Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

311–320 of 777 posts

Re: Mozilla’s DNS over HTTPs

#313
post #261
post #125

Earlier quoted context omitted.

Does it submit every FQDN via DoH? So does Cloudflare see myspookybox.zeveb? Because if so then even that is an information leak.

It's very frustrating to be constantly downvoted for saying that Firefox's DoH implementation leaks information without any of the downvoters saying why. Seriously, do you disagree that it leaks information? Do you agree that it does, but believe it is less problematic for two companies to have this information than having it sharded across all ISPs? Do you agree that it's more problematic but you don't care for some…

Perhaps you could check with Wireshark for DoH traffic (ie https to Cloudflare) when resolving a local domain?

(I agree with what you've said here, FYI)

Re: Mozilla’s DNS over HTTPs

#314

Does anyone know when something like this might come to Brave?

I know Brave is supposed to be a privacy-centric browser, but their plan for advertising seems at odds with that. Advertising is a slippery slope and I wonder how long before these promises are eroded or outright reversed. > 100% of your ad spend is placed for active users that opt-in to a rewarding private ad experience. > Craft effective offers and provide captivating full-page experiences directly with consumers i…

Advertising doesn't have to be at odds with privacy. So long as the user agent is in charge of deciding what ads to show rather than a centralized server (which is the entire point of Brave), no user data needs to be revealed to anyone.

Re: Mozilla’s DNS over HTTPs

#315
So now just one company will have access to all the data from 99% of firefox users? I don't see how giving so much power to just one entity is better for our privacy.

Previously if I used my computer at home, coffee shop, work, hotel etc it would be very hard if not impossible for one company to get all of my browsing history. And giving it all to one company is a better idea?

Re: Mozilla’s DNS over HTTPs

#316

Earlier quoted context omitted.

This is quite a radical position, but there are no legitimate use cases for content filtering. What use cases do people have in mind? * State censorship. Totalitarian. * "Parental controls". Child abuse. Learn how to build trust in your children instead. * Corporate filtering. Find other ways to motivate your employees than blocking Facebook. The problem with this implementation is that it doesn't go far enough. I wa…

How about wanting to filter advertising, or filter content for myself - I block imgur via DNS for example, or block domains used by trackers and malware creators?

uBlock Origin works well. But you have a good point — you should be able to impose content filtering on yourself. And Firefox supports that.

Re: Mozilla’s DNS over HTTPs

#317
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

> We continue to explore enabling DoH in other regions, and are working to add more providers as trusted resolvers to our program. DoH is just one of the many privacy protections you can expect to see from us in 2020. Cloudflare is just one of the initial providers and they indicate that they are adding more. Also, I'm assuming you can add your own custom provider based on the screenshot in the article. You can just…

99 % of users won’t touch default values, so it’s not a valid excuse.

I really have come to the conclusion that privacy is just a marketing feature for Mozilla. They e.g. also do nothing against data exfiltration by popular extensions although they have known that issue for years.

If they’re really serious about privacy they should have waited to implement DoH as an open standard and allow more DNS providers to support it. The browser could then simply see if your default DNS supports it and if yes switch to DoH.

This really smells like some kind of data deal between them and Cloudflare. This is not surprising because DNS data is really valuable and passive DNS monitoring is used for many purposes, e.g. security and marketing. Controlling this data gives you many interesting business opportunities, hence I can understand why Cloudflare and Google are after it.

It’s also revealing that they don’t enable this in the EU, because they rightfully fear that it’s not compliant.

Re: Mozilla’s DNS over HTTPs

#318
post #121

Earlier quoted context omitted.

There are a couple use-cases here. * On devices that you own and control you don't need a network level control like this except for convenience. This is when you should be applying the override record. * On devices that you do not own or control (family/friends/guests) disabling DoH makes you the malicious network operator. Connecting to your Wi-Fi doesn't make you trusted in any sense of the word. * On devices that…

I'm _maliciously_ stopping my kids Android apps from connecting to tracking and malware domains. What a tyrant I am - I should have over control to a third-party for profit company??!? You're kidding, right.

You own and control your child's phone. You're in case #1. Family is meant to mean your spouse, adult children, or relatives.

Re: Mozilla’s DNS over HTTPs

#319
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

> It sends all the users DNS queries to Cloudflare

I wonder how much Cloudflare paid for this 'privilege' of being the default DNS provider.

Re: Mozilla’s DNS over HTTPs

#320
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

> We continue to explore enabling DoH in other regions, and are working to add more providers as trusted resolvers to our program. DoH is just one of the many privacy protections you can expect to see from us in 2020. Cloudflare is just one of the initial providers and they indicate that they are adding more. Also, I'm assuming you can add your own custom provider based on the screenshot in the article. You can just…

"You can just opt out" is the same tired line that in former times Mozilla has fought against.

It's extremely hard to keep track of and manage "opt outs", especially in a household with multiple computers and multiple people.

Formerly, I "opted out" of having a browser that phoned home my browsing traffic by using Firefox.

Post reply on HN