Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

91–100 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#91
post #27

Earlier quoted context omitted.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

Yes, Google used the right approach here. They honor your DNS settings, and upgrade it if it's available. Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change.

>Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change.

Mozilla has explicitly stated on their blog that they don't intend to make any change to a user's DNS settings without getting the user's consent.

>When DoH is enabled, users will be notified and given the opportunity to opt out

https://blog.mozilla.org/futurereleases/2019/09/06/whats-nex...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#92
post #90
post #87

Earlier quoted context omitted.

This is a pretty silly debate. All you have to do is look at AT&T's DNS, see it hijack NXDOMAIN to send you to ad sites, and know that mainstream ISP DNS isn't trustworthy. We don't need to weigh up counterfactuals.

I’m not saying that some ISPs aren’t malicious. But to say there is no reason for an ISP to serve DNS is absurd.

There is no reason for ISP customers to use ISP DNS, given the available alternatives, and this will become even clearer as more people boot up DoH resolvers as alternatives to Cloud Flare.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#93
post #6

In many economies, ISPs have legal immunity from acts done by users (customers) because of laws associated with 'common carrier' status. But that status is fragile. The ISP has to act like it knows its obligations in law, and there are things ISPs have been doing to work with LEA for a long long time, which they won't be able to do as simply, or as well, or in some cases at all. As a customer its easy to assume the o…

I'm not sure what the issue is. My ISP can still intercept my DNS traffic and provide it to law enforcement. If it's unreadable because of encryption, how is that different than the fact that all my HTTPS requests are similarly unreadable?

They can't provide what they don't have. ISPs in the US (and I presume most countries) aren't obligated to ensure their customers don't use encryption.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#94
post #6

In many economies, ISPs have legal immunity from acts done by users (customers) because of laws associated with 'common carrier' status. But that status is fragile. The ISP has to act like it knows its obligations in law, and there are things ISPs have been doing to work with LEA for a long long time, which they won't be able to do as simply, or as well, or in some cases at all. As a customer its easy to assume the o…

DoH and DoT are just new delivery technologies. You've always been able to securely tunnel your traffic out of the country and you always will as it's trivial. DoT changing the resolver from one public company in the to another public company of the will not prevent the government from issuing warrants, particularly since they already issue warrants to these companies as it is. Common carrier defence is not going to…

There is a volume of ability north of 95% which could be lost, and the ISP has a mechanism to act (block DoT) but in DoH, its less simple. Hence, the liaison between Mozilla and Google, and state authorities.

Why do you think Mozilla turns this on selectively?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#95

Earlier quoted context omitted.

How do you know this fact?

I worked for a Comcast subsidiary in 2010-2011 timeframe. The company owned the network end to end. They had about 250k subscribers at the time across 4 states and at the time was the first DOCIS 3.0 network in the US. They were collecting DNS log data back then. I've been told that hasn't stopped and has progressed. Don't trust your ISP to not be passively monitoring. This particular ISP had closets full of old Sand…

We'll know how much this will affect those TLAs when the government suddenly gets involved for some altruistic reason to block DNS over HTTPS. "Don't let google take over the internet!" "Time to break up big tech!"

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#96
post #82
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

We agree that ISPs should not need to view your browsing data without your consent. But there are many technical reasons for an ISP to want to run DNS outside the resolver privacy conversation: For one some ISPs run content filtering services. Some users prefer to concede extreme privacy for what they view as a safer browsing experience. It might not be your jam, but it exists. DNS is designed to be provider independ…

ISPs are still able to run their filtering version of DNS server which the users are able to opt into. Nobody is going to take this away from them.

But that is not a valid use case for filtering dns requests to other services.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#97
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

To make money on analytics?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#98
post #82
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

We agree that ISPs should not need to view your browsing data without your consent. But there are many technical reasons for an ISP to want to run DNS outside the resolver privacy conversation: For one some ISPs run content filtering services. Some users prefer to concede extreme privacy for what they view as a safer browsing experience. It might not be your jam, but it exists. DNS is designed to be provider independ…

But DoH is provider independent. It's just like I can swap out AT&T's regular DNS service for Cloudflare's in my home setup. Which I did.

Mozilla's move to reconfigure Firefox to use DoH is a bit sneakier, but it fits with their privacy stance and their low market share does give them cover.

Post reply on HN