Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

151–160 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#151
post #72

I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…

Exactly this. I build a DNS security product that works at the router level. Everything is secure on home networks running the product and it uses DoT for privacy so that ISPs can’t view your data—no browser intervention needed. Browsers interfering with user-configured defaults is incredibly presumptuous. I’m worried browsers are becoming less user-agent and more platform-agent...

FWIW, Chrome using an upgrade list only checks the system config (doesn't do any "do I eventually end up using 8.8.8.8" checks), so it shouldn't upgrade DoH even if your backend resolver is a third-party.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#152
post #81
post #43

Earlier quoted context omitted.

Why can't the PiHole create it's own DoH connection upstream? Y'know, the most classic way of doing a MitM on encrypted traffic?

Oh, it totally can, and there's nothing wrong with that. I would just hate for someone to terminate DoH on their home network and expose direct-to-the-roots DNS to their ISP, which is, if anything, marginally more attributable than normal ISP DNS. I'm definitely not talking down the idea of doing a PiHole setup.

I don't get why you'd think direct to the root DNS servers would be worse than using your ISPs servers. Using the root servers means you get DNSSEC which would prevent the greatest threats, hijacking and injection.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#153
post #29

Earlier quoted context omitted.

Chrome's design attempts to use your current DNS settings to access a DoH resolver and fallsback to the current behaviour if it fails. The browser isn't interfering in any of your network operations.

So, assuming my local LAN DNS resolver, which serves my own custom DNS information to LAN clients, doesn't support DoH itself, but uses DoH to reach out to the authoritative servers, chrome will bypass this my local resolver? Sounds like interfering with the way my intranet operates to me.

Why can't your local LAN DNS resolver support DoH itself if it can act as a DoH client to authoritative servers? That way the browser would know it can trust it to begin with.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#154
post #121
post #25

Earlier quoted context omitted.

PiHole supports DoH [0], via the cloudflared daemon. This won't change anything. [0] https://docs.pi-hole.net/guides/dns-over-https/

This is incorrect. Mozilla is ignoring your os/dhcp configured server and using Cloudflare. Your PiHole no longer sees the traffic. There is a way to configure your network to make Firefox not do this, so that's good. But it's not the default.

Thats also false.

Mozilla added a canary domain (use-application-dns.net) that if blocked will default to the local dns resolver. There are several threads in the pihole community about blocking it by default so I expect that will be done before mozilla turns int on for the masses.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#155
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

I have this adversarial opinion that I think is very unusual. Would love to hear your perspective.

Google pissed in the punch bowl by offering google fiber.

This forced the carriers to perceive google as an existential threat they are absolutely dependent upon for cheap ass android and ISP revenue from YouTube.

The only move they could make was to make google bleed. So they start offering content monetization and competing advertising platforms. Their goal isn’t to win, it’s to HURT GOOGLE. Advertising prices go down when there is meaningful competition. So shitty content monetizatuon from Comcast and VZ & ATT forces the price of google advertising down.

There is a big part of me that is pulling for the carriers on this front. I’m bummed more people don’t see it this way.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#156
post #8

I'm usually very skeptical of Google's plan for anything, but if it's pissing off big ISPs then sign me up.

Google's plans usually have carefully laid out technical justifications, and are mostly kinda boringly/obviously good, like QUIC/HTTP3. That you're usually skeptical of any plan coming from Google suggests that your skepticism is miscalibrated.

Why are those plans "obviously good"? They promote a view of the web that is all about piping a ton of content, sprinkled with ads, to passive consumers; just like TV.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#159

Earlier quoted context omitted.

To make money on analytics?

He is speaking of the developers and engineers who have the technical expertise and should know it's a bad idea but still agree to implement it regardless of their moral compass.

I've worked on questionable projects at a big telecom. I refuse to run ISP provided modems/routers at home, i refuse to use my isps dns and use dns-tls etc etc based on what i have seen.

The devs have often said things bad idea and raise concerns unfortunately you generally have no power, the decision to implement something is made above you. Generally the people making the decisions know things are questionable but you need to make your KPIs / get promoted / earn more money for the company etc etc.

If you don't follow a direct order and refuse to work on a piece of work in reality you will be fired.

That leaves you with the option of looking for a new job yourself or being forced to find a new job as you was kicked out.

While some people can take the moral highground, outright refuse and resign, others have to deal with life issues such as paying the bills and supporting a family which makes it extremely hard to pick a fight refusing to do something. We do not like to think it but we are just another cog in the wheel and dispensable.

Post reply on HN