Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

271–280 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#271
post #249

Earlier quoted context omitted.

Great. Now I've taken my laptop out of my house (where I'm using your router) to the coffee shop downstairs where they use an ISP provided gateway... And the ISP is spying on me again. Until DNS request is encrypted there are no solutions outside of a wholly self-managed network.

I’m unsure why this has to be set at the browser level instead of the OS level. What happens to all the DNS calls made by non-browser services on your laptop?

I believe it is due to technical problems of switching everything to DoH. Moreover if we think about it, I'll see that it is not a Google or Mozilla problem, it is a problem of OS developers. For example, it might be done by gethostbyname using DoH to resolve names. But it is up to libc developers, and it would lead to other problems, like system after update stopped working, due to custom configuration incompatible with DoH.

Mozilla and Google become unsatisfied with gethostbyname but they cannot change that part of OS. So they are solving their problems on their side.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#272
post #87

Earlier quoted context omitted.

This is a pretty silly debate. All you have to do is look at AT&T's DNS, see it hijack NXDOMAIN to send you to ad sites, and know that mainstream ISP DNS isn't trustworthy. We don't need to weigh up counterfactuals.

I think the missing piece here is the constant focus on the US. In Europe ISPs are under much stricter rules about data privacy and generally cannot do things like the above. Having worked for several ISPs here I’ve never found them misusing DNS data (although sometimes it was logged for a time for management / troubleshooting.) For a European; with reasonable trust in my ISP, I don’t want Mozilla sending all my quer…

I absolutely agree with you. I have more trust into my local European ISP than into Google, Cloudflare and such.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#274
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

While I definitely agree with the sentiment, I would much rather browsers used my own caching DNS server that I can configure to talk to root nameservers: this would be the best of both worlds (ISPs can't track me, and I wouldn't be handing data to another party either, except, well, root servers). I am sure it's going to be possible, but compared to setting it on my DHCP server, now every client's browser would need reconfiguration.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#275

Earlier quoted context omitted.

I tend to call people out when they make claims that are not accurate. > I care about what people _do_, not what they say in their PR blogs. Did you read the blog? It's not just words, they are talking about products they have shipped. E.g. Files Go. You can believe what you want, but if you're going to big claims, you should back those up with credible data.

https://blog.apnic.net/2018/01/29/measuring-quic-vs-tcp-mobi... Further, we found that QUIC consumes significantly more than its fair share of bottleneck bandwidth when competing with TCP flows, which can be detrimental to a wide range of applications. https://blog.codavel.com/quic-vs-tcptls-and-why-quic-is-not-... QUIC is at its essence an ARQ protocol, i.e. feedbacks are required to recover from packet losses. And…

It does show QUIC falling apart with _out of order delivery_, however that is not something that latency or slow networks will produce. There is no reason to think that slow / third world countries have significantly more out of order delivery. The networks might be slower / have higher latencies, but packet order is likely to be the same.

That is different than dropped packets requiring retransmissions, but given QUIC and TCP both use the same congestion control algorithm (Cubic) there should be no difference on that score.

In terms of it being “unfair” when both types of streams are present that’s correct, but TCP with BBR also produces this kind of effect. It’s the algorithm used, not whether it’s QUIC or TCP, that causes this.

QUIC is not perfect, it’s still only at draft stage in the IETF. I’d be concerned that arguments like this are being made which, while seemingly well intentioned, have the effect of stifling innovation for all internet users.

You can bet that on a high latency link the fewer round-trips to set up a TLS connection with QUIC are gonna improve things.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#276
post #82
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

We agree that ISPs should not need to view your browsing data without your consent. But there are many technical reasons for an ISP to want to run DNS outside the resolver privacy conversation: For one some ISPs run content filtering services. Some users prefer to concede extreme privacy for what they view as a safer browsing experience. It might not be your jam, but it exists. DNS is designed to be provider independ…

I don't think any of these things justify the ISP's response.

Regarding content filtering services, in that case the user is specifically opting in to that service, so they won't need or care to use an alternate resolver.

I agree that, ideally, you would use a resolver that's close to you in order to minimize latency and increase reliability, but:

1) This requires you to trust your ISP. Many people don't, and with good reason.

2) ISP DNS isn't exactly always the most reliable or fast thing anyway. I easily get better latency from Cloudflare or Quad9 (their old-school Do53 stuff, not the new-fangled DoH) than from Comcast's resolver.

And regardless, if your DoH provider of choice goes down, you can always fall back to a different one, or to your ISP's resolver.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#277
With the statement "could interfere on a mass scale with critical Internet functions, as well as raise data-competition issues" they are actually lying and misrepresenting the issue. In reality there is not much "to interfere" - especially not so much, that you would need to contact the Congress...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#278
post #252

Earlier quoted context omitted.

I’m not sure why anyone cares about Zuckerberg’s opinions on morality. The point that a CS degree does not impart a higher moral code is not controversial. My comment only pointed out that Zuckerberg was a bad example because he doesn’t have a CS degree.

And my comment pointed out that your parent comment didn't present Zuckerberg as an example, but as a source of support. (Does that make sense? No, he'd make more sense as an example. But that's not what the comment said.)

Yes, I see now, thanks for pointing that out. The implication being Zuckerberg relies on people with CS degrees even if he himself does not have one.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#279
post #66

Earlier quoted context omitted.

Chrome doesn’t know that your local intranet is trusted or that the local resolver is trustworthy. You need to tell Chrome this by flipping a switch to either change your DoH provider or disable it all together. This change is explicitly protecting users from malicious network operators. Since you control the endpoints it should be no big deal, you apply GPO, run Puppet, whatever and everybody is talking to your loca…

In that context, I'd be perfectly happy if chrome had a "I'm on an untrusted network right now" switch, like incognito window. Not sure we should assume that the entire network between the browser and cloudflare is untrusted though. Aren't there some "hijacks" that are actually valuable to users? For example, if I run a network inside an extremely limited internet environment, I can hijack the user's DNS and redirect…

Yes. You would be malicious. Doesn't matter what your intentions are if someone with bad intensions could do something bad in that scenario.

For example redirecting the user to a fake webpage asking for their username and password.

A user will learn that there's blocking if they try and access Netflix and it doesn't work.

You can get something like a Juniper SRX firewall which can recognise applications via signature and do blocking that way. Rather than against IP ranges only.

Also as a network admin you're not saying why you won't be able to block DNS over HTTPS providers.

Unless you're thinking there's going to be some unknown DNS server used by the browser.

But if that's your fear you'll need to block all the online DNS lookup websites.

What if a user just types the IP address directly? Totally circumnavigates DNS.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#280
post #90
post #87

Earlier quoted context omitted.

This is a pretty silly debate. All you have to do is look at AT&T's DNS, see it hijack NXDOMAIN to send you to ad sites, and know that mainstream ISP DNS isn't trustworthy. We don't need to weigh up counterfactuals.

I’m not saying that some ISPs aren’t malicious. But to say there is no reason for an ISP to serve DNS is absurd.

I don't think anyone is arguing that there's no reason for an ISP to serve DNS.
Post reply on HN