Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

71–80 of 422 posts

Re: Turn off DoH, Firefox

#71
post #55

I strongly support DoH as it prevents government snooping on the public. It’s really unhelpful that people like this attack Firefox over this issue. Stand strong Firefox against this.

One goes fishing where the fish is. There are dozens of large and hundreds of medium to small ISPs in the US. There's only one Cloudflare. That's where the resources to get the data would be concentrated. It has been demonstrated with PRISM.

If Mozilla wants to play this game, it really should make DoH a visible top level choice for a user.

Re: Turn off DoH, Firefox

#72

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

> the article deliberately buries that it's trivial to change your DoH provider While true for you or me, the vast majority of people will have this enabled by default - probably not even realising it's on

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

Re: Turn off DoH, Firefox

#73
post #20

Earlier quoted context omitted.

> I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! I trust my ISP and government more than a US company I have no formal contract with and the US government. Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Fi…

> I trust my ISP and government more than a US company I have no formal contract with and the US government. You're not affected then, because the DoH rollout w/ Cloudflare as the default is only planned for the US.

For now

Re: Turn off DoH, Firefox

#74
post #61
post #49

Earlier quoted context omitted.

> I don't think anyone believes CF will start selling data, that's not what the article argues. > Regardless, it's opt-out not opt-in. Which is against newer consumer protection laws such as GDPR. I understand the argument in theory.. but the reality is CF is a more trustworthy DNS provider than basically any consumer ISP in the EU.

This is where me and the author disagree with you. In most places in Europe there is a complete distrust of US companies and hosting anything on US soil. Historically we've seen many cases of US companies handing over data to US authorities (willingly or not).

And practically, US companies are not restricted from selling of user data to third parties, while EU companies are.

Re: Turn off DoH, Firefox

#75
post #13
post #9

Earlier quoted context omitted.

I do trust my ISP and my government more than I trust CloudFlare.

Is your ISP in the US and your government the US government? The DoH rollout w/ Cloudflare is only planned for the US.

> The DoH rollout w/ Cloudflare is only planned for the US.

For now.

Re: Turn off DoH, Firefox

#76
post #58

There are two points: 1. centralization of all dns lookups is worrisome 2. Dns should not be handled by applications. It should be handled by the operating system. I see a lot of people conflating the two in the comments.

> 2. Dns should not be handled by applications. It should be handled by the operating system. I agree with #1 but why it should be managed by the OS?

Because the OS gets provisioned with DNS by DHCP. Because the OS incorporates the hosts file. Any internal domains or local domain edits are not covered by this.

Re: Turn off DoH, Firefox

#77
post #42
post #23

This misses the forest for the trees. In the UK ISPs are already legally mandated to log your web requests and provide them to the government. Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications. The fact that cloudflare is a US entity and thus not subject to UK law is the whole point.

As far as I understood the OP is that it shouldn't be the default. If you worry for your government, you should use a VPN anyway (where possible which is the case for UK afaik).

Why shouldn't it be the default? Switzerland has a population 8 million. Why should the default be geared towards a small minority when there are billions of people not just in the UK but in Asia and Africa who would benefit from this feature. If they OP thinks that their country's laws are strong enough to make the feature unnecessary then they can turn it off.

Re: Turn off DoH, Firefox

#78
post #16

It seems like this change by Firefox would bypass a pi-hole. Am I understanding it correctly?

...and a local HOSTS file. So now it will, by default, contact all the ad/tracking hosts that you configured to be blocked. "But now your DNS queries to those ad/tracking hosts are encrypted!" No. I don't care. I didn't want to connect to those hosts in the first place.

Even worse, corporate intranet addresses get leaked.

Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.

Re: Turn off DoH, Firefox

#79

Earlier quoted context omitted.

ISPs have proven themselves untrustworthy repeatedly, CloudFlare yet really hasn't. Not that I like the control they have, but it's honestly the fault of ISP's this has happened.

some ISPs. The problem is that Mozilla is taking a very US-centric view of a product that is used worldwide.

…and DNS over HTTPS, using CloudFlare, is only being enabled in the US. A US-centric view for a US-only decision seems fair to me?

Re: Turn off DoH, Firefox

#80

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services

Not true. ISPs typically record and store netflow-like data, very rarely DNS-data (I'd say storing DNS data is even unusual). If ISPs are in a position to get more detailed than netflow data on you they resort to things like deep packet inspection (DPI), which doesn't rely on DNS, pretty much all mobile/cellular ISPs do that today.

> DoH is vital to protect users around the world from censorship and worse.

Not true either. DoH can't do anything against censorship and if enabled by default in all browsers can actually give worldwide censorship powers to a single US entity that already has something akin "we will block anything we don't like and do anything our government wants" in their ToS.

Post reply on HN