I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…
Big ISPs aren’t happy about Google’s plans for encrypted DNS
31–40 of 456 posts
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#32While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.
At least Cloudflare has KPMG audit them on their privacy claims. Better than nothing.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#33Earlier quoted context omitted.
What’s stopping your PiHole or DMS adblocker from functioning as a MITM proxy? You’d just terminate HTTPS at the PiHole and perform the filtering there, right? Regardless, it’s a tiny thing to give up for more privacy.
Ah yes, Google and CloudFlare, those well-known bastions of privacy.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#34From Google's perspective being able to block ads with your hosts file is a bug, not a feature.
Ads are a much smaller threat than unscrupulous ISPs. They have access to ALL your traffic.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#35Earlier quoted context omitted.
Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.
Completely untrue. Those services just need to serve their own DoH endpoint and the user can add it in Firefox preferences. No harder than and arguably easier than the complicated procedure for changing system DNS, and it allows you to block things in your browser that you may not want blocked at the system level for all users.
What is the case, however, is that you could set up a DoH endpoint on some other network and route your DNS there.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#36Earlier quoted context omitted.
We already know they do - they’ve injected ads + “suggestions” instead of dns failures in the past. They’ve also injected permanently unique cookies in http requests. ISPs can’t be trusted as dumb pipes, they’re closer to “clueless criminal” pipes. But I agree with you, I don’t particularly trust google either.
Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#37Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#38Strange these isps seem to have entirely ignored pihole, which for me is blocking around 30% of my DNS queries and overrides ISP DNS servers entirely.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#39Earlier quoted context omitted.
We already know they do - they’ve injected ads + “suggestions” instead of dns failures in the past. They’ve also injected permanently unique cookies in http requests. ISPs can’t be trusted as dumb pipes, they’re closer to “clueless criminal” pipes. But I agree with you, I don’t particularly trust google either.
Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.
So in other words trust them with everything.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#40While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.