Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

291–300 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#291
post #176

Earlier quoted context omitted.

Netflow data, DNS capture, enrichment of cell tower access data (location), reporting on non-usage (idle time, tracking), Bill and household information, credit account usage, etc. SPs are huge sellers in this market. We still need to encrypt the accessed resource and DNS queries everywhere. Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.

What about 8.8.8.8? I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.

If you are not using gmail and google search, and are using adblockers, Google shouldn’t really have any information on your IP, so it is anonymised data. Your ISP knows even your bank details.

But the limits of using google DNS (or even encrypted DNS) is that most commercial websites aren’t sharing IP addresses, so I bet the ISP can pretty much reconstruct the data it would get from DNS with very little effort just by looking at your IP traffic and mapping IP addresses to domains from other users DNS queries.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#292

Earlier quoted context omitted.

He is speaking of the developers and engineers who have the technical expertise and should know it's a bad idea but still agree to implement it regardless of their moral compass.

I've worked on questionable projects at a big telecom. I refuse to run ISP provided modems/routers at home, i refuse to use my isps dns and use dns-tls etc etc based on what i have seen. The devs have often said things bad idea and raise concerns unfortunately you generally have no power, the decision to implement something is made above you. Generally the people making the decisions know things are questionable but…

Nice point. I've been considering changing my router for a while out of privacy concerns. Do you have a suggestion? I was wondering whether i could use my raspberry pi 3b+ for it.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#293

Earlier quoted context omitted.

I find it interesting that Google and CloudFlare are now the scapegoats. I mean, it's not like DoH isn't configurable and we don't have a choice.

Not attacking Google - their approach here is fine. But Mozilla switching people is a worry for me. Sure people “have a choice” but in reality expecting the average Joe who doesn’t even know what DNS is to make an informed decision about it is unrealistic. Meanwhile Mozilla has started sending a list of every domain you visit to a US company subject to US law enforcement. Not ideal.

Mozilla only started to doing that for US users.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#294
post #208

Earlier quoted context omitted.

Usually because it is very slow to do so. And anything that likes a persisted connection is likely to get a lot of connection resets. Like websockets (slack) or irc

In my experience, Tor through VPN services isn't substantially slower than Tor alone. I only know that from experiments using VPS, however, because I've never used Tor (or I2P or Freenet, for that matter) directly. VPNs through Tor also aren't substantially slower than Tor alone. And indeed, one can use MPTCP to aggregate multiple VPN-via-Tor connections. But only between suitably configured devices, of course.

regardless of "substantially slower" it is indeed slower, I guess it depends on your VPN link, but at the very least your MTU has to be considerably smaller meaning more round trips for "large" objects (anything over 1KiB essentially)

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#295
post #87

Earlier quoted context omitted.

This is a pretty silly debate. All you have to do is look at AT&T's DNS, see it hijack NXDOMAIN to send you to ad sites, and know that mainstream ISP DNS isn't trustworthy. We don't need to weigh up counterfactuals.

I think the missing piece here is the constant focus on the US. In Europe ISPs are under much stricter rules about data privacy and generally cannot do things like the above. Having worked for several ISPs here I’ve never found them misusing DNS data (although sometimes it was logged for a time for management / troubleshooting.) For a European; with reasonable trust in my ISP, I don’t want Mozilla sending all my quer…

Mozilla is only enabling DoH for US users, and Chrome is only enabling DoH if you were already using a DNS provider that also supports it.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#296
post #147

Earlier quoted context omitted.

It's more an industry error, I suspect. The University I went to forced all the Software Engineers to do some of the traditional Engineering papers, including courses on ethics. The professional institute that accredits the University's ability to call their course an Engineering course required those courses. Courses like that don't fix unethical people, but they make the rest of us aware that ethical concerns exist…

I question the amount that such ethics courses actually help. Business majors have had ethics courses for as long as I can imagine, and yet you don't have to go far on HN (even in this very thread) before you see people saying business majors are unethical. The bigger problem, IMO, is that many tech companies have started handing out kool-aid that data collection and analytics is ethical. They justify it by saying th…

Saying that business majors are full of unethical people is like saying that politics is full of unethical people, it is the job that attract those characteristics.

The objective of those ethical classes is to move the neutral/good majority in hope in hope to counterbalance the unethical minority.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#297

Earlier quoted context omitted.

True. Except that you don't need to trust anyone, entirely. That's the point of nested VPN chains. Let's say that you have three different VPN services in the chain. The first VPN knows your ISP-assigned IP address, and the IP address of the second VPN server. The second VPN knows the IP address of the first VPN server, and the IP address of the third VPN server. The third VPN knows the IP address of the second VPN s…

You're still vulnerable at the operating system and hardware level. It doesn't matter what you do after booting up if you're computer has already successfully been infiltrated from the Hardware/BIOS/OS initialization that always happens before.

I have considered those issues.

I don't use hardware that I've purchased using my meatspace identity. The machines mainly come from yard sales and swap meets. Typically nowhere near where I've lived. And all purchased with cash. So I'm pretty confident that they're not backdoored. I have purchased SSDs from stores, but also for cash.

I'm relatively confident that Debian hasn't been backdoored. Windows perhaps, but I rarely use it, and only in VMs.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#298

Earlier quoted context omitted.

He is speaking of the developers and engineers who have the technical expertise and should know it's a bad idea but still agree to implement it regardless of their moral compass.

[flagged]

There are many different kinds of capitalism

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#299
post #294

Earlier quoted context omitted.

In my experience, Tor through VPN services isn't substantially slower than Tor alone. I only know that from experiments using VPS, however, because I've never used Tor (or I2P or Freenet, for that matter) directly. VPNs through Tor also aren't substantially slower than Tor alone. And indeed, one can use MPTCP to aggregate multiple VPN-via-Tor connections. But only between suitably configured devices, of course.

regardless of "substantially slower" it is indeed slower, I guess it depends on your VPN link, but at the very least your MTU has to be considerably smaller meaning more round trips for "large" objects (anything over 1KiB essentially)

Sure. But as they say, speed kills.

Seriously, higher latencies and lower traffic peaks likely improve anonymity.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#300
post #262

I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…

If you're so technical. Why not just put some firewall rules to block known DoH providers? If a malicious app was to use their own DoH server then there's nothing you can do. Well you can get a MITM web security product to inspect traffic. Or only allow internet traffic through a proxy on your network and then block DNS providers. Local caching via DNS? Perhaps on unencrypted HTTP traffic.

That's what I do. I actively block third party DNS and known DNS services except cloudflare and quad9, but only when coming from my raspberry pi. I haven't allowed an unencrypted DNS request from my local network in a long time. At least not that I know of. I have blocked a lot of apps/appliances trying to use their own DNS, and so far that has been enough. When they figure out that they can use DNS on non-standard ports I'm fudged.
Post reply on HN