Mozilla’s DNS over HTTPs
blog.mozilla.org
Mozilla’s DNS over HTTPs
1–10 of 777 posts
Re: Mozilla’s DNS over HTTPs
#21. Isn't this better implemented at the OS level?
2. Isn't centralisation to two DoH providers more centralised than five large ISPs?
Others are probably better suited to answer, but the answers I can think of:
1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this problem at some point in the future, Firefox can always be changed again to use that.
2. Given that Firefox doesn't own the full market, the net result is indeed less centralisation: five ISPs that handle traffic by other browsers, and two DoH providers that handle Firefox's. That said, the main factor here is that the track record of ISPs in the US is abysmal, whereas the current (and hopefully potential future other ones) DoH providers have committed to far stronger privacy protections.
Re: Mozilla’s DNS over HTTPs
#3DNS is the primary way governments control and spy on web access.
Re: Mozilla’s DNS over HTTPs
#4I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…
Re: Mozilla’s DNS over HTTPs
#5People don’t take issue with DoH, they take issue with an advertising supported browser like Mozilla’s unicast (and now bicast) centralization of DNS traffic that was previously distributed.
We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization.
They make this about DoH when really the primary issues are with how they went about it.
Re: Mozilla’s DNS over HTTPs
#6I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…
Optional for menu icon:
https://getbitbar.com/ and https://github.com/jedisct1/bitbar-dnscrypt-proxy-switcher
Re: Mozilla’s DNS over HTTPs
#7Doth protest too much. People don’t take issue with DoH, they take issue with an advertising supported browser like Mozilla’s unicast (and now bicast) centralization of DNS traffic that was previously distributed. We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization. They make this about DoH when really the primary issues are with how they went about it.
Ummm so what’s the downside then? Are those services arcane and hard to use and utterly forbidding blackest black magic, like almost all crypto stuff?
If you’re thinking browser users will just do this then that then this and x and y and z to “get dns crypto going”, then I’ll take Mozilla’s “it just works” approach.
It’s a much much better approach for the browsers to implement it rather than wait for everyone’s operating system to implement secure dns because that’ll happen .... well I can’t imagine any time in the future you could say everyone’s OS is using crypto DNS, whereas if browsers implement it for themselves, instant massive adoption.
Re: Mozilla’s DNS over HTTPs
#8Why are people so down on DNS over HTTPS? DNS is the primary way governments control and spy on web access.
Re: Mozilla’s DNS over HTTPs
#9Why are people so down on DNS over HTTPS? DNS is the primary way governments control and spy on web access.
And now they have a one-stop shop for all their DNS surveillance needs.
DNS is the most openly insecure aspect of the entire internet. It’s wide open.
Re: Mozilla’s DNS over HTTPs
#10I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…