Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

31–40 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#31

I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…

If you're on a mainstream US ISP, interference from your browser with your ISP's "network level operations" is a privacy necessity. They're passively monitoring DNS to collect data on their customers and hijacking it to send users to advertising sites. ISP DNS is manifestly untrustworthy.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#32
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

Actually everyone should prefer the other guy do it rather than host it themselves. Either way the bits have to be transported to the same colocated facilities it's a matter of who has to pay for and operate the servers.

At least Cloudflare has KPMG audit them on their privacy claims. Better than nothing.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#33
post #30
post #19

Earlier quoted context omitted.

What’s stopping your PiHole or DMS adblocker from functioning as a MITM proxy? You’d just terminate HTTPS at the PiHole and perform the filtering there, right? Regardless, it’s a tiny thing to give up for more privacy.

Ah yes, Google and CloudFlare, those well-known bastions of privacy.

I hate to respond to low-effort snark but will do so here to remind people that Google's plan doesn't default you to Google's servers, will honor your own nameservers, and will upgrade you to DoH if any of those servers support it. It's really hard to see what more you could ask for.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#34
post #5

From Google's perspective being able to block ads with your hosts file is a bug, not a feature.

Ads are a much smaller threat than unscrupulous ISPs. They have access to ALL your traffic.

Only the unencrypted traffic, which is increasingly becoming just DNS. But even if all DNS was encrypted, the default DNS servers you hit are those of your ISP so they’d still have access in the common/default case

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#35
post #13

Earlier quoted context omitted.

Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.

Completely untrue. Those services just need to serve their own DoH endpoint and the user can add it in Firefox preferences. No harder than and arguably easier than the complicated procedure for changing system DNS, and it allows you to block things in your browser that you may not want blocked at the system level for all users.

If your PiHole servers a DoH endpoint, you're probably back to exposing plaintext DNS to your ISP. The whole point of DoH is to tunnel DNS out of your untrusted ISP network to anywhere else in the world where it can be trusted more.

What is the case, however, is that you could set up a DoH endpoint on some other network and route your DNS there.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#36
post #27
post #22

Earlier quoted context omitted.

We already know they do - they’ve injected ads + “suggestions” instead of dns failures in the past. They’ve also injected permanently unique cookies in http requests. ISPs can’t be trusted as dumb pipes, they’re closer to “clueless criminal” pipes. But I agree with you, I don’t particularly trust google either.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

The UI bug tracker is private so we don't know if there might also be a "select DNS resolver" option and/or a checkbox for "encrypt DNS" in Settings.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#37

From Google's perspective being able to block ads with your hosts file is a bug, not a feature.

Perhaps. I personally would still setup DoH at the router level. ISPs begone.

This wouldn't make it into a large portion of consumer routers which are provided by the ISP.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#38
post #16

Strange these isps seem to have entirely ignored pihole, which for me is blocking around 30% of my DNS queries and overrides ISP DNS servers entirely.

Your ISP, by virtue of supplying the pipe to the internet, can (and very likely does) still snoop on any old-fashioned plaintext DNS requests you make across it, even when you're not using their servers.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#39
post #27
post #22

Earlier quoted context omitted.

We already know they do - they’ve injected ads + “suggestions” instead of dns failures in the past. They’ve also injected permanently unique cookies in http requests. ISPs can’t be trusted as dumb pipes, they’re closer to “clueless criminal” pipes. But I agree with you, I don’t particularly trust google either.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

> Google's design doesn't ask you to trust Google more than you already do if you use Chrome.

So in other words trust them with everything.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#40
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.
Post reply on HN