Live data from Hacker News

Measuring open DNS resolver use

blog.apnic.net

41–50 of 53 posts

Re: Measuring open DNS resolver use

#41
post #39
post #38

Earlier quoted context omitted.

Alright, but the reason for the complaint about centralization you're dismissing is that most people are encountering DoH via Firefox's plan to default resolve via DoH to Cloudflare, rather than in the context of being deft Unix hands searching for a way to tunnel their DNS out of an untrustworthy network.

I do not think a feature that delegates DNS to Cloud Flare is an unalloyed good. I think the protocol is. The distinction is important.

Oh. Well, I lean to the view that X-over-HTTP is often a bad model; partly because HTTP has been heavily-commercialized.

I can see that there are problems with DNS; there always have been, and it's always been obvious. But for now, I think I prefer running my own resolver. Unbound is really easy to set up.

Re: Measuring open DNS resolver use

#42
post #40
post #33

Earlier quoted context omitted.

I can't think of anything bad about it. One popular strain of criticism is clearly bogus, that it removes a measure of visibility from network operators (that's the point). Another is that it centralizes DNS services at companies like Cloud Flare, which, no, you can run your own DoH resolver server (and probably shouldn't use Cloud Flare regardless). Finally, people say that it's clunky compared to datagram-based alt…

Serious question - why do you prefer DoH vs say, DNS over TLS? The former always seemed rather hacky to me.

I don't think there's anything wrong with DoT, but DoH is deliberately more difficult to block, which is a sensible design goal for a privacy and anti-censorship protocol. Both are better than directly using legacy plaintext DNS.

Re: Measuring open DNS resolver use

#43
post #39

Earlier quoted context omitted.

I do not think a feature that delegates DNS to Cloud Flare is an unalloyed good. I think the protocol is. The distinction is important.

Oh. Well, I lean to the view that X-over-HTTP is often a bad model; partly because HTTP has been heavily-commercialized. I can see that there are problems with DNS; there always have been, and it's always been obvious. But for now, I think I prefer running my own resolver. Unbound is really easy to set up.

I'm not seeing how unbound solves the problem of your network provider spying on and recording all your DNS lookups.

Re: Measuring open DNS resolver use

#44
post #43

Earlier quoted context omitted.

Oh. Well, I lean to the view that X-over-HTTP is often a bad model; partly because HTTP has been heavily-commercialized. I can see that there are problems with DNS; there always have been, and it's always been obvious. But for now, I think I prefer running my own resolver. Unbound is really easy to set up.

I'm not seeing how unbound solves the problem of your network provider spying on and recording all your DNS lookups.

Unbound does support DoT.

Re: Measuring open DNS resolver use

#45
post #44
post #43

Earlier quoted context omitted.

I'm not seeing how unbound solves the problem of your network provider spying on and recording all your DNS lookups.

Unbound does support DoT.

Sure, but you're not speaking DoT to the authority servers. DoH and DoT aren't magic security dust; they're just a means of tunneling requests from an untrusted network to a more trusted network. If you run your own recursive resolver locally, DoT is mostly theater.

Re: Measuring open DNS resolver use

#46
post #27

Earlier quoted context omitted.

DNSSEC doesn't "essentially escrow keys with governments". It's exactly as true to say that DANE gave Gaddafi ownership of bit.ly's CA as to say that today Boris Johnson owns the CA for slither.io - and as ridiculous. Back when you first started claiming this the Ten Blessed Methods weren't even a thing. You're complaining about the inadequate back door lock on a house that has the front door propped open. I work for…

You haven't offered a rebuttal other than saying this argument is "ridiculous". I'm obviously not coming out of nowhere with it. Can you do better than "nuh-uh"?

If you don't agree that it's ridiculous to say Boris Johnson controls the CA for slither.io then... I guess we just have a very different definition of what it means to be ridiculous.

I can live with that.

Re: Measuring open DNS resolver use

#47
post #37
post #36

Earlier quoted context omitted.

At the point when I would be "run[ning] my own DoH resolver", I'm already at the point of setting up my own resolver. Why wouldn't I just turn on unbound and call it a day?

The point of running your own DoH resolver is that you're doing it somewhere off-network, to tunnel DNS out of an ISP network you don't trust to somewhere else you trust more. You can also just not run DoH if you trust your network. I'm saying DoH is a good thing, not that everyone has to use it.

Your ISP knows where you go without looking at your DNS. Because after you do the lookup you go there.

Re: Measuring open DNS resolver use

#48

Earlier quoted context omitted.

What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.

It makes it very hard to control your network. I have a DNS setup at home that I want all my equipment using. It blocks ads and other sites I don't want accessed. With DoH, I can't really be sure that browsers, devices, etc aren't using an alternative DNS system.

But the plain DNS makes you absolutely unable to control your DNS queries outside your network.

Nothing stops anyone in the middle intercepting your queries and returning whatever they want, including your provider.

Re: Measuring open DNS resolver use

#49
post #27

Earlier quoted context omitted.

You haven't offered a rebuttal other than saying this argument is "ridiculous". I'm obviously not coming out of nowhere with it. Can you do better than "nuh-uh"?

If you don't agree that it's ridiculous to say Boris Johnson controls the CA for slither.io then... I guess we just have a very different definition of what it means to be ridiculous. I can live with that.

If my iPhone honored my passphrase, but also a second secret passphrase held by Apple in iCloud that I had no control over, what would you call that scheme? I would say that Apple had an escrowed passphrase. Well, that's precisely how DNSSEC works. I control my own key, sure, and never have to reveal it, but that doesn't matter, because the roots can simply override that key with their own.

You keep making these emotional appeals, but if I'm wrong, I don't see you actually rebutting me. "Your argument is so bad I will not deign to engage with it" is not a rebuttal.

Re: Measuring open DNS resolver use

#50
post #49

Earlier quoted context omitted.

If you don't agree that it's ridiculous to say Boris Johnson controls the CA for slither.io then... I guess we just have a very different definition of what it means to be ridiculous. I can live with that.

If my iPhone honored my passphrase, but also a second secret passphrase held by Apple in iCloud that I had no control over, what would you call that scheme? I would say that Apple had an escrowed passphrase. Well, that's precisely how DNSSEC works. I control my own key, sure, and never have to reveal it, but that doesn't matter, because the roots can simply override that key with their own. You keep making these emot…

At the risk of wasting my time with Humpty Dumpty:

OK, so first up I guess the problem is you've no idea what "escrow" is and so you ended up confused as to what key escrow could be. So let's fix that first.

Escrow is a service people or companies offer, the idea goes like this. Alice wants to do a deal with Bob, and Bob wants to make a deal with Alice, they're going to swap some of Alice's baseball cards for Bob's antique vase, but they don't trust each other. Fortunately they both trust Trent, a Third Party. Trent offers an Escrow service, both Alice and Bob agree with Trent that the baseball cards and the antique vase go to Trent, and then when he's got both things he'll send them to their new owners. If anything goes wrong, Trent gives back anything he received to the person who sent it and the deal is off.

In the tech industry the most likely set up you'll see is that investors are worried all the stuff they're spending a lot of money on at a startup is not material that a bunch of burly guys can pick up and put in a truck if the firm fails - instead it's in Git repos or Google Drives and if it falls apart they know it has residual value that could be realised but they're not technical people, they're money people. So an escrow firm says fine, pay us a bunch of money and make the startup sign this data escrow agreement, and then if they fail you activate this clause and we give you a bunch of USB drives full of source code and whatever else. The escrow firm has IT people who can do stuff like send over keys for access to a GitHub, who know the difference between an S3 bucket and a SD card, which the investors don't want to have to learn about.

In key escrow _your_ keys are held by a third party on your behalf. You can do end-to-end encryption if you want, but you're obliged to use this escrowed key. If the third party releases the key (e.g. because of a warrant, or an NSL, or because they're corrupt) then whoever gets it can now decrypt everything you've sent, or impersonate you seamlessly.

If your iPhone honors a secret Apple passphrase that's a _backdoor_. If instead Apple insists on keeping a copy of your passphrase in a safe at Apple HQ that Tim Cook promises not to open _that_ would be escrow.

Your objection that in DNSSEC "the roots can simply override that key with their own" also applies to any PKI, the whole _point_ of a PKI is that the trusted third party binds identity to keys, and if trust is misplaced they might falsely bind an identity to the wrong key. So the problem is - as I illustrated - that objections on the basis of DNSSEC being a PKI work just as well against the Web PKI. As a reason to prefer the Web PKI over DNSSEC they're ineffective.

Post reply on HN