Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

301–310 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#301
post #147
post #131

Earlier quoted context omitted.

Engineers are people who come in all ethical flavors. I used to know one whom I consider evil, in the actively, knowingly malicious sense. I've known a whole lot more who generally just don't think about these questions. Thinking knowledge, intelligence or capability correlates with ethics is a category error.

It's more an industry error, I suspect. The University I went to forced all the Software Engineers to do some of the traditional Engineering papers, including courses on ethics. The professional institute that accredits the University's ability to call their course an Engineering course required those courses. Courses like that don't fix unethical people, but they make the rest of us aware that ethical concerns exist…

Unless you imagine some sort of industry-wide reckoning from a political/legal perspective, the industry will probably never "grow up". This isn't the sort of industry where a couple bridges might fall down and everyone suddenly gains self-awareness that it's time to be a little more adult.

Just look at the resistance on this forum to the idea of GDPR or data privacy bills. This is one of the most self-aware forums on the internet and still probably a majority of users are not only aware of who (and what) is signing their paychecks, but they actively endorse it in their personal discourse during their time off too.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#302
post #143

Earlier quoted context omitted.

It's a good point, but it is preventable by the network admin. For example, I bypass that by tunneling everything out over a VPN, and the local resolver attempts to use HTTPS to connect to upstream anyway. Obviously not every user is in a position to protect themselves in such a way, so I get why the browser is attempting to protect them. Just seems very wrong to me to take the control away from the user/network-admi…

> Delete HTTP from the browser entirely, right? It’s not being deleted , but Chrome at least has been gradually phasing in a warning in the address bar whenever you visit an HTTP site. [1] (Firefox will apparently do the same starting soon.) I wouldn’t be surprised if the warning UIs get more aggressive a few years down the line, as HTTPS adoption continues to increase. [1] https://blog.chromium.org/2018/05/evolving-…

Firefox currently shows a red crossed out padlock for HTTP sites with form elements, but not yet for HTTP sites without form elements which for now get neutral treatment. The rationale is that you definitely shouldn't be using insecure forms, what could you possibly be writing where you really don't care about at least confidentiality (to prevent eavesdroppers from reading it) or integrity (to prevent a MitM from changing it) ?

If you set HSTS and then subsequently remove HTTPS from a site it should (will for Firefox, kind of for Chrome) brick wall you, saying that it isn't able to reach the HTTPS site without offering to let you see the insecure and perhaps compromised HTTP site even if you spell out the HTTP URL.

Unlike HPKP this isn't considered a foot gun because you can fix it by just enabling HTTPS, and why didn't you have HTTPS anyway?

The biggest forward pressure for HTTPS is that newer protocol versions (after HTTP/1.1) do not in practice exist for plain HTTP. The way to do plain HTTP/2 is documented but nobody has plans to implement it, and there isn't even intent to document a plain HTTP/3 because the stuff it's built on is all encrypted from the ground up. From my point of view this is good news.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#304

Earlier quoted context omitted.

I question the amount that such ethics courses actually help. Business majors have had ethics courses for as long as I can imagine, and yet you don't have to go far on HN (even in this very thread) before you see people saying business majors are unethical. The bigger problem, IMO, is that many tech companies have started handing out kool-aid that data collection and analytics is ethical. They justify it by saying th…

> Business majors have had ethics courses for as long as I can imagine I took a business ethics course in undergrad, and it was surprising how many students advocated all sorts of (to me) aberrant ethical views. (Note I’m pretty traditional, morally speaking. The environment was strongly postmodern, and this was before all the modern insanity about “free speech is bad because some people say bad/offensive things”.) N…

Most nations besides the US don't subscribe to an unlimited right to speech. Hell, the US doesn't subscribe to an unlimited right to speech.

Should I be allowed to say that I think you should die for the opinion you just espoused? That is probably not a legal statement for me to make under the US principles of free speech.

Should you be allowed to say that you think I should die for my genetics or the social group that I am born into?

Glad we've agreed that while free speech isn't bad because some people say bad things, that doesn't mean that all free speech should be legal, either.

As we've thus agreed, we can absolutely restrict certain categories of speech without diminishing the actual social value of free discourse.

This idea is entirely uncontroversial in every single developed country except for the US. Nobody else thinks that "well I just want to murder all the jews but you want to suppress free discourse, looks like you have some growing up to do" is a valid position for people to take.

No, that's not polite to say, but that's where your argument ends up, and that's really the entire purpose of that argument. Otherwise - what arguments exactly do you feel could not legally be expressed in a modern first-world democracy, that actually should be expressed?

This argument literally, always comes down to someone who argues that "well I don't actually (openly) support Nazis marching in the streets, but I don't think they should be legally suppressed from expressing their desire to murder an entire race of human beings". Again, otherwise, be glad to hear what exactly you think you think people have a problem with that is legally suppressed in the communist state of Germany or Sweden in 2019.

The reality is that the laws are always interpreted by humans and a huge amount of deference is given to free speech in all but the most explicit cases. Yes, if the system becomes corrupted we have a problem, but that's literally always the case even with an unlimited right to free speech. There is no slippery slope here unless things go completely off the rails, and things can always go completely off the rails under any system.

We really, actually, can just ban the Nazis marching in the streets without everything magically turning into a dystopia. Germany has done it for 75 years.

I realize you probably think I'm overreacting because this idea always went over well at your college smokeouts, but I'm under no obligation to sugar coat this for you, I'm just being blunt: this is an occasion when your opinion is trite and shallow and you really should re-think the consequences, because it's entirely possible that your opinion gets people killed over the next decade. You're not Atticus Finch for white-knighting the right of Nazis to express hate speech.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#305
post #291
post #176

Earlier quoted context omitted.

What about 8.8.8.8? I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.

If you are not using gmail and google search, and are using adblockers, Google shouldn’t really have any information on your IP, so it is anonymised data. Your ISP knows even your bank details. But the limits of using google DNS (or even encrypted DNS) is that most commercial websites aren’t sharing IP addresses, so I bet the ISP can pretty much reconstruct the data it would get from DNS with very little effort just…

> Your ISP knows even your bank details.

Google was buying MasterCard records: https://www.bloomberg.com/news/articles/2018-08-30/google-an...

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#307

Earlier quoted context omitted.

> Perhaps because downloading Tor (or even searching for it / visiting its website) demonstrates an active interest in thwarting surveillance. Not if you access tor over VPN. VPN hides all traffic from ISP and Gov. Obviously, make sure your browser does not use Google or Cloudflare DNS.

VPN hides all traffic from ISP and Gov. VPN like... Onavo?

Very funny :)

No, VPN like AirVPN, IVPN, Mullvad or PIA.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#308
In the land where GDPR exists, I can see why ISPs are a little annoyed.

Directing users to local CDN instances has now got harder, which means its going to cost more for things like netflix

In the US, yes, that means that ISP can't mine youre data, however, you are handing more information to google.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#309
post #31

I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility tho…

If you're on a mainstream US ISP, interference from your browser with your ISP's "network level operations" is a privacy necessity. They're passively monitoring DNS to collect data on their customers and hijacking it to send users to advertising sites. ISP DNS is manifestly untrustworthy.

There is a difference between not respecting ISP supplied DNS and not respecting DHCP supplied DNS.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#310
post #53

Earlier quoted context omitted.

Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.) I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.

DNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements. So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any c…

_with_ DoH you are passing not just network information, but session information as well.

DoH is not a privacy boon.

DNS, whilst plaintext is at least federated, and is a network level service. That is, its not tied to a single session in a browser.

as I understand it, there is nothing stopping a browser from appending metadata to the get request, or putting extra headers in. This means that its perfectly possible to nail your complete browsing history, down to the server you've been given.

Post reply on HN