Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

91–100 of 777 posts

Re: Mozilla’s DNS over HTTPs

#91
post #20

Why isn't this being solved on an operating system level instead?

This question should be upvoted more.

Under unix in general (linux, bsd and, I assume, OSX) you can change your system resolver as you please. DoH is supported by several implementations to a various degree already. You can switch right now, for everything running on your system if you wanted to!

But browsers nowdays basically live under the following assumptions:

- the users are dumb, and "we know what's best for you" (well, to be fair this has been a consistent trend for everything in the industry) - the OS cannot be trusted for anything, the baseline being the lowest common denominator of any old/broken version of android/osx/windows/linux they want to support - the users cannot change the system resolver even if they wanted to because the OS is locked down (android, ios, and windows with group policies)

I think all the above reasons are detrimental, but at the same time they're all sadly true. Because browsers essentially are now not far from operating systems, they abstract themselves above everything, including the resolver.

Re: Mozilla’s DNS over HTTPs

#92
post #2

I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…

For 1, you're spot on.

For 2, the one thing that's missing from here is that we _know_ many ISPs are selling your data. I'm really uncertain why people are so determined to villify Cloudflare - who don't really stand to gain that much more useful info about you from this than they already have - and give a totally clear pass to their ISP despite years of proven bad behaviour. Yeah this (by default) uses CF's DoH service - note that you can change this if you want - but in my view that's strictly better than continuing to allow your ISP to to sell your browsing history. In other words - a bit of by-default centralisation is in my view an acceptable price to pay for the increases in privacy and security (especially as it's trivial to switch away from CF if they behave badly).

Re: Mozilla’s DNS over HTTPs

#93

Cloud flare is American and we know since the PRISM scandal that US based tech companies are directly plugged into the NSA, and everybody in the chain will deny it under the threat of prison. So, if this rolls out 'as-is' in any other country than the US, we will go from "all DNS requests are clear text, but dispatched among many entities" to "DNS requests are encrypted, but all read and controlled by american agenci…

They only enabled it by default for US users, so at this time it doesn't really matter. shrugs

When they roll out in the EU, I will pay close attention to how they are doing it, what partners they use under what jurisdictions etc.

Re: Mozilla’s DNS over HTTPs

#94
post #26
post #2

I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…

The ISP can just check which IP you contact, so I don't see this increasing privacy.

For some (large, especially) sites, the IP address maps to the entity you're trying to contact. For others (small, especially) sites, the IP address is shared among many entities... not just shared origin hosts but also the massive reverse proxies of the world (Cloudflare, etc.).

Re: Mozilla’s DNS over HTTPs

#95

Cloud flare is American and we know since the PRISM scandal that US based tech companies are directly plugged into the NSA, and everybody in the chain will deny it under the threat of prison. So, if this rolls out 'as-is' in any other country than the US, we will go from "all DNS requests are clear text, but dispatched among many entities" to "DNS requests are encrypted, but all read and controlled by american agenci…

The page, which you didn't read, specifically makes the point that they have no plans to roll this out (by default) anywhere except for the US.

Re: Mozilla’s DNS over HTTPs

#96

As a resident of a country whose government and ISPs heavily and habitually censor the Internet for political reasons, I for one truly appreciate Firefox's DoH. They should also enable 'network.security.esni.enabled' by default because the censors here have upgraded from DNS to SNI-based blocking. I get it that better solutions are possible, but got to teach people to first walk before teaching them to run. AFAIK, Ch…

[deleted]

Re: Mozilla’s DNS over HTTPs

#97
post #61

Questions I couldn’t find answers to in the post or linked info about the Trusted Resolver Program: What’s in it for the Cloudflare & NextDNS? Are they getting paid to handle this traffic or paying to have the opportunity to access this data? Can users outside the US opt-in? The comment about having “no plans” to enable this outside the USA seems a bit disingenuous. Hard to believe they built this program / feature a…

> The comment about having “no plans” to enable this outside the USA seems a bit disingenuous The comment actually very clearly says "we do not have plans to roll out the feature in Europe or other regions at this time ". Also I have mixed feelings about this. On one hand yeah, encryption is great and someone sitting between me and my ISP will no longer be able to monitor my DNS queries. On the other hand I don't fee…

> DoH just enables any piece of software or hardware on my network to bypass any security controls I have in place.

I think this is an error in how you've thought about the problem. If your "security controls" depend upon other people volunteering to use some protocol then those weren't "security controls" they were more like "guidelines".

[ My local airport has a sign and a telephone so that if you've arrived with goods that are forbidden or without permission to enter the country you can call up the relevant authorities and have them come fine or arrest you. The telephone looks dusty. Do you think maybe people just decide not to call? ]

Mozilla does also have a programme https://iot.mozilla.org/ about how to design IoT devices that allow their owners to control them rather than trying to bodge things by hoping they use protocols you can intercept.

Re: Mozilla’s DNS over HTTPs

#98

Cloud flare is American and we know since the PRISM scandal that US based tech companies are directly plugged into the NSA, and everybody in the chain will deny it under the threat of prison. So, if this rolls out 'as-is' in any other country than the US, we will go from "all DNS requests are clear text, but dispatched among many entities" to "DNS requests are encrypted, but all read and controlled by american agenci…

NSA don’t factor into my personal threat model _at all_ where random ISPs snooping and selling do. I would gladly give the NSA all of my traffic unencrypted in exchange for decent commercial privacy

Re: Mozilla’s DNS over HTTPs

#99
post #95

Cloud flare is American and we know since the PRISM scandal that US based tech companies are directly plugged into the NSA, and everybody in the chain will deny it under the threat of prison. So, if this rolls out 'as-is' in any other country than the US, we will go from "all DNS requests are clear text, but dispatched among many entities" to "DNS requests are encrypted, but all read and controlled by american agenci…

The page, which you didn't read, specifically makes the point that they have no plans to roll this out (by default) anywhere except for the US.

Nowhere it says they have no plan of doing it. They just release it only for the US __build__, __by default__, __now__.

But to make things more honest, I'll edit my comment.

Re: Mozilla’s DNS over HTTPs

#100
post #46
post #5

Doth protest too much. People don’t take issue with DoH, they take issue with an advertising supported browser like Mozilla’s unicast (and now bicast) centralization of DNS traffic that was previously distributed. We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization. They make this about DoH when really the primary issues are with how they went about it.

DNS over TLS and DNSCrypt both depend on servers... exactly as centralized as DoH. They are just different wire protocols that in the end do the exact same thing with a centralized DNS server.

In fact, the only meaningful difference between DoH and DoT is that DoT runs on a separate port, so network operators (and ISPs) can filter it. DoT is DoH with a kill switch.
Post reply on HN