Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

381–390 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#381

Earlier quoted context omitted.

> DNS-level routing and load balancing How do you mean? Why should my ISPs hijack communication between me and a content provider and reroute it? This is as if I'm in a phone meeting and when I say "let me call you back at 15:00" the phone company injects "19:00" instead, because that's a time the phone network is less loaded so it'd help them. > NAT64 embedding ipv4 addresses into ipv6 ones NAT64 is a good point, ac…

Some authoritative DNS servers may respond with incorrect IP addresses for specific IP subnets of an ISP (i.e. pointing to unreachable or slow far away servers), so it could be useful to fix this either statically or by forwarding domains to another DNS resolver which gets proper responses. Things like that.

My experience is that things like that will obviously break more than it fixes. One cannot assume to know better between two third parties like that.

Half of global loadbalancing is getting around ISPs doing stupid shit they shouldn't have been messing with.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#382

Earlier quoted context omitted.

What do you mean? There's a whole genre of reasonably talented morally bankrupt "whitehats" building passivedns mass surveillance infrastructure. Cisco collects more than 24TB of DNS query data every day. Here's a Cisco employee demonstrating the kinds of horrifying analytics they perform on this data https://www.first.org/resources/papers/conf2018/Mahjoub-Dhia...

Wow, that is amazing. Is Cisco telling their clients they're doing this? That's a lot of root servers too.

This surveillance is mostly targeted at residential users. I’m sure they mention this in some opendns legalese, but they definitely don’t openly advertise this.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#383

I am a bit stuck here. I know it is a bit insane, but I run a simple system at home because I think, so if I drop dead tomorrow how is my wife going to sort this. If I am dead, internet still needs to work so my kid can do her home work. So despite my geek love, I do not run my own DNS, etc. the other part is I use unblock-us so iPlayer (BBC) works here in the US. I would love to set everything up so everything is en…

Setup a seperate SSID called "DadDied" with a simple password, scrawl it onto the fridge door with a knife. Have this SSID give out standard ISP DNS. Bonus points if you setup the SSID on the ISP supplied router, bypassing all the equipment you installed behind it.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#384

I am a bit stuck here. I know it is a bit insane, but I run a simple system at home because I think, so if I drop dead tomorrow how is my wife going to sort this. If I am dead, internet still needs to work so my kid can do her home work. So despite my geek love, I do not run my own DNS, etc. the other part is I use unblock-us so iPlayer (BBC) works here in the US. I would love to set everything up so everything is en…

That sounds backwards. You sure that will be their biggest concern if you drop dead? They can always throw out your weird techy stuff and buy some cheap commodity solution and get them installed. Your reasoning sounds like, I'm not going to do breakfast for my family, because, ya know, if I drop dead, they will miss the breakfasts.

> You sure that will be their biggest concern if you drop dead?

That it's not their biggest concern doesn't mean that it won't be a concern, nor did it mean that it's not something he can avoid becoming a concern.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#385

Earlier quoted context omitted.

>Firefox, on the other hand, plans to force all of their users to trust Cloudflare by default.. and most users won't even know they made that change. Mozilla has explicitly stated on their blog that they don't intend to make any change to a user's DNS settings without getting the user's consent. >When DoH is enabled, users will be notified and given the opportunity to opt out https://blog.mozilla.org/futurereleases/2…

The problem is it’s just a banner with “ok” at the top, which clearly says “we’ve increased your privacy by (insert technical jumbo jumbo here).” As Bert Hubert pointed out, to most users it ends up looking like this: https://twitter.com/powerdns_bert/status/1123666707279695874...

So? It's clearly beneficial for the average user.

As long as the people who don't want it can easily opt out, I'm not seeing the problem.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#386
post #312

Earlier quoted context omitted.

Netflow data, DNS capture, enrichment of cell tower access data (location), reporting on non-usage (idle time, tracking), Bill and household information, credit account usage, etc. SPs are huge sellers in this market. We still need to encrypt the accessed resource and DNS queries everywhere. Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.

As a European it baffles me that this is normal in the USA. Why is this even legal? This should be PII.

This is definitely happening in Europe. It's not like you get to opt-in to these things

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#387
post #40
post #15

While I don't particularly trust Google all that much anymore, the fact that ISPs even have an opinion on this is a smoking gun that they're doing sketchy things with DNS data. There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service.

They definitely are. I know for a fact that they are running massive Hadoop clusters storing information on DNS records involved in their customer traffic. If I recall correctly they mirror a lot of the traffic to analytics environments.

In the mid 2000s it was common that several large broadband isps would have folks on their DNS team selling DNS traffic data under the table to people engaging in domain tasting and other things. It was only a matter of time until the isps realized they could wet their beak with the same info.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#388
post #312

Earlier quoted context omitted.

Netflow data, DNS capture, enrichment of cell tower access data (location), reporting on non-usage (idle time, tracking), Bill and household information, credit account usage, etc. SPs are huge sellers in this market. We still need to encrypt the accessed resource and DNS queries everywhere. Even once that’s done, things like opencaching will be used by SPs to gather tons of data where they participate.

As a European it baffles me that this is normal in the USA. Why is this even legal? This should be PII.

Because our government is not really interested in protecting its citizens from abuse at the hands of corporations.

edit: you can see this clearly in the way they pay lip service to "breaking up big tech" (whether or not that's a good idea, this comment is not a statement of opinion on that subject) because it's politically sexy on both sides, while all these other, arguably more egregious abuses of consumer data are so far off the radar that most people probably aren't aware they're happening.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#389
post #335

Earlier quoted context omitted.

Why would you fear ISPs offering an encrypted service? It’s hardly a step backwards? DoT would be preferable to DoH (no additional metadata / cookies,) but either way ISPs should adopt encrypted DNS. You are correct it boils down to “who you trust.” In my country the ISP wins hands down over a foreign mega-corp so I end up making a different decision to you. The key thing is that is a choice for users, not something…

Because DoH is supposed to hide the DNS traffic from ISPs (among others). Sending the DNS traffic straight to the ISP defeats the purpose of it. That's like MITM on the first hop.

But the default state is to use the dns provided by your isp so nothing really changes.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#390
There have been several articles in the past few days whinging about both mozilla and chrome incorporating DNS over TLS. Someone seems to be REALLY unhappy about this and those people seem to be trying to use the press as a microphone.

It seems like it's touching a nerve and advertisers and governments are really sweating losing their ability do low effort snooping.

Post reply on HN