Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

11–20 of 777 posts

Re: Mozilla’s DNS over HTTPs

#11
post #5

Doth protest too much. People don’t take issue with DoH, they take issue with an advertising supported browser like Mozilla’s unicast (and now bicast) centralization of DNS traffic that was previously distributed. We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization. They make this about DoH when really the primary issues are with how they went about it.

>> We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization. Ummm so what’s the downside then? Are those services arcane and hard to use and utterly forbidding blackest black magic, like almost all crypto stuff? If you’re thinking browser users will just do this then that then this and x and y and z to “get dns crypto going”, then I’ll take Mozilla’s “it just works” approach…

Not sure what any of your reply means. Adding OS support isn’t required. People just run a local resolver that supports these things. No different than any other application. Nothing arcane. Certainly no more than HTTP and SSL.

I think you have some reading to do.

Re: Mozilla’s DNS over HTTPs

#12
post #2

I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…

> DoH providers have committed to far stronger privacy protections.

What about DNS tampering? In many countries there are different rules for taking down a website. My ISP applies different rules than 8.8.8.8, which is handy when required by law in France but not in USA.

Effectively, government-mandated tampering will be applied with much less granularity because of centralization (or bi-centralization).

Re: Mozilla’s DNS over HTTPs

#14
Does the disable code still work in the about:config? I would rather not have the trusted providers see all our internal server names (which is wasted bandwidth and time) and our controls in the library work.

DNS resolution is the OS's job. This hijacking of function is a pain. Has no one at Mozilla ever had to deal with the realities of using their browser in an organization?

Re: Mozilla’s DNS over HTTPs

#15
post #11

Earlier quoted context omitted.

>> We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization. Ummm so what’s the downside then? Are those services arcane and hard to use and utterly forbidding blackest black magic, like almost all crypto stuff? If you’re thinking browser users will just do this then that then this and x and y and z to “get dns crypto going”, then I’ll take Mozilla’s “it just works” approach…

Not sure what any of your reply means. Adding OS support isn’t required. People just run a local resolver that supports these things. No different than any other application. Nothing arcane. Certainly no more than HTTP and SSL. I think you have some reading to do.

>> People just run a local resolver that’s support’s these things.

Nowhere do “people just run a local resolver”. Grandma and aunty Beryl certainly don’t, nor does any other ordinary person. If you want secure DNS you have to build it in to the browser.

Only systems people think that this is the sort of thing that ordinary people do.

Re: Mozilla’s DNS over HTTPs

#16
post #8

Earlier quoted context omitted.

And now they have a one-stop shop for all their DNS surveillance needs.

Well it’s absolutely happening right now to every unencrypted DNS server, so what’s your point? DNS is the most openly insecure aspect of the entire internet. It’s wide open.

So you’re arguing that everybody should switch to DNS over TLS (DoT), then? Sounds great!

Re: Mozilla’s DNS over HTTPs

#17

Why are people so down on DNS over HTTPS? DNS is the primary way governments control and spy on web access.

My main gripe is that before DoH, setting a custom DNS via DHCP was enough to get all devices on a network and all applications on these devices to use a custom DNS.

Now we are headed to a future where each software vendor decides how to make DNS queries. I can predict that all of them will apply their own custom heuristics to detect things like split-horizon.

Re: Mozilla’s DNS over HTTPs

#19

Does the disable code still work in the about:config? I would rather not have the trusted providers see all our internal server names (which is wasted bandwidth and time) and our controls in the library work. DNS resolution is the OS's job. This hijacking of function is a pain. Has no one at Mozilla ever had to deal with the realities of using their browser in an organization?

AFAIK the ESR (business release) does not have this on by default
Post reply on HN