Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

251–260 of 777 posts

Re: Mozilla’s DNS over HTTPs

#251
post #55

Earlier quoted context omitted.

This logic makes no sense to me. Can you imagine if AT&T or Spectrum made a statement like this? The “network administrator” is an untrusted 3rd party who should have basically 0 say in how my device operates. The device administrator, ie the owner of the machine, is the one who should have the final say over when DoH is used. The use-application-dns record is for businesses that want an easy way to stop DoH on machi…

So what if I run a Pihole at home as a DNS server and want to stop being able to resolve various domains? I would like to know how to stop all devices (actually worse, individual applications!) on my network deciding to DoH of their own accord (and therefore bypassing my local DNS server). This kind of centralised ability to block DoH is very useful to me.

Of note: PiHole supports DoH, so you point your DoH supporting applications at it. If your OS gets around to adding DoH support you can point your entire OS at it and disable DoH in applications, but until then you'll have to do things the hard way.

Re: Mozilla’s DNS over HTTPs

#252

Earlier quoted context omitted.

"The correct behavior for devices is to treat the intermediate network between them and the servers they talk to as hostile." Thanks for this - I had not thought of that. Looks like I'll be keeping my "smart" TV off the network forever then (my old LG used to send a network request whenever I pressed any button on the remote)! And all my Android devices, Windows 10 devices and my Apple TV and MacBook too. (This is on…

This is precisely why many of us use Linux and put up with some of the inconveniences or doing so - it’s more trustworthy. (And it gets more convenient as more people start using it.)

the irony is that almost all of the smart devices use linux....

Re: Mozilla’s DNS over HTTPs

#253

Can you disable this?

What are some reasons why someone would prefer to or need to disable it. Just curious.

I have Pi-hole on my network and I do not want to use any other DNS provider other than my own (with my own blacklist/whitelist).

Re: Mozilla’s DNS over HTTPs

#254
post #121

Earlier quoted context omitted.

There are a couple use-cases here. * On devices that you own and control you don't need a network level control like this except for convenience. This is when you should be applying the override record. * On devices that you do not own or control (family/friends/guests) disabling DoH makes you the malicious network operator. Connecting to your Wi-Fi doesn't make you trusted in any sense of the word. * On devices that…

Thanks. Not to be argumentative, but I find it odd/interesting that guests connecting to my WiFi and using my DNS set up makes me a "malicious network operator" in your eyes. That's a very odd view of the world in my opinion, as it is my WiFi and DNS set up. That's like saying that me stopping guests taking photos of my daily activities (showering, using the toilet) whilst in my house is a malicious behaviour too. I…

If you can't trust your guests, then don't let them use your network.

You can attempt to block and filter things, but there will always be a way for something malicious to bypass it.

Re: Mozilla’s DNS over HTTPs

#255

Seems very marginal for privacy when people in the middle can still see the IP you're connecting to, just not which DNS record you may have retrieved the IP with.

It's actually quite massive. Most sites (well not most, but a lot) sit behind something like cloudflare, so your scummy intercepting ISP would only see a connection to cloudflare. Of course none of this really means too much until encrypted SNI is a thing but it's a definitely a lot more than marginal imo

Re: Mozilla’s DNS over HTTPs

#256

Does anyone know when something like this might come to Brave?

I know Brave is supposed to be a privacy-centric browser, but their plan for advertising seems at odds with that. Advertising is a slippery slope and I wonder how long before these promises are eroded or outright reversed.

> 100% of your ad spend is placed for active users that opt-in to a rewarding private ad experience.

> Craft effective offers and provide captivating full-page experiences directly with consumers in Brave’s Private Ad Tabs.

> Brave uses local machine learning with the browser profile to only place ads in optimal conditions. Ads are matched to opportunities, and users become partners instead of targets.

> Private ad matching efficiently matches ads directly from the device, without breaching personal information.

https://brave.com/brave-ads-waitlist/

Re: Mozilla’s DNS over HTTPs

#258
post #233

Does anyone know when something like this might come to Brave?

If I recall correctly, brave://flags should have "Secure DNS" or something like that.

Sweet! Did not know about that. Ask a question, learn something new. Now I have knobs to play with. :)

Re: Mozilla’s DNS over HTTPs

#259

Can you disable this?

What are some reasons why someone would prefer to or need to disable it. Just curious.

I'm not sure if disabling it is the right way to go, but I do not plan on letting Firefox ship all my DNS queries to CloudFlare. I do not trust Cloudflare any more (and maybe a little less honestly) than my ISP.

I do want a container with my own DNS-over-HTTP running on my own hosted VM (or Digital Ocean, or Vultr or Linode or whoever) and I'll ship my DNS queries there.

Re: Mozilla’s DNS over HTTPs

#260

how long does Cloudflare or NextDNS retain dns query logs?

Also, why limit the choices to just those two? If you're going to provide an app-based service for this, why not allow the user to use any DoH server they want to use? Did Mozilla make some kind of deal with Cloudflare and NextDNS?
Post reply on HN