Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

11–20 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#12
post #6

In many economies, ISPs have legal immunity from acts done by users (customers) because of laws associated with 'common carrier' status. But that status is fragile. The ISP has to act like it knows its obligations in law, and there are things ISPs have been doing to work with LEA for a long long time, which they won't be able to do as simply, or as well, or in some cases at all. As a customer its easy to assume the o…

DoH and DoT are just new delivery technologies. You've always been able to securely tunnel your traffic out of the country and you always will as it's trivial. DoT changing the resolver from one public company in the to another public company of the will not prevent the government from issuing warrants, particularly since they already issue warrants to these companies as it is.

Common carrier defence is not going to be lost from encrypting URLs, the same FUD was spread about encrypted banking then the encryption of most websites. The only thing that has resulted from the increase in encryption is the decrease of ISP injected ads and the decrease of customer tracking information being sold.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#14

From Google's perspective being able to block ads with your hosts file is a bug, not a feature.

I agree with this perspective, it doesn’t make any difference on computers, but embedded devices and applications now have the ability to bypass DNS restrictions such as the pihole.

Personally, I would have liked to see strong privacy laws fill the gap, but it looks like DoH is here to stay now.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#15
While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#17
post #13
post #4

Death to big ISPs.

Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.

If I get the choice between finding a different way to do DNS based ad blocking and hiding my traffic from ISPs' advertising divisions, I will happily find a new PiHole alternative.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#19
post #13
post #4

Death to big ISPs.

Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.

What’s stopping your PiHole or DMS adblocker from functioning as a MITM proxy? You’d just terminate HTTPS at the PiHole and perform the filtering there, right?

Regardless, it’s a tiny thing to give up for more privacy.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#20
post #6

In many economies, ISPs have legal immunity from acts done by users (customers) because of laws associated with 'common carrier' status. But that status is fragile. The ISP has to act like it knows its obligations in law, and there are things ISPs have been doing to work with LEA for a long long time, which they won't be able to do as simply, or as well, or in some cases at all. As a customer its easy to assume the o…

> The ISP has to act like it knows its obligations in law, and there are things ISPs have been doing to work with LEA for a long long time, which they won't be able to do as simply, or as well, or in some cases at all.

As I understand the current caselaw, whilst an ISP is required to make some efforts, they are not required to make efforts when a task is impossible or difficult.

If an ISP is required to create a porn filter, for example, they aren't also required to try and forward that blocker across Tor.

Rather a "best effort" is exactly what is legally required.

So when a new technology is adopted that makes their previous "best efforts" obsolete, then they will no longer be forced to attempt something that is no longer possible.

However, that whole conversation is mute when it comes to this particular instance.

Google will attempt to use the ISP's own DoH resolver. So the answer is simply to run one, or not. If Chrome can't find a DoH with the current DNS, it'll fallback to today's behaviour. This isn't changing the status quo at all.

It's only a problem if customers move wide-scale away from the ISP's own DNS servers. Which happens when the ISP's interests conflict with the user's already, so again, no change to the status quo.

Post reply on HN