Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

71–80 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#71
post #66

Earlier quoted context omitted.

So, assuming my local LAN DNS resolver, which serves my own custom DNS information to LAN clients, doesn't support DoH itself, but uses DoH to reach out to the authoritative servers, chrome will bypass this my local resolver? Sounds like interfering with the way my intranet operates to me.

Chrome doesn’t know that your local intranet is trusted or that the local resolver is trustworthy. You need to tell Chrome this by flipping a switch to either change your DoH provider or disable it all together. This change is explicitly protecting users from malicious network operators. Since you control the endpoints it should be no big deal, you apply GPO, run Puppet, whatever and everybody is talking to your loca…

In that context, I'd be perfectly happy if chrome had a "I'm on an untrusted network right now" switch, like incognito window. Not sure we should assume that the entire network between the browser and cloudflare is untrusted though.

Aren't there some "hijacks" that are actually valuable to users? For example, if I run a network inside an extremely limited internet environment, I can hijack the user's DNS and redirect them to a "Hey, we're sorry, but running Netflix here will ruin the network for everyone, we hope you understand" page. If their browser is ignoring my local DNS server my option would seem to be simply black-hole netflix packets in the firewall, which is a lot less friendly to the user. Would I be a malicious network operator in this case?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#72

I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…

Exactly this. I build a DNS security product that works at the router level. Everything is secure on home networks running the product and it uses DoT for privacy so that ISPs can’t view your data—no browser intervention needed. Browsers interfering with user-configured defaults is incredibly presumptuous. I’m worried browsers are becoming less user-agent and more platform-agent...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#73
post #61

Earlier quoted context omitted.

If Google/Cloudflare are having significant issues resolving DNS everybody is getting a call anyways.

Not sure I understand. If you're using your ISP's DNS service, majority of your requests are going to hit their cache. You shouldn't notice any downtime as long as the cache doesn't expire.

I mean if all of Google/Cloudflares anycast resolvers go tits up I'm going to get endless calls regardless if the end user can resolve a cached name or not.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#74
post #27
post #22

Earlier quoted context omitted.

We already know they do - they’ve injected ads + “suggestions” instead of dns failures in the past. They’ve also injected permanently unique cookies in http requests. ISPs can’t be trusted as dumb pipes, they’re closer to “clueless criminal” pipes. But I agree with you, I don’t particularly trust google either.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

So it's more like HSTS for DNS? Auto-switch to encryption if our chosen target supports encryption?

Because that seems MUCH more sensible than a lot of the stories/comments about this recently make it seem.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#75
post #40
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#76
post #29

Earlier quoted context omitted.

Chrome's design attempts to use your current DNS settings to access a DoH resolver and fallsback to the current behaviour if it fails. The browser isn't interfering in any of your network operations.

So, assuming my local LAN DNS resolver, which serves my own custom DNS information to LAN clients, doesn't support DoH itself, but uses DoH to reach out to the authoritative servers, chrome will bypass this my local resolver? Sounds like interfering with the way my intranet operates to me.

No it should use your local resolver.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#77
post #23
post #21

Earlier quoted context omitted.

For now. Google sneezes and this is gone. We didn't think they'd take away extensions' abilities to block ads, and yet here we are. We've seriously got to pursue breaking this company up. They're the absolute worst.

That is a serious misrepresentation of what's happening with Manifest v3.

> serious misrepresentation

How is it a serious misrepresentation?

Manifest v3 cripples the ability to block ads.

Google is an ad company and has the largest browser market share by far.

How is this not abuse?

Google can claim that things like AMP are not intended to rope us into their walled garden, that it's all about improving performance. But at the end of the day, most of the moves they make further their goal of serving more ads.

In twenty years I wouldn't be too terribly surprised if independent websites are largely gone. Disappeared like IRC, RSS, blogging on your own website, and the like.

I'm sorry you disagree. I just don't like what I see happening.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#78
post #68

Earlier quoted context omitted.

Yes, Google used the right approach here. They honor your DNS settings, and upgrade it if it's available. Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change.

[deleted]

The article itself says this.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#79
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

[deleted]

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#80
post #68

Earlier quoted context omitted.

Yes, Google used the right approach here. They honor your DNS settings, and upgrade it if it's available. Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change.

[deleted]

The article?
Post reply on HN