Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

261–270 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#261
post #53

Earlier quoted context omitted.

Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.) I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.

DNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements. So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any c…

Even with DOH, as things stand right now the ISP can see with SNI what sites your visiting, or certificate name for sites still using TLS 1.2 or lower.

So moving the DNS to Cloudflare only means “now Cloudflare have my entire browsing history as well as my ISP.”

I do appreciate there is a draft on ESNI but it’s not there yet.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#262

I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…

If you're so technical. Why not just put some firewall rules to block known DoH providers?

If a malicious app was to use their own DoH server then there's nothing you can do.

Well you can get a MITM web security product to inspect traffic.

Or only allow internet traffic through a proxy on your network and then block DNS providers.

Local caching via DNS? Perhaps on unencrypted HTTP traffic.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#263

I am a bit stuck here. I know it is a bit insane, but I run a simple system at home because I think, so if I drop dead tomorrow how is my wife going to sort this. If I am dead, internet still needs to work so my kid can do her home work. So despite my geek love, I do not run my own DNS, etc. the other part is I use unblock-us so iPlayer (BBC) works here in the US. I would love to set everything up so everything is en…

You know you can configure a fallback DNS, right?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#264
post #249

Earlier quoted context omitted.

Great. Now I've taken my laptop out of my house (where I'm using your router) to the coffee shop downstairs where they use an ISP provided gateway... And the ISP is spying on me again. Until DNS request is encrypted there are no solutions outside of a wholly self-managed network.

I’m unsure why this has to be set at the browser level instead of the OS level. What happens to all the DNS calls made by non-browser services on your laptop?

Go pay Microsoft and/or Apple to implement DNS over HTTPS.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#265
post #75

Earlier quoted context omitted.

I wonder why someone who knows how to do any of that, would think it is a good idea or go along with implementing that. The shitbirds who actually want to do this type of thing are not smart enough to execute it.

What do you mean? There's a whole genre of reasonably talented morally bankrupt "whitehats" building passivedns mass surveillance infrastructure. Cisco collects more than 24TB of DNS query data every day. Here's a Cisco employee demonstrating the kinds of horrifying analytics they perform on this data https://www.first.org/resources/papers/conf2018/Mahjoub-Dhia...

Wow, that is amazing. Is Cisco telling their clients they're doing this? That's a lot of root servers too.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#266
post #176

Earlier quoted context omitted.

What about 8.8.8.8? I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.

I think google is evil. But I know AT&T is.

This. I know from experience how terrible a company they are with customer service, but there is that little arrangement with the NSA called PRISM...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#267

What I fear will happen in several years is that local ISPs will also begin offering DoH by default (if you can't beat the competition, join them) and continue snooping on your traffic, just like Google or Cloudflare could do now technically, if they wanted to. Ultimately this boils down to which entity you trust more, your ISP or some other provider. Today Google/Cloudflare et al are by far the more trustworthy opti…

Why would you fear ISPs offering an encrypted service? It’s hardly a step backwards?

DoT would be preferable to DoH (no additional metadata / cookies,) but either way ISPs should adopt encrypted DNS.

You are correct it boils down to “who you trust.” In my country the ISP wins hands down over a foreign mega-corp so I end up making a different decision to you.

The key thing is that is a choice for users, not something software just does without knowledge of what’s going on.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#268
post #252

Earlier quoted context omitted.

To be even more fair, I feel pretty sure Zuckerberg would be happy to agree that "you don't magically become a paragon of morality just because you got a CS degree".

I’m not sure why anyone cares about Zuckerberg’s opinions on morality. The point that a CS degree does not impart a higher moral code is not controversial. My comment only pointed out that Zuckerberg was a bad example because he doesn’t have a CS degree.

And my comment pointed out that your parent comment didn't present Zuckerberg as an example, but as a source of support.

(Does that make sense? No, he'd make more sense as an example. But that's not what the comment said.)

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#269
I work for a large retailer ecommerce office and over the years found the business purchase huge lists of subscriber names plus domains from ISP customer browsing. Att and Verizon selling that I know about, maybe more that I dont know. With the amount of money involved that Im sure they aren't happy.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#270

Earlier quoted context omitted.

> developing nations -- but of course, Google doesn't care about those audiences Do you have a citation for your claims? There is plenty of evidence to the contrary: https://www.blog.google/technology/next-billion-users/ .

Yes, they designed a protocol which assumes low-latency highly reliable connections, which developing nations do not have. I care about what people _do_, not what they say in their PR blogs. Also, wow, your comment history is just jam-packed with defending Google. Just a fan? Or do you still work at Youtube ( https://news.ycombinator.com/item?id=13261130 ) ?

I would love to see the evidence for this as well.

Instead of providing any you just attacked the person who questioned you?

What specifically about the transport layer in QUIC makes it perform poorly on high latency links? It’s going through the IETF now I’d be surprised if they were complicit in such a backwards move.

Post reply on HN