Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

131–140 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#131
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

Engineers are people who come in all ethical flavors. I used to know one whom I consider evil, in the actively, knowingly malicious sense. I've known a whole lot more who generally just don't think about these questions.

Thinking knowledge, intelligence or capability correlates with ethics is a category error.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#133
post #57

Earlier quoted context omitted.

Google makes the majority of its revenue by knowing things about their users and then allowing them to be targeted with ads. Google's plans being usually "obviously good" is a highly subjective opinion.

And yet, most of Google's plans do not warrant skepticism.

Google's plans fall into two categories: obviously good is one of those.

That doesn't mean that AMP is a great idea.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#134
post #19
post #13

Earlier quoted context omitted.

Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.

What’s stopping your PiHole or DMS adblocker from functioning as a MITM proxy? You’d just terminate HTTPS at the PiHole and perform the filtering there, right? Regardless, it’s a tiny thing to give up for more privacy.

Running a MITM HTTPS proxy means running a CA, means the proxy gets to decide what to do about certificate errors instead of the client, means maintaining a whitelist of sites that can't be MITM'd, means segregating all the devices that I can't put a CA signing certificate on, and is just in general an ugly thing that should be avoided wherever possible.

Mozilla's method of implementing this has also created a blueprint for malware to avoid network-level detection.

I don't like it. In my view, what's being given up is significant and the privacy gain minimal.

(Right now, Mozilla has a DNS-based killswitch, but how long until all the 'bad actors' Mozilla is targeting have implemented it? I know of one public DNS provider already doing that. They'll take away the killswitch, then all the 'bad countries' will force their populations to install MITM certificates [along with the UK] and the world is going to end up worse off thanks to Mozilla)

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#135
post #31

Earlier quoted context omitted.

If you're on a mainstream US ISP, interference from your browser with your ISP's "network level operations" is a privacy necessity. They're passively monitoring DNS to collect data on their customers and hijacking it to send users to advertising sites. ISP DNS is manifestly untrustworthy.

Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.) I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.

> I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.

Mozilla and Cloudflare negotiated a special privacy policy for Firefox DoH requests [1] that limits what Cloudflare can do with the data – in particular, most information must be deleted after 24 hours. There is no technical measure holding them to that policy, but it’s a contract enforceable through the courts. Nothing similar applies to your average American consumer ISP.

[1] https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#137
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

In countries or locations with a nearly nonexistent tech industry, your employment options as a software engineer may be limited to that kind of crap

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#138
post #27
post #22

Earlier quoted context omitted.

We already know they do - they’ve injected ads + “suggestions” instead of dns failures in the past. They’ve also injected permanently unique cookies in http requests. ISPs can’t be trusted as dumb pipes, they’re closer to “clueless criminal” pipes. But I agree with you, I don’t particularly trust google either.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

That's true, but Google has made no commitment to keep it that way.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#139
I may not have the technical expertise to understand this fully but right now I'm doing adblocking by using adguard's DNS IPs in my router (1).

It kinda works everywhere but for some apps like Chromecast I have to null route two IP addresses (8.8.8.8 and 8.8.4.4) otherwise it doesn't work. Those are both Google's IPs afaik.

So my question is: will I be able to keep doing it after this? I am asking because I am extremely suspicious of Google these days and wondering if they have an ulterior motive to prevent users from doing such host based adblocking in future?

(1) https://adguard.com/en/adguard-dns/overview.html

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#140
post #107
post #98

Earlier quoted context omitted.

But DoH is provider independent. It's just like I can swap out AT&T's regular DNS service for Cloudflare's in my home setup. Which I did. Mozilla's move to reconfigure Firefox to use DoH is a bit sneakier, but it fits with their privacy stance and their low market share does give them cover.

To be clear I’m not arguing against DoH/T. I’m arguing that there are technical and product reasons an ISP might want to run DNS.

That is understandable. But when the majority of US ISPs are monopolitical or oligopolitical organizations with zero oversight (Ajit Patel), it becomes harder to argue that sell.
Post reply on HN