Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

281–290 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#281
post #105
post #92

Earlier quoted context omitted.

There is no reason for ISP customers to use ISP DNS, given the available alternatives, and this will become even clearer as more people boot up DoH resolvers as alternatives to Cloud Flare.

Again this is absolutely false. Your ISP, and nobody else, can deliver the lowest latency and quickest path DNS resolution short of other providers paying ISPs for last mile fog boxes (as some DNS providers do). Why can’t my ISP support DoT? But that also highlights a huge misconception about DoT/DoH: it only provides privacy to the resolver . It does not make your requests private in the eyes of the server or spanni…

> Why can’t my ISP support DoT?

They can, and I would be fine using it if it were a) fast, b) reliable, and c) (here's the big one) legally required that they not log or do anything with my queries.

As it stands, Comcast's provided resolver is somehow slower than some of the third-party providers for me, and I don't care to give them the ability to sell my DNS data.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#282

Earlier quoted context omitted.

I tend to call people out when they make claims that are not accurate. > I care about what people _do_, not what they say in their PR blogs. Did you read the blog? It's not just words, they are talking about products they have shipped. E.g. Files Go. You can believe what you want, but if you're going to big claims, you should back those up with credible data.

https://blog.apnic.net/2018/01/29/measuring-quic-vs-tcp-mobi... Further, we found that QUIC consumes significantly more than its fair share of bottleneck bandwidth when competing with TCP flows, which can be detrimental to a wide range of applications. https://blog.codavel.com/quic-vs-tcptls-and-why-quic-is-not-... QUIC is at its essence an ARQ protocol, i.e. feedbacks are required to recover from packet losses. And…

The claim I was referencing was taking a weakness in protocol, and jumping to conclusions.

This would be the equivalent of one saying, "You don't care about the environment because you took a gas powered bus today". And then provide evidence about how busses are harmful to the environment, and provide details about busses emitting GHGs.

Likewise, you can't jump from a weakness in QUIC to big tech doesn't care about NBU.. when in reality, much of big tech pours so much engineering effort towards NBU (amongst other things). Files Go is a small example, and you can download the app here: https://play.google.com/store/apps/details?id=com.google.and.... It is not vaporware.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#283
post #126

Earlier quoted context omitted.

> Its distributed nature means there are technical performance advantages to doing the above: reduced request latency, localized traffic routing and reduced bandwidth, etc. You don’t need a giant any cast network to serve DNS. You just need to use the servers closest to you. My issue with this is that I've never been with an ISP that had a faster response time than Cloudflare/Google - and one would think they should,…

I'm taking issue at the hyperbolic nature of the comment. I'm not an ISP apologist. But to say there are zero technical reasons for an ISP to want to provide DNS is unfair and incorrect. Cloudflare and Google pay ISPs for the latency they get, FWIW. If I made my own resolver service today I would not be able to compete with your ISP without forking over $$$.

I don't really understand why you keep repeating this claim that we're arguing that there are zero technical reasons for an ISP to want to provide DNS. No one is saying that.

Perhaps you misunderstood my original topelevel comment. If that's the case, let me try to clarify: ISPs have zero technical reasons to complain that people are using alternative resolvers. I totally see why they want to provide DNS resolvers, and that makes perfect sense. Unfortunately, part of that "want" is so they can sell DNS query data to third parties, which is just another reason why I don't want to use them.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#284
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

Actually everyone should prefer the other guy do it rather than host it themselves. Either way the bits have to be transported to the same colocated facilities it's a matter of who has to pay for and operate the servers. At least Cloudflare has KPMG audit them on their privacy claims. Better than nothing.

That made me curious to see who runs KPMG and whether it itself is trustworthy.

There is this: https://en.wikipedia.org/wiki/KPMG#Controversies

and then there is this:

https://home.kpmg/content/dam/kpmg/us/pdf/2019/01/2018-trans...

At the end of the day, any grouping of individuals are a (partially biased) sample of the society in general. The role of media and education is fairly decisive in forming social norms. We may have one or two lost generations of engineers following orders, but as Joe said 'The future is unwritten".

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#285

I may not have the technical expertise to understand this fully but right now I'm doing adblocking by using adguard's DNS IPs in my router (1). It kinda works everywhere but for some apps like Chromecast I have to null route two IP addresses (8.8.8.8 and 8.8.4.4) otherwise it doesn't work. Those are both Google's IPs afaik. So my question is: will I be able to keep doing it after this? I am asking because I am extrem…

Yes you will.

If using Firefox you’ll need to manually change the DNS settings, as it will by default bypass your local DNS and send it to Cloudflare using DoH. You can easily disable that though.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#286
post #122
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

They do use that information, it's not necessarilly sketchy. They run analytics just like everyone else. In fact, one could argue Google's huge push for https was primarily motivated to deprive service providers of valuable data that Google has anyway.

I consider most analytics use cases to be sketchy. To me, the onus should be on the company to prove to me that their use is not sketchy.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#287
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

While I definitely agree with the sentiment, I would much rather browsers used my own caching DNS server that I can configure to talk to root nameservers: this would be the best of both worlds (ISPs can't track me, and I wouldn't be handing data to another party either, except, well, root servers). I am sure it's going to be possible, but compared to setting it on my DHCP server, now every client's browser would need…

I don’t understand how that achieves anything.

If your DNS server is in the cloud, your ISP can still see your unencrypted queries to that server. If it is at home, your ISP can still see the unencrypted queries of that server to the root servers.

Unless you encrypt the traffic, DNS is transparent to the ISP whichever way you set it up.

And unless you are also using a VPN, the ISP can learn most of what it can learn with DNS just by looking at the IPs you send packets too. Most commercial websites that matter aren’t sharing IPs.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#288

Earlier quoted context omitted.

Perhaps because downloading Tor (or even searching for it / visiting its website) demonstrates an active interest in thwarting surveillance. Almost by definition, that means you're worth taking a closer look at. Once you're under the microscope, you'd better hope your opsec is flawless or that your activities are completely boring, or else the $TLA knows exactly what you've been up to, TOR or not. Disclosure: my acti…

> Perhaps because downloading Tor (or even searching for it / visiting its website) demonstrates an active interest in thwarting surveillance. Not if you access tor over VPN. VPN hides all traffic from ISP and Gov. Obviously, make sure your browser does not use Google or Cloudflare DNS.

VPN hides all traffic from ISP and Gov.

VPN like... Onavo?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#289
post #8

I'm usually very skeptical of Google's plan for anything, but if it's pissing off big ISPs then sign me up.

Google's plans usually have carefully laid out technical justifications, and are mostly kinda boringly/obviously good, like QUIC/HTTP3. That you're usually skeptical of any plan coming from Google suggests that your skepticism is miscalibrated.

I think you're cherry picking. I'd say AMP and the consequent AMP for email are recent examples to the contrary. Nothing wrong with skepticism, especially directed at a company the size of Google.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#290
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

I have this adversarial opinion that I think is very unusual. Would love to hear your perspective. Google pissed in the punch bowl by offering google fiber. This forced the carriers to perceive google as an existential threat they are absolutely dependent upon for cheap ass android and ISP revenue from YouTube. The only move they could make was to make google bleed. So they start offering content monetization and com…

If the carriers were good actors that in general act in good faith most of the time, maybe (assuming your hunch is correct) I'd feel bad for them. But they don't, so I don't.
Post reply on HN