Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

361–370 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#361
post #357

Earlier quoted context omitted.

Wholesale data collection has become normalized in the US. For-profits, non-profits, it doesn't matter the industry, everyone is obsessed with capturing as much data as possible and believe it's just the standard way of business. No one outside of HN cares about PII or has an understanding of things like GDPR (it's just for the Europeans). Consumers are clueless or otherwise feel hopeless.

Just want to say for the sake of others reading that this comment is exaggerating + generalizing a bit. Everyone is not obsessed with turning data into revenue. Most smaller tech companies (ie. Sub billions in revenue) are not in the game of monetizing data. My feeling is the market exists mostly between very well establish and very large companies (such as ISPs, advertising networks), but that same market doesn’t ex…

Everyone in the EU has heard of it, at least for the fact that everyone received a whole bunch of email that mentioned it on May 25th 2018. I'd say a lot of people know that "it's about privacy"; the actual understanding obviously varies.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#362
post #357

Earlier quoted context omitted.

Wholesale data collection has become normalized in the US. For-profits, non-profits, it doesn't matter the industry, everyone is obsessed with capturing as much data as possible and believe it's just the standard way of business. No one outside of HN cares about PII or has an understanding of things like GDPR (it's just for the Europeans). Consumers are clueless or otherwise feel hopeless.

Just want to say for the sake of others reading that this comment is exaggerating + generalizing a bit. Everyone is not obsessed with turning data into revenue. Most smaller tech companies (ie. Sub billions in revenue) are not in the game of monetizing data. My feeling is the market exists mostly between very well establish and very large companies (such as ISPs, advertising networks), but that same market doesn’t ex…

No one heard about it, at least in Spain. My father asked me about it because he heard it on the news, but I'd say that 99% of my non-tech friends have no idea of what it is about. Anyway, I work for a large telco and they are very paranoid liabilities involving data. It's a behemoth, so you wouldn't expect them to be this careful.

As far as I remember, they still sell some anonymized data (they had some demos on how to plan public transport with location data) and I'd bet they are not doing much with DNS data.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#363

What I fear will happen in several years is that local ISPs will also begin offering DoH by default (if you can't beat the competition, join them) and continue snooping on your traffic, just like Google or Cloudflare could do now technically, if they wanted to. Ultimately this boils down to which entity you trust more, your ISP or some other provider. Today Google/Cloudflare et al are by far the more trustworthy opti…

Why would you fear ISPs offering an encrypted service? It’s hardly a step backwards? DoT would be preferable to DoH (no additional metadata / cookies,) but either way ISPs should adopt encrypted DNS. You are correct it boils down to “who you trust.” In my country the ISP wins hands down over a foreign mega-corp so I end up making a different decision to you. The key thing is that is a choice for users, not something…

> Why would you fear ISPs offering an encrypted service?

encryption doesn't hide anything from whoever's on the other side, just the people in the middle. If the goal is to not let ISPs in on your DNS history, then DoH to the ISP won't do that.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#364
post #304

Earlier quoted context omitted.

> Business majors have had ethics courses for as long as I can imagine I took a business ethics course in undergrad, and it was surprising how many students advocated all sorts of (to me) aberrant ethical views. (Note I’m pretty traditional, morally speaking. The environment was strongly postmodern, and this was before all the modern insanity about “free speech is bad because some people say bad/offensive things”.) N…

Most nations besides the US don't subscribe to an unlimited right to speech. Hell, the US doesn't subscribe to an unlimited right to speech. Should I be allowed to say that I think you should die for the opinion you just espoused? That is probably not a legal statement for me to make under the US principles of free speech. Should you be allowed to say that you think I should die for my genetics or the social group th…

I read the argument and then re-read it. Went through few odd stages of amusement and I still disagree. Defending Nazi right to express free speech is more necessary now than ever given that people apparently forgot what an important right it is.

As for the argument that, opinion gets people killed, I can only reply with the following.

Opinions don't kill people. People kill people. It is important to know the difference.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#365

Earlier quoted context omitted.

So if VPN over Tor (or Tor over VPN) increases anonymity then why is it the popular advice on the Net is not to do it?

Perhaps because downloading Tor (or even searching for it / visiting its website) demonstrates an active interest in thwarting surveillance. Almost by definition, that means you're worth taking a closer look at. Once you're under the microscope, you'd better hope your opsec is flawless or that your activities are completely boring, or else the $TLA knows exactly what you've been up to, TOR or not. Disclosure: my acti…

That's why more people should use it. You can't take a closer look at everyone.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#366
post #53

Earlier quoted context omitted.

Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.) I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.

DNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements. So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any c…

You can use a personal installation of dnscrypt-proxy which supports both dnscrypt and DoH and allows you to select multiple providers. It even supports round-robin. This is what I'm doing.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#367
post #87

Earlier quoted context omitted.

This is a pretty silly debate. All you have to do is look at AT&T's DNS, see it hijack NXDOMAIN to send you to ad sites, and know that mainstream ISP DNS isn't trustworthy. We don't need to weigh up counterfactuals.

I think the missing piece here is the constant focus on the US. In Europe ISPs are under much stricter rules about data privacy and generally cannot do things like the above. Having worked for several ISPs here I’ve never found them misusing DNS data (although sometimes it was logged for a time for management / troubleshooting.) For a European; with reasonable trust in my ISP, I don’t want Mozilla sending all my quer…

Wouldn't the US company resolver be based in the EU though and subject to EU Law? That would have to be the case without the DNS resolver having ridiculously slow DNS query times.

I don't think the US govt can ask for data present/originated from the EU.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#368
post #176

Earlier quoted context omitted.

What about 8.8.8.8? I'm guessing we're just trusting Google here (and Cloudflare 1.1.1.1 who now also does 10gb free VPNs) + the good will of engineers with access to this information within Google.

You don't need to just blindly trust, there are ToS and privacy statements. My TL;DR is that Google doesn't use logs outside of service health (eg vs DDoS).

For reference: https://developers.google.com/speed/public-dns/privacy

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#370

> the company has no plans to switch Chrome users to its own DNS servers. Meanwhile, the Chromecast inexplicably ignores DHCP/NDP-provided DNS servers and uses 8.8.8.8 for all queries.

Even worse - it will disable itself if it cannot connect to 8.8.8.8. https://news.ycombinator.com/item?id=19170671

I don't think that's true anymore. I've blocked my Chromecasts accessing Google's DNS servers and then just fall back to the ones from DHCP.
Post reply on HN