Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

111–120 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#111
post #40
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

[deleted]

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#112
Google wants the whole internet to go through them. Starting with the bloody DNS ... nice plan ... probably needs quite a bit lobbying and bad-mouthing other actors to succeed though ...

Absolutely. You can find a dishonest ISP. The difference is that there are thousands of them. And not just one big opaque entity.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#113
I am a bit stuck here. I know it is a bit insane, but I run a simple system at home because I think, so if I drop dead tomorrow how is my wife going to sort this. If I am dead, internet still needs to work so my kid can do her home work. So despite my geek love, I do not run my own DNS, etc. the other part is I use unblock-us so iPlayer (BBC) works here in the US. I would love to set everything up so everything is encrypted but ... yah. Sorry depressive.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#114
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

Personally I have absolutely zero qualms with implementing any system to collect mass analytics. I just don’t give a shit, at these scales users are cattle.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#115

Earlier quoted context omitted.

To make money on analytics?

He is speaking of the developers and engineers who have the technical expertise and should know it's a bad idea but still agree to implement it regardless of their moral compass.

[deleted]

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#116

Earlier quoted context omitted.

He is speaking of the developers and engineers who have the technical expertise and should know it's a bad idea but still agree to implement it regardless of their moral compass.

Why the implication that devs/engineers who have such technical expertise "know it's a bad idea"? There are plenty of devs and engineers who would have no moral issue with mass data collection and analytics. You don't magically become a paragon of morality just because you got a CS degree. Just ask Zuckerberg.

I’m working at a company and they want to do a massive amount of logging from our companies IOS app. Basically log everything in the name of security. I made the statement today what does legal think about the data we would be now storing? It has user locations, gps coordinates, all the other fun stuff you can get from a users phone. They all looked at me like I was crazy for even asking that question. And I don’t think a single person in the room the devs included had even though about the personal data we were going to be able to collect. And if we SHOULD be collecting it.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#117
post #112

Google wants the whole internet to go through them. Starting with the bloody DNS ... nice plan ... probably needs quite a bit lobbying and bad-mouthing other actors to succeed though ... Absolutely. You can find a dishonest ISP. The difference is that there are thousands of them. And not just one big opaque entity.

They're not moving anybody to Google's own DNS servers. If your current DNS provider offers encrypted service, they'll begin using that.

Starting with version 78, Chrome will begin experimenting with the new DoH feature. Under the experiment, Chrome will "check if the user's current DNS provider is among a list of DoH-compatible providers, and upgrade to the equivalent DoH service from the same provider," Google wrote. "If the DNS provider isn't in the list, Chrome will continue to operate as it does today."

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#118
post #75

Earlier quoted context omitted.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

To make money on analytics?

Seriously browse through the who's hiring thread... some engineers may see it as an easy way to get their foot in the door in the data analytics industry. Hopefully they just focus on bettering their portfolio.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#119
post #112

Google wants the whole internet to go through them. Starting with the bloody DNS ... nice plan ... probably needs quite a bit lobbying and bad-mouthing other actors to succeed though ... Absolutely. You can find a dishonest ISP. The difference is that there are thousands of them. And not just one big opaque entity.

ISPs are de facto more opaque than Google, and I'm not sure having a thousand of them is better than having only one.

A single company is easily legislatable, auditable, fineable, and chargeable if offenses are found. A thousand individual bad actors? The odds decrease.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#120
post #82
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

We agree that ISPs should not need to view your browsing data without your consent. But there are many technical reasons for an ISP to want to run DNS outside the resolver privacy conversation: For one some ISPs run content filtering services. Some users prefer to concede extreme privacy for what they view as a safer browsing experience. It might not be your jam, but it exists. DNS is designed to be provider independ…

> Its distributed nature means there are technical performance advantages to doing the above: reduced request latency, localized traffic routing and reduced bandwidth, etc. You don’t need a giant any cast network to serve DNS. You just need to use the servers closest to you.

My issue with this is that I've never been with an ISP that had a faster response time than Cloudflare/Google - and one would think they should, after all, my ISP should be able to reach me as quickly (or quicker) than any other corporation.

My current ISP has the fastest DNS benchmarks I've seen, and they're at 81ms for an uncached response, vs Cloudflare's 63ms and Google's 69ms. Cached response is similar (since I have a local cache).

In addition, my ISP does not provide DoH/DNSCrypt/DNSSec. None. Just 'vanilla' DNS. Furthermore, they also don't provide an unaltered DNS service: they block some websites from resolving, the list isn't made available, and is decided via extrajudicial means. You cannot opt-out, and all ISPs in the country adhere to this. They're not forced by law to do so. I'm also not in a normally thought of as a repressive country: it's a member state of the European Union, after all.

There are very good reasons for people to be outright hostile to ISPs and their shady underhanded practices, as you're seeing in this discussion. I feel that it is in any mostly online-based organisation's best interests to expose those practices.

Post reply on HN