Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

211–220 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#211

Earlier quoted context omitted.

There is virtually no DNSSEC deployed on any major sites on the Internet and, because DNSSEC is a terrible protocol, it's unlikely there ever will be. I'm a broken record on this; you can just search "author:tptacek DNSSEC" in the bar below to get lots of different reasons why. The most important thing for this thread though is that DNSSEC provides zero privacy and, in ordinary deployments (where you talk to a namese…

I don't think DNSSEC itself is likely to ever win. But it does have an additional dimension that makes it a better foundation for privacy than DoH. DoH is strictly transport layer security, meaning it still relies on a trusted third party (Mozilla or Google or whomever) to not vacuum your requests. Whereas if records are signed, they can be sent laterally between mutually untrusting peers, including bulk broadcasts,…

A better foundation for privacy? No. DNSSEC provides literally no privacy. It doesn't encrypt, it only signs. DNSSEC is passively observable by design.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#212

Earlier quoted context omitted.

I don't think DNSSEC itself is likely to ever win. But it does have an additional dimension that makes it a better foundation for privacy than DoH. DoH is strictly transport layer security, meaning it still relies on a trusted third party (Mozilla or Google or whomever) to not vacuum your requests. Whereas if records are signed, they can be sent laterally between mutually untrusting peers, including bulk broadcasts,…

A better foundation for privacy? No. DNSSEC provides literally no privacy. It doesn't encrypt, it only signs. DNSSEC is passively observable by design.

For privacy, getting records signed is ultimately more long-term important than getting queries encrypted immediately. As DoH shows, bolting on transport layer security is trivial.

For example, you'd never want to set your DoH resolver to an arbitrary TOR hidden service. But there would be no problem querying DNSSEC through TOR (assuming the setup wrapped the server-server protocol in something that allowed such forwarding).

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#213
post #208

Earlier quoted context omitted.

So if VPN over Tor (or Tor over VPN) increases anonymity then why is it the popular advice on the Net is not to do it?

Usually because it is very slow to do so. And anything that likes a persisted connection is likely to get a lot of connection resets. Like websockets (slack) or irc

In my experience, Tor through VPN services isn't substantially slower than Tor alone. I only know that from experiments using VPS, however, because I've never used Tor (or I2P or Freenet, for that matter) directly.

VPNs through Tor also aren't substantially slower than Tor alone. And indeed, one can use MPTCP to aggregate multiple VPN-via-Tor connections. But only between suitably configured devices, of course.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#214
post #25
post #13

Earlier quoted context omitted.

Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.

PiHole supports DoH [0], via the cloudflared daemon. This won't change anything. [0] https://docs.pi-hole.net/guides/dns-over-https/

I think there are multiple definitions of "using DoH". I think that guide sets this up:

Browser -[regular DNS]-> pihole -[regular DNS]-> cloudflared -[DoH]-> 1.1.1.1

So of the 3 hops, only 1 uses DoH. And specifically, the browser itself doesn't talk DoH.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#215

Earlier quoted context omitted.

And yet, most of Google's plans do not warrant skepticism.

Everything warrants skepticism until proven otherwise. Especially things that are being given out for free. Google might be operating on the up and up, but Google is just a large collection of people and some of them will be ethically lacking. And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists.

Internally, Google employees have quite a large incentive to NOT collect unnecessary data. It's a fundamental tenant. Don't collect any data unless it's for a specific tangible feature that benefits the user.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#216

Earlier quoted context omitted.

Here's a twitter thread worth reading, from the former VP of the Firefox group: https://twitter.com/johnath/status/1116871238922776576 It's easy to make proposals that incrementally increase user security while simultaneously increasing one's own ability to consolidate and exploit user data. Technical appeal needs to be evaluated with a simultaneous critical eye to social impact (QUIC is a perfect example -- it outco…

Forget about developing nations, there are plenty of parts of the US where mobile Internet is unreliable or altogether unavailable (I live in Utah, ask me how I know). Google doesn't even care if you're a paying customer -- they sell phones without expandable storage with the explanation that customers should just use the cloud (i.e., Google Drive) instead. Laughable.

Then buy a phone with expandable storage, that does run Google's operating system. That's the beauty of Google -- don't like their hardware? Buy one of the hundred other models.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#218

Earlier quoted context omitted.

A better foundation for privacy? No. DNSSEC provides literally no privacy. It doesn't encrypt, it only signs. DNSSEC is passively observable by design.

For privacy, getting records signed is ultimately more long-term important than getting queries encrypted immediately. As DoH shows, bolting on transport layer security is trivial. For example, you'd never want to set your DoH resolver to an arbitrary TOR hidden service. But there would be no problem querying DNSSEC through TOR (assuming the setup wrapped the server-server protocol in something that allowed such forw…

What a strange argument. If you want to argue that Tor is superior to DoH, argue that. DNSSEC has nothing to do with it. Which, of course, is obvious: DNSSEC is passively observable by design.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#219

Earlier quoted context omitted.

Here's a twitter thread worth reading, from the former VP of the Firefox group: https://twitter.com/johnath/status/1116871238922776576 It's easy to make proposals that incrementally increase user security while simultaneously increasing one's own ability to consolidate and exploit user data. Technical appeal needs to be evaluated with a simultaneous critical eye to social impact (QUIC is a perfect example -- it outco…

> developing nations -- but of course, Google doesn't care about those audiences Do you have a citation for your claims? There is plenty of evidence to the contrary: https://www.blog.google/technology/next-billion-users/ .

Yes, they designed a protocol which assumes low-latency highly reliable connections, which developing nations do not have. I care about what people _do_, not what they say in their PR blogs.

Also, wow, your comment history is just jam-packed with defending Google. Just a fan? Or do you still work at Youtube (https://news.ycombinator.com/item?id=13261130) ?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#220

Earlier quoted context omitted.

Forget about developing nations, there are plenty of parts of the US where mobile Internet is unreliable or altogether unavailable (I live in Utah, ask me how I know). Google doesn't even care if you're a paying customer -- they sell phones without expandable storage with the explanation that customers should just use the cloud (i.e., Google Drive) instead. Laughable.

Then buy a phone with expandable storage, that does run Google's operating system. That's the beauty of Google -- don't like their hardware? Buy one of the hundred other models.

Damn, why didn't I think of that?

It was just an example in support of the point made in the parent: as far as Google is concerned, the only people that matter are ones with unlimited, fast and reliable Internet access at all times without exception.

If you thought I was facing some kind of dilemma regarding whether or not to buy a phone that is useless half the time I leave my house, then thank you, but that's not the case.

Post reply on HN