Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

191–200 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#191

Earlier quoted context omitted.

Google's plans usually have carefully laid out technical justifications, and are mostly kinda boringly/obviously good, like QUIC/HTTP3. That you're usually skeptical of any plan coming from Google suggests that your skepticism is miscalibrated.

Here's a twitter thread worth reading, from the former VP of the Firefox group: https://twitter.com/johnath/status/1116871238922776576 It's easy to make proposals that incrementally increase user security while simultaneously increasing one's own ability to consolidate and exploit user data. Technical appeal needs to be evaluated with a simultaneous critical eye to social impact (QUIC is a perfect example -- it outco…

Forget about developing nations, there are plenty of parts of the US where mobile Internet is unreliable or altogether unavailable (I live in Utah, ask me how I know).

Google doesn't even care if you're a paying customer -- they sell phones without expandable storage with the explanation that customers should just use the cloud (i.e., Google Drive) instead.

Laughable.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#192
post #126

Earlier quoted context omitted.

> Its distributed nature means there are technical performance advantages to doing the above: reduced request latency, localized traffic routing and reduced bandwidth, etc. You don’t need a giant any cast network to serve DNS. You just need to use the servers closest to you. My issue with this is that I've never been with an ISP that had a faster response time than Cloudflare/Google - and one would think they should,…

I'm taking issue at the hyperbolic nature of the comment. I'm not an ISP apologist. But to say there are zero technical reasons for an ISP to want to provide DNS is unfair and incorrect. Cloudflare and Google pay ISPs for the latency they get, FWIW. If I made my own resolver service today I would not be able to compete with your ISP without forking over $$$.

> Cloudflare and Google pay ISPs for the latency they get, FWIW. If I made my own resolver service today I would not be able to compete with your ISP without forking over $$$.

I think the main reason for this is even if your competitor grew like a weed, it would be a decade or two before you had the scale to justify rolling out a CDN/caching infrastructure like that of cloudflare. That's not a matter of simply paying ISPs money.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#193
post #47

Earlier quoted context omitted.

I think you're being a bit over generous, the days of "Do no evil" have come and gone. Still, ISPs are definitely higher up on the evil-o-meter.

I don't think I'm being generous. Google's large scale plans are mostly about making the internet and technology ecosystem faster, safer, and more widely available. Of course, this is because their revenue scales as a factor of the number of people using the internet, the number of pages each person using the internet browses, and the willingness of people to spend money on the internet. But don't let the motive dist…

All of Google's large scale plans have strong centralizing effects. The benefits are not worth it.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#194

Earlier quoted context omitted.

I assume that all US TLAs have (or could have) access to all data that my ISP logs (or could log). That's just how it is. Given government ~monopoly on force. And that's why I use VPN services. But the same is true for VPN services, regarding US and/or other TLAs. So I use nested VPN chains, to make it harder to get complete data. And when it really matters, I add Tor to the mix. Even if it's heavily infiltrated by U…

So if VPN over Tor (or Tor over VPN) increases anonymity then why is it the popular advice on the Net is not to do it?

I mean routing traffic to Tor entry guards through VPN services. The Tor Project does indeed not recommend that. They argue that using a VPN service is risky, because it can log everything. Where access to entry guards is blocked, they recommend using bridges (of one sort or another) run by Tor volunteers.

I don't agree with that argument. Because ISPs can already do that. And for most people, their ISP is far more likely to be cooperating with their local adversaries than some random VPN service is.

And for what it's worth, one of Tor's inventors (Paul Syverson) has agreed publicly that there are reasons to access Tor through VPNs. Basically, when you don't want your ISP to know that you're using Tor. Indeed, if I were a CIA agent using Tor in Iran, I probably wouldn't want the ISP to know that I was using Tor.

But I don't trust VPN services either. So I use nested VPN chains. That's basically the same approach that Tor itself uses, routing traffic through multiple (three) relays. So no one relay (or for me, VPN service) knows both who I am, and what I'm doing online.

There's also the issue of trusting the Tor network. Some argue that it's compromised by US TLAs. So with a nested VPN chain between me and entry guards, I'm less concerned that some TLA is running them. But even if that's just paranoia, there have been bugs that deanonymized users.

For example, some years ago, CMU researchers exploited the "relay-early" bug to allow malicious entry guards and exit relays to exchange information, and so learn that they were routing the same circuit. That allowed said CMU researchers to deanonymize Tor users. The FBI learned of this, and subpoenaed the data. And lots of people went to jail over it. Mostly drug dealers and child pornographers, but whatever.

However, routing VPN services through Tor is a totally different matter. If you do that, your anonymity depends entirely on how anonymously you've obtained, paid for, and used the VPN service. If you used an email address that's linked to you, you're screwed. If there's a money trail in paying for the VPN service, you're screwed. If you ever use the VPN account without Tor, you're screwed.

And even if you manage all that anonymously, the very fact of using a VPN through Tor decreases your anonymity. That's because Tor by default switches circuits at ten minute intervals. But when a VPN is connected through a Tor circuit, that circuit is pinned. So by using a VPN through Tor, you've blocked one way it increases anonymity.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#196
post #176

Earlier quoted context omitted.

Netflow data, DNS capture, enrichment of cell tower access data (location), reporting on non-usage (idle time, tracking), Bill and household information, credit account usage, etc. SPs are huge sellers in this market. We still need to encrypt the accessed resource and DNS queries everywhere. Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.

What about 8.8.8.8? I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.

i suspect they somehow throttle this traffic -- i used to use 1.1.1.1 for a while and had to repeatedly switch out b/c my dns resolution times would be terrible after a while

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#197
post #81

Earlier quoted context omitted.

Oh, it totally can, and there's nothing wrong with that. I would just hate for someone to terminate DoH on their home network and expose direct-to-the-roots DNS to their ISP, which is, if anything, marginally more attributable than normal ISP DNS. I'm definitely not talking down the idea of doing a PiHole setup.

I don't get why you'd think direct to the root DNS servers would be worse than using your ISPs servers. Using the root servers means you get DNSSEC which would prevent the greatest threats, hijacking and injection.

There is virtually no DNSSEC deployed on any major sites on the Internet and, because DNSSEC is a terrible protocol, it's unlikely there ever will be. I'm a broken record on this; you can just search "author:tptacek DNSSEC" in the bar below to get lots of different reasons why.

The most important thing for this thread though is that DNSSEC provides zero privacy and, in ordinary deployments (where you talk to a nameserver rather than directly running on on your computer) no protection against injection between you and your nameserver.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#198

What I fear will happen in several years is that local ISPs will also begin offering DoH by default (if you can't beat the competition, join them) and continue snooping on your traffic, just like Google or Cloudflare could do now technically, if they wanted to. Ultimately this boils down to which entity you trust more, your ISP or some other provider. Today Google/Cloudflare et al are by far the more trustworthy opti…

As a reminder, here is Google's privacy FAQ for DNS.

https://developers.google.com/speed/public-dns/faq#privacy

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#199
post #8

I'm usually very skeptical of Google's plan for anything, but if it's pissing off big ISPs then sign me up.

Google's plans usually have carefully laid out technical justifications, and are mostly kinda boringly/obviously good, like QUIC/HTTP3. That you're usually skeptical of any plan coming from Google suggests that your skepticism is miscalibrated.

Google's technical justifications are usually pathetically self-serving. My favorite example: Why have they not yet removed cookies from HTTP? There are obvious improvements to privacy if we switch to server-managed sessions chosen by user-provided identities, and get rid of cookies, but it would frustrate Google's tracking of us, so it can't happen.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#200

Earlier quoted context omitted.

ISPs are still able to run their filtering version of DNS server which the users are able to opt into. Nobody is going to take this away from them. But that is not a valid use case for filtering dns requests to other services.

I'd separate "valid" and "reasonable". UK ISPs have a "valid" reason to DPI DNS and block pornhub, but i wouldn't say its reasonable for them to mess with internet packets not destined for their network. Thankfully DoH pressures them to suck it up and accept that blocking needs to be done by parents via parental controls.

That's what I'm saying. They can run their own DNS that people can opt into. They can provide those parental controls as well.
Post reply on HN