Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

251–260 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#251
post #66

Earlier quoted context omitted.

Chrome doesn’t know that your local intranet is trusted or that the local resolver is trustworthy. You need to tell Chrome this by flipping a switch to either change your DoH provider or disable it all together. This change is explicitly protecting users from malicious network operators. Since you control the endpoints it should be no big deal, you apply GPO, run Puppet, whatever and everybody is talking to your loca…

In that context, I'd be perfectly happy if chrome had a "I'm on an untrusted network right now" switch, like incognito window. Not sure we should assume that the entire network between the browser and cloudflare is untrusted though. Aren't there some "hijacks" that are actually valuable to users? For example, if I run a network inside an extremely limited internet environment, I can hijack the user's DNS and redirect…

> Not sure we should assume that the entire network between the browser and cloudflare is untrusted though.

The network is compromised. This is the fundamental assumption of networks. If you operate from this position you are much less likely to get burned.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#252
post #130

Earlier quoted context omitted.

To be fair Zuckerberg didn’t get a CS degree. Your point still stands of course.

To be even more fair, I feel pretty sure Zuckerberg would be happy to agree that "you don't magically become a paragon of morality just because you got a CS degree".

I’m not sure why anyone cares about Zuckerberg’s opinions on morality. The point that a CS degree does not impart a higher moral code is not controversial. My comment only pointed out that Zuckerberg was a bad example because he doesn’t have a CS degree.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#253

Earlier quoted context omitted.

Everything warrants skepticism until proven otherwise. Especially things that are being given out for free. Google might be operating on the up and up, but Google is just a large collection of people and some of them will be ethically lacking. And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists.

Disclaimer: I work at Google. > And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists. I can only speak from personal experience. But I would not agree. Collection of data needs to be covered in a privacy document. You must argue why you're collecting it. There has to be a retention plan, such that data is purged when the user account is deleted,…

Your comment is 'dead' (at my time of posting) when you simply stated that you disagree and politely brought up some factual supporting points. I didn't expect such hivemind-like behavior from HN...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#254
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

What do you mean? There's a whole genre of reasonably talented morally bankrupt "whitehats" building passivedns mass surveillance infrastructure.

Cisco collects more than 24TB of DNS query data every day. Here's a Cisco employee demonstrating the kinds of horrifying analytics they perform on this data https://www.first.org/resources/papers/conf2018/Mahjoub-Dhia...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#256
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

> I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that

The age-old answer: money.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#257

Earlier quoted context omitted.

Yes, Google used the right approach here. They honor your DNS settings, and upgrade it if it's available. Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change.

>Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change. Mozilla has explicitly stated on their blog that they don't intend to make any change to a user's DNS settings without getting the user's consent. >When DoH is enabled, users will be notified and given the opportunity to opt out https://blog.mozilla.org/futurereleases/2…

The problem is it’s just a banner with “ok” at the top, which clearly says “we’ve increased your privacy by (insert technical jumbo jumbo here).”

As Bert Hubert pointed out, to most users it ends up looking like this:

https://twitter.com/powerdns_bert/status/1123666707279695874...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#258
post #134
post #19

Earlier quoted context omitted.

What’s stopping your PiHole or DMS adblocker from functioning as a MITM proxy? You’d just terminate HTTPS at the PiHole and perform the filtering there, right? Regardless, it’s a tiny thing to give up for more privacy.

Running a MITM HTTPS proxy means running a CA, means the proxy gets to decide what to do about certificate errors instead of the client, means maintaining a whitelist of sites that can't be MITM'd, means segregating all the devices that I can't put a CA signing certificate on, and is just in general an ugly thing that should be avoided wherever possible. Mozilla's method of implementing this has also created a bluepr…

Thanks. I was also thinking... how does DoH prevent an ISP from spying on you? Even though the DNS requests and responses are encrypted, content requests are still routed via the ISP, right?

So the ISP still has a log of which IPs you’ve visited. They can resolve this back to site names and get the same information on you they had before.

Edit: answer here: https://security.stackexchange.com/questions/200201/how-does...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#259
post #27

Earlier quoted context omitted.

Google's design doesn't ask you to trust Google more than you already do if you use Chrome. It doesn't default you to Google's DNS servers, will honor your current nameservers, and will upgrade you to DoH at any of those servers who support it. I'm honestly not sure what more you could ask for from Google on this particular issue.

So it's more like HSTS for DNS? Auto-switch to encryption if our chosen target supports encryption? Because that seems MUCH more sensible than a lot of the stories/comments about this recently make it seem.

Yes, as Google plan you implement it, which is fine.

Most of the hulaboo is about Mozilla who are moving customers DNS queries to Cloudflare en mass, regardless of what DNS server they have already configured.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#260
post #75
post #40

Earlier quoted context omitted.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

> I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that

Modern silicon valley is built off people implementing similar pervasive tracking, without it there is no google, facebook and many other startups. Not to mention online newspapers and everyone who makes money indirectly from the tracking.

I agree it's a bad thing, but that ship sailed long ago and things like the GDPR are only just starting to bring it back.

Post reply on HN