Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

321–330 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#321
post #316
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

I use Sky. I wasn't aware of this. :(

I also use my own router so I assume it doesn't affect me or does this mean that their network doesn't allow other DNS servers?

How would that affect a VPN? I use PIA and they have their own DNS servers.

I'll need to experiment with this when I get home I think.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#322

Earlier quoted context omitted.

Everything warrants skepticism until proven otherwise. Especially things that are being given out for free. Google might be operating on the up and up, but Google is just a large collection of people and some of them will be ethically lacking. And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists.

Disclaimer: I work at Google. > And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists. I can only speak from personal experience. But I would not agree. Collection of data needs to be covered in a privacy document. You must argue why you're collecting it. There has to be a retention plan, such that data is purged when the user account is deleted,…

> The paperwork is a strong incentive to avoid keeping data you don't need.

The paperwork is a modest incentive to avoid keeping data Google doesn't need. The problem is that what people need is not necessarily the same as what Google's surveillance and manipulation profit machine needs.

I don't need Google to keep a hyper-detailed record of every site I visit, but Google's business model means that they "need" to do it. So they do.

>> And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists.

You see, Googlers are incentivized not to see the ethical catastrophe that is collecting the data they "need" to collect in order to implement and enhance Google's surveillance and manipulation profit machine.

Sure, if some data are irrelevant to the surveillance and manipulation profit machine, there is a modest incentive not to collect those data. The problem is that Google "needs" a great deal of highly personal, sensitive data whose aggregation poses societal risks that can hardly be overstated. But, since Google--and therefore, Googlers' salaries, bonuses, and RSU gains--"needs" those data, Googlers are incentivized to rationalize its collection, aggregation, and exploitation.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#323
post #317
post #316

Earlier quoted context omitted.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

An NSLOOKUP will tell you the DNS server that your query went to.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#324
post #237

How exactly encrypted DNS will reduce spying? ISPs will still be able to observe IP addresses users connect to and even particular host names in SSL handshakes.

Due to shared hosting you can't map every IP to a hostname, and encrypted SNI is a thing.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#325
post #317
post #316

Earlier quoted context omitted.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

[deleted]

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#326
post #316
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

> which made it impossible to use another DNS server other than theirs

'cause DNS logs & users data brings them good money, so they just defends business.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#327
post #317

Earlier quoted context omitted.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

An NSLOOKUP will tell you the DNS server that your query went to.

[deleted]

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#328
post #317
post #316

Earlier quoted context omitted.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

If it is not "encrypted" (with some form of end-to-end encryption, like HTTPS or SSH), you dont.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#329
post #317

Earlier quoted context omitted.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

An NSLOOKUP will tell you the DNS server that your query went to.

ISPs can man-in-the-middle spoof that too, right?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#330
post #317

Earlier quoted context omitted.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

An NSLOOKUP will tell you the DNS server that your query went to.

Even if you intercept and nat traffic going to UDP/53?
Post reply on HN