Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

341–350 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#341
post #304

Earlier quoted context omitted.

> Business majors have had ethics courses for as long as I can imagine I took a business ethics course in undergrad, and it was surprising how many students advocated all sorts of (to me) aberrant ethical views. (Note I’m pretty traditional, morally speaking. The environment was strongly postmodern, and this was before all the modern insanity about “free speech is bad because some people say bad/offensive things”.) N…

Most nations besides the US don't subscribe to an unlimited right to speech. Hell, the US doesn't subscribe to an unlimited right to speech. Should I be allowed to say that I think you should die for the opinion you just espoused? That is probably not a legal statement for me to make under the US principles of free speech. Should you be allowed to say that you think I should die for my genetics or the social group th…

Impartial view here, not entirely sure where I fall on free speech:

You've concluded that the absolute morality expressed by public consciousness should be the arbiter of publicly expressible speech. Maybe the next thing that gets people killed is not allowing public discourse to challenge socially accepted, morally unacceptable beliefs.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#342

Earlier quoted context omitted.

How do you know this fact?

I worked for a Comcast subsidiary in 2010-2011 timeframe. The company owned the network end to end. They had about 250k subscribers at the time across 4 states and at the time was the first DOCIS 3.0 network in the US. They were collecting DNS log data back then. I've been told that hasn't stopped and has progressed. Don't trust your ISP to not be passively monitoring. This particular ISP had closets full of old Sand…

Thanks for the explanation. I was curious about some more specifics:

- How was the DNS logged?

- Was every query logged, or only unique queries?

- Was it combined with other data?

- How long was it searchable for?

- What were the DNS queries used for? Simply sold to 3rd parties? If so, who was buying?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#343

Earlier quoted context omitted.

You don't need to just blindly trust, there are ToS and privacy statements. My TL;DR is that Google doesn't use logs outside of service health (eg vs DDoS).

So what pays for this service?

I don't know. I think not everything a large company does necessarily immediately pays for itself. Also, Google overall benefits when people use the web more.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#344
post #317
post #316

Earlier quoted context omitted.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

of course: dnsleaktest.com

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#345

Earlier quoted context omitted.

I find it interesting that Google and CloudFlare are now the scapegoats. I mean, it's not like DoH isn't configurable and we don't have a choice.

Not attacking Google - their approach here is fine. But Mozilla switching people is a worry for me. Sure people “have a choice” but in reality expecting the average Joe who doesn’t even know what DNS is to make an informed decision about it is unrealistic. Meanwhile Mozilla has started sending a list of every domain you visit to a US company subject to US law enforcement. Not ideal.

>Meanwhile Mozilla has started sending a list of every domain you visit to a US company subject to US law enforcement. Not ideal.

Do you have an article which explains this?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#346
post #317
post #316

Earlier quoted context omitted.

Here in the UK sky recently pushed out an update to their firmware which made it impossible to use another DNS server other than theirs. There was a decent amount of push back, I managed to get them to downgrade my firmware but who knows how long that will last before they "accidently" update it again.

What's the best way to tell if they're intercepting queries to other dns servers and replying themselves? Say I manually set my dns to 1.1.1.1, is there a way to tell if the replies are really from 1.1.1.1?

I noticed they were doing this when I saw that in-band DNS updates were failing. Eventually I realied that my router (or something upstream of it) was returning an error to the client rather than passing through the GSS-TSIG-signed nsupdate packet.

So far I have been unsuccessful in my attempts to get through to a technician who knows anything other than "try turning it on and off again". I suspect this policy is deliberate.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#347
post #176

Earlier quoted context omitted.

What about 8.8.8.8? I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.

I think google is evil. But I know AT&T is.

Big G is driven by money like any other company, but they lose more money if they don't employ top security practices and prevent others from getting their data. ATT's main business isn't selling the data, it's selling the pipes that carry data, so security on their data lakes is probably less of a priority.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#348
post #312

Earlier quoted context omitted.

Netflow data, DNS capture, enrichment of cell tower access data (location), reporting on non-usage (idle time, tracking), Bill and household information, credit account usage, etc. SPs are huge sellers in this market. We still need to encrypt the accessed resource and DNS queries everywhere. Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.

As a European it baffles me that this is normal in the USA. Why is this even legal? This should be PII.

Wholesale data collection has become normalized in the US. For-profits, non-profits, it doesn't matter the industry, everyone is obsessed with capturing as much data as possible and believe it's just the standard way of business. No one outside of HN cares about PII or has an understanding of things like GDPR (it's just for the Europeans). Consumers are clueless or otherwise feel hopeless.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#350

> the company has no plans to switch Chrome users to its own DNS servers. Meanwhile, the Chromecast inexplicably ignores DHCP/NDP-provided DNS servers and uses 8.8.8.8 for all queries.

When this came up on hn before someone from Google said it was because they'd had problems with malformed responses from other DNS providers.
Post reply on HN