Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

51–60 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#51

Haha Big ISPs...there’s absolutely no reason why regular HTTP requests/responses should be TLS encrypted while DNS queries should not...they go hand in hand for maintaining end-user privacy and YOUR integrity.

"Going blind" is a term I've heard recently when talking with operators. Where as "going dark" referred to the DOJ/FBI's term for ubiquitous encipherment of the content, "going blind" refers to the metadata (DNS in this case). My view is pretty basic: If I can see your DNS, I can pretty much guess on a very short list what kind of [browsing] behavior you are engaging in.

You don’t have to guess. You can actually see it.

What you can infer is why and who. Which is the real danger. I would trust google to protect sensitive data like sexual preferences before I trust my ISP.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#52
post #40
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

How do you know this fact?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#53
post #31

Earlier quoted context omitted.

If you're on a mainstream US ISP, interference from your browser with your ISP's "network level operations" is a privacy necessity. They're passively monitoring DNS to collect data on their customers and hijacking it to send users to advertising sites. ISP DNS is manifestly untrustworthy.

Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.) I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.

DNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements.

So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any connection you make.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#54
Something I’ve wondered: It isn’t quite clear from the various articles how they’re doing this monitoring. I can totally see how they could monitor their own caching resolvers. They might even passively monitor popular internet resolvers (1.1.1.1, 8.8.8.8). But if I run my own caching resolver at home, is that data being mined? I am aware it’s unencrypted and possible to do so, but is it actually happening? DoH sounds nice, but it brings me back to using a shared caching resolver which I’m not a huge fan of.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#56
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

How do you know this fact?

I’m friends with solutions engineers at Hortonworks and Cloudera. It’s possible I’m wrong, and since this is anecdotal evidence I see “fact” isn’t a valid use here.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#57
post #8

I'm usually very skeptical of Google's plan for anything, but if it's pissing off big ISPs then sign me up.

Google's plans usually have carefully laid out technical justifications, and are mostly kinda boringly/obviously good, like QUIC/HTTP3. That you're usually skeptical of any plan coming from Google suggests that your skepticism is miscalibrated.

Google makes the majority of its revenue by knowing things about their users and then allowing them to be targeted with ads.

Google's plans being usually "obviously good" is a highly subjective opinion.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#58
post #27

Earlier quoted context omitted.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

> Google's design doesn't ask you to trust Google more than you already do if you use Chrome. ...well, I don't, so there. Also, this is true if I'd _only_ use Chrome, and never used other software for networking. Damn, I actually used to respect you. This is so disappointing.

A whole bunch of irrelevant retorts + a personal attack. I've never seen a comment more deserving of getting flagged than this one.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#59
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

Actually everyone should prefer the other guy do it rather than host it themselves. Either way the bits have to be transported to the same colocated facilities it's a matter of who has to pay for and operate the servers. At least Cloudflare has KPMG audit them on their privacy claims. Better than nothing.

Tried searching, but couldn’t find a report by KPMG. Has one been produced already or is this a future thing?

Regardless, impressive step to take.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#60
post #51

Earlier quoted context omitted.

"Going blind" is a term I've heard recently when talking with operators. Where as "going dark" referred to the DOJ/FBI's term for ubiquitous encipherment of the content, "going blind" refers to the metadata (DNS in this case). My view is pretty basic: If I can see your DNS, I can pretty much guess on a very short list what kind of [browsing] behavior you are engaging in.

You don’t have to guess. You can actually see it. What you can infer is why and who. Which is the real danger. I would trust google to protect sensitive data like sexual preferences before I trust my ISP.

It all depends how much is abstracted behind a common host (eg name based virtual hosting). I can see you are going to Google. But I don't know what within Google you are really accessing or using in most cases.
Post reply on HN