers in EU.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#107
post #91

What I still don't see addressed is the question how this will affect non-browser applications. It's nice that Firefox (currently) still offers options to turn off DoH and to keep using local domains. (although the way DoH and HTTPS-everywhere are structured show that non-internet sites don't seem to have much of a place in the web of the future) However, now that we have public DoH endpoints available for everyone t…

The same thing that stopped it before DoH was standardized: nothing.

There are ways to make FW rules based on trusted DNS lookups (i.e. you can only do traditional DNS to a trusted DNS server with domain filtering and you can only connect to an IP if a DNS lookup has been performed) but this is extremely hard to maintain in any sort of foolproof way.

The truth is if you allow outbound connectivity then there all the sender needs to do is add 1 more level of obfuscation than you secure against.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#108
post #71
post #67

Earlier quoted context omitted.

who will write the article about the weird world we live in, where the person who is mitm'ing the network connection is me, and it's the non-mitm'ed connection that is untrusted and worrying. at this point i expect to see talk of “the VPN”, a new network for hobbyists and academics, that's kinda like the old internet, and we only use devices that are wrapped in it.

Take a look at Privoxy. It's mostly useless now with everyone defaulting to HTTPS unless you install a root certificate on all your devices.

This is actually what I'm doing.

With some additional duct tape[1] I made privoxy work on https too. I run an instance for each host, though it could be possible to distribute a personal CA certificate.

[1]: https://maxwell.ydns.eu/git/rnhmjoj/privoxy-tls

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#109
post #97
post #93

Earlier quoted context omitted.

This attitude always amazes me. You have obviously mastered a set of system administration skills over several years, and you are comfortable with a particular way of doing things. When somebody points out a weakness with the status quo and tries to offer something better, though, you react with hostility. Why do you think that is? I understand that their solution is not perfect (nothing ever starts out that way), bu…

I think the underlying issue is absolutely a power struggle. Until recently, the general understanding was that each network operator was responsible for the clients inside their network - and therefore also had the ability to set the network's configuration. In 99.99% of the cases, this included access to nonlocal sites on other, public network's, aka "the web", but this was nowhere technically required. Browsers an…

Sorry, I don't understand why this is. Can you not just set up your own DoH server, or use your ISP's (perhaps automatically via DHCP)? How is that different from what happens now, except the traffic is now encrypted?

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#110
post #95
post #78

Earlier quoted context omitted.

> Firefox decided to stop using my DNS server In an ideal world, your probably want some sort of encrypted connection to your own DNS server (unless your LAN is 100% trusted). Maybe something like HTTPS would work... oh wait. Most people don't have their own DNS server, so their DNS traffic is already who-knows-what server with who-knows-what monetization in place (plus its in plaintext, so the rest of the internet g…

> Most people don't have their own DNS server, so their DNS traffic is already who-knows-what server with who-knows-what monetization in place (plus its in plaintext, so the rest of the internet gets it too). I know perfectly well who operates my DNS server: My ISP. If they are doing shady stuff, I can sue them, raise awareness or switch providers. I can't do the same with hardwired DoH endpoints.

It's easier to switch ISPs than it is to just configure FireFox to use some other DoH provider?
Post reply on HN