Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

371–380 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#371
post #53

Earlier quoted context omitted.

DNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements. So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any c…

I encountered this in a local ISP in India in 2012: they were intercepting all DNS requests and forcibly using OpenDNS’s annoying NXDOMAIN advertising thing. When I returned in 2016 they’d stopped doing that. No idea if the technique is widespread.

Indian ISPs have intercepted HTTPS traffic to inject ads [0]. And DPI is now a thing among Indian ISPs.

[0] https://news.ycombinator.com/item?id=12091900

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#372
post #357

Earlier quoted context omitted.

Wholesale data collection has become normalized in the US. For-profits, non-profits, it doesn't matter the industry, everyone is obsessed with capturing as much data as possible and believe it's just the standard way of business. No one outside of HN cares about PII or has an understanding of things like GDPR (it's just for the Europeans). Consumers are clueless or otherwise feel hopeless.

Just want to say for the sake of others reading that this comment is exaggerating + generalizing a bit. Everyone is not obsessed with turning data into revenue. Most smaller tech companies (ie. Sub billions in revenue) are not in the game of monetizing data. My feeling is the market exists mostly between very well establish and very large companies (such as ISPs, advertising networks), but that same market doesn’t ex…

> To anyone in the EU: is GDPR something that your non-technical friend will have heard of and knows what it is? Or is it similar to the US, where 75% of people probably haven’t heard of it or if they have, couldn’t say what the regulation does.

Basically everyone who is in EU needs to keep GDPR in mind. Especially if you are employed, then you need to keep in mind GDPR for the interests of your employer so that they are abiding the law, and won't get fined. It is actually legal people who know GDPR very well; not so much tech people. In a lot of Dutch companies a "functionaris gegevensbescherming" (FG; data protection officer) is mandatory, who basically deal with PII, and have known about GDPR (AVG) ever since it was announced it was going to be active (2 years before it was active). The Dutch professional association for the data protection officer was founded in 2003 [1].

On top of that, it was widely covered in newspapers, daily news, etc. If you are in EU and you have not heard about it you are living under a rock, or you're not a working adult (nothing wrong with either).

[1] https://www.ngfg.nl

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#373

Earlier quoted context omitted.

I think google is evil. But I know AT&T is.

Big G is driven by money like any other company, but they lose more money if they don't employ top security practices and prevent others from getting their data. ATT's main business isn't selling the data, it's selling the pipes that carry data, so security on their data lakes is probably less of a priority.

> ATT's main business isn't selling the data, it's selling the pipes that carry data

... and I'm sure their shareholders are pressing them to forego the greater revenue from subscriber data so they can keep their dividend cheques comfortably small.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#374
post #357

Earlier quoted context omitted.

Wholesale data collection has become normalized in the US. For-profits, non-profits, it doesn't matter the industry, everyone is obsessed with capturing as much data as possible and believe it's just the standard way of business. No one outside of HN cares about PII or has an understanding of things like GDPR (it's just for the Europeans). Consumers are clueless or otherwise feel hopeless.

Just want to say for the sake of others reading that this comment is exaggerating + generalizing a bit. Everyone is not obsessed with turning data into revenue. Most smaller tech companies (ie. Sub billions in revenue) are not in the game of monetizing data. My feeling is the market exists mostly between very well establish and very large companies (such as ISPs, advertising networks), but that same market doesn’t ex…

Anyone working in an office will have probably come in contact with GDPR. Blue collar workers probably not so much.

Maybe people will know it as the cause of cookie popup screens. But I'm also grossly over-estimating computer literacy among the general population so maybe not.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#375

Earlier quoted context omitted.

> Business majors have had ethics courses for as long as I can imagine I took a business ethics course in undergrad, and it was surprising how many students advocated all sorts of (to me) aberrant ethical views. (Note I’m pretty traditional, morally speaking. The environment was strongly postmodern, and this was before all the modern insanity about “free speech is bad because some people say bad/offensive things”.) N…

> this was before all the modern insanity about “free speech is bad because some people say bad/offensive things”.) To be totally fair, the idea "free speech is bad because some people say bad things" is older than the mind of man can remember.

> To be totally fair, the idea "free speech is bad because some people say bad things" is older than the mind of man can remember.

Yes, it's just that we've only recently been allowed to talk about it openly.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#376
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

It used to be illegal for ISPs to use web browsing data for advertising purposes but the Republican House, Senate and President passed a law allowing them to make it an opt-out. https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

[deleted]

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#377
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

It used to be illegal for ISPs to use web browsing data for advertising purposes but the Republican House, Senate and President passed a law allowing them to make it an opt-out. https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

Good article, but no link or details on how to actually opt-out?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#378
post #233
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

I worked at a couple of major telcos at my country, and at the last one - where we had literally millions of active ISP and mobile users - we were approached by a company willing to pay for DNS resolver data. It is definitely a thing (and possible income source) even if you don’t do that kind of analytics yourself. But I’m fascinated by the legal implications. Right now in Portugal sites are DNS-blocked for copyright…

I'm living in Kazakhstan which blocks some websites. Also Russia blocks a lot of websites. I can't wait to see how eSNI will play out with all those blocks, if Cloudflare and other big networks will dare to roll it out.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#379
post #356
post #312

Earlier quoted context omitted.

As a European it baffles me that this is normal in the USA. Why is this even legal? This should be PII.

Who says it's not also happening in Europe?

If it is, the stakes are much higher since they have real penalties if they fail to disclose the practice or lose control of that data. Anyone in the EU can send them a request under the GDPR to learn what’s collected, so it’s much easier to get caught.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#380
post #357

Earlier quoted context omitted.

Wholesale data collection has become normalized in the US. For-profits, non-profits, it doesn't matter the industry, everyone is obsessed with capturing as much data as possible and believe it's just the standard way of business. No one outside of HN cares about PII or has an understanding of things like GDPR (it's just for the Europeans). Consumers are clueless or otherwise feel hopeless.

Just want to say for the sake of others reading that this comment is exaggerating + generalizing a bit. Everyone is not obsessed with turning data into revenue. Most smaller tech companies (ie. Sub billions in revenue) are not in the game of monetizing data. My feeling is the market exists mostly between very well establish and very large companies (such as ISPs, advertising networks), but that same market doesn’t ex…

Anyone in the UK who does an office job has heard of GDPR. Most companies are having to update practices to comply with it. It's actually amazing how effective it's been at curbing the "let's just store everything" behaviour.
Post reply on HN