Live data from Hacker News

Big ISPs aren’t happy about Google’s plans for encrypted DNS

arstechnica.com

451–456 of 456 posts

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#451

Earlier quoted context omitted.

> How does DNSSEC at the roots actually protect you from an attacker manipulating DNS? Assuming that is the question you mean... it works by not allowing the attackers to take the easy course of hijacking all DNS queries and answering how they like. Instead they have to inspect each packet and only hijack those they can, which is a lot harder to do. So it is raising the bar in hope of raising it high enough that it i…

You're not following me. What you're saying is the "easy course" is neither easy nor the normal way DNS hijacking occurs. DNS hijacking typically starts with a target domain.

How do they pick out the target domain without packet inspecting all your DNS traffic?

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#452
post #426

Earlier quoted context omitted.

I read the argument and then re-read it. Went through few odd stages of amusement and I still disagree. Defending Nazi right to express free speech is more necessary now than ever given that people apparently forgot what an important right it is. As for the argument that, opinion gets people killed, I can only reply with the following. Opinions don't kill people. People kill people. It is important to know the differ…

I totally agree, nuclear bombs don't kill people, people kill people. There is no reason people should be unable to build their own weapons and bombs. And don't even start with the WMD slippery slope. More seriously, limiting speech should not be necessary in a good society were people don't let such stuff spread. But that doesn't seem to be how humans work. The marketplace of ideas does not necessarily prevent bad o…

It is a good argument. It sounds reasonable. But having 'reasonable rules' is a vague statement. It is something akin to me saying in a corporate meeting 'it is all about balance'.It is and it conveniently can be applied to anything.

For the record, I personally dislike German approach despite understanding its genesis.

I can't really speak for aerospace rules, but I am not certain they say that much about speech.

edit. I just remembered. Internet has all manner of rather dangerous information out there. Materials may be highly difficult to procure, but knowledge is still at your fingertips.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#453

Earlier quoted context omitted.

You're not following me. What you're saying is the "easy course" is neither easy nor the normal way DNS hijacking occurs. DNS hijacking typically starts with a target domain.

How do they pick out the target domain without packet inspecting all your DNS traffic?

If they were "packet inspecting all your DNS traffic", DNSSEC wouldn't matter to begin with, because it's a server-to-server protocol; your browser's resolver can't cryptographically verify anything. But that's not in fact what's happening.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#454

Earlier quoted context omitted.

How do they pick out the target domain without packet inspecting all your DNS traffic?

If they were "packet inspecting all your DNS traffic", DNSSEC wouldn't matter to begin with, because it's a server-to-server protocol; your browser's resolver can't cryptographically verify anything. But that's not in fact what's happening.

But we are specifically talking a using a recursive resolver communicating with the root servers, server-to-server. The browser only comes into play here as a client to the local resolver. The original context was about a pi-hole running a recursive resolver directly against the root servers instead of the ISP's.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#455
post #395

I guess everyone who cares about privacy should run his own DNS server/cache somewhere on the internet. Same as mail, really.

How does that help at all? You're upstream DNS requests would still be unencrypted when they are forwarded to the root servers.

The upstream DNS requests to the authorative DNS servers are unavoidable at the moment so you achieve a minimum of privacy invasion.

Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS

#456
post #410
post #280

Earlier quoted context omitted.

I don't think anyone is arguing that there's no reason for an ISP to serve DNS.

> There is no actual technical reason why they should care if you use their DNS servers or something else, even a private, encrypted DNS service. That’s the part of your comment I am replying to. Anyway I see you’re arguing ISPs shouldn’t care which provider you use, not that they shouldn’t want to default you to running their own. Perhaps I misunderstood your point. Regardless I’d argue the problem in the us is that…

Your reply was:

> But to say there is no reason for an ISP to serve DNS is absurd.

The part of my comment that you quoted does not at all say that. (In fact, no part of my comment says, or even suggest, that.)

I agree that any DNS provider can abuse your data, but it's important to look at incentives. Comcast doesn't care one bit about its public image because it already has a terrible one, but customers have no choice in the matter, so Comcast's public image is mostly irrelevant.

Several DoH providers bill themselves as privacy-focused, and make privacy a big point in their marketing around their DNS service. Violating that privacy would be damaging to their product and reputation, in a way that they'd likely care quite a bit about.

I'd rather just have my local resolver have a list of 5 or so DNS providers with reasonably low-latency presence in my area (possibly including the local ISP, even, who knows), and just round-robin requests to them. There's really no way to make DNS not an "open book" as you put it; you can't ask someone to resolve a hostname for you without telling them what the hostname is.

So yes, we need ways to mitigate harm. Unless a provider has their reputation on the line, I don't really see a way to keep providers from doing sketchy things with your data, at least not without legal regulation. It's not like things like the EU's GDPR and California's CCPA were dreamed out of nothing; they came about because people have started to realize that companies just will not act as good stewards of our data unless we legally mandate toothy financial consequences as punishment.

Post reply on HN