This misses the forest for the trees. In the UK ISPs are already legally mandated to log your web requests and provide them to the government. Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications. The fact that cloudflare is a US entity and thus not subject to UK law is the whole point.
Turn off DoH, Firefox
81–90 of 422 posts
Re: Turn off DoH, Firefox
#82Earlier quoted context omitted.
> the article deliberately buries that it's trivial to change your DoH provider While true for you or me, the vast majority of people will have this enabled by default - probably not even realising it's on
And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?
Re: Turn off DoH, Firefox
#83There are two points: 1. centralization of all dns lookups is worrisome 2. Dns should not be handled by applications. It should be handled by the operating system. I see a lot of people conflating the two in the comments.
> 2. Dns should not be handled by applications. It should be handled by the operating system. I agree with #1 but why it should be managed by the OS?
Example: Say you use hosts file to block porn and other shady sites for your kid, all they have to do is use chrome.
Re: Turn off DoH, Firefox
#84This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
Like I've asked before, should Mozilla also start including an obfuscating VPN by default, to bypass the Chinese firewall?
This is a political issue, and one that I don't think Mozilla should even get involved in because it could have very ugly consequences --- just focus on making a good browser and leave the politics (and VPN/firewall-busters) to others.
Re: Turn off DoH, Firefox
#85* https://www.proofpoint.com/us/threat-insight/post/psixbot-no...
Re: Turn off DoH, Firefox
#86Earlier quoted context omitted.
It seems very American to me to trust a private actor such as CouldFlare more than your own government. I feel like at least in Europe, a large majority of people would trust their government and local ISP much more than some company halfway over the world with basically no accountancy in your own country, especially an American one since it means your data is basically at the mercy of the US government.
Aren't there a bunch of European ISPs applying government enforced DNS blocking? Seems like this is a very good move for them.
I still trust my DNS servers (or those of most ISPs, for that matter) more than I trust Cloudflare. I'd rather have intelligence services go through the effort of infiltrating every single ISP separately to get any useful dragnet intelligence, instead of just one large entity that can illegally collect all traffic from all users of a web browser.
Re: Turn off DoH, Firefox
#87This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services Not true. ISPs typically record and store netflow-like data, very rarely DNS-data (I'd say storing DNS data is even unusual). If ISPs are in a position to get more detailed than netflow data on you they resort to things like deep packet inspection (DPI), which doesn't rely on DNS,…
Re: Turn off DoH, Firefox
#88If the single DoH 'server' is the issue, wouldn't having a list of several 'servers' around the globe (hopefully in places where there isn't any form of censorship and preferably though non-commercial institutions) that the browser selects randomly solve this?
How the operating system resolves names, is up to it. It could use tcp-over-pigeons, if the sysadmin configured it so, and no application should be working around that.
If you want to use DoH with Cloudflare, you are free to configure your system to do so. You will also get consistency, all your apps will use the same system, not just the browser. Let the others to have their systems configured as it suits them.
Re: Turn off DoH, Firefox
#89This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
So far I'm using NextDns.io at home, which is DoH and also applies ad-filtering. I haven't heard of any security concerns yet Disclaimer: I do not work or have any financial connection to that service