Earlier quoted context omitted.
> Think about it: a Firefox DoH user could get different DNS answers than other apps get on the same machine using standard DNS on port 53, if Google or Cloudflare wanted to, because they’re essentially talking to different versions of the internet. How is that different than existing DNS servers?
There's no difference that a DNS server can see between a browser on your computer making a DNS request vs. any other app. But if the browser is using DoH and other apps don't, then it can tell.
Mozilla’s DNS over HTTPs
431–440 of 777 posts
Re: Mozilla’s DNS over HTTPs
#432Earlier quoted context omitted.
Firefox by default is configured with a fallback option, where if resolution would fail, it will fallback to the system-provided DNS servers. So your internal TLDs are safe. Additionally, if you've setup Firefox to be installed with Firefox for Enterprise, DoH is disabled by default and you've got nothing to worry about. DOH is able to be configured through GPO as well, allowing the use of a custom server.
And that is even more dangerous, it would mean that if for some reason an identical domain extists on the internet (or somebody registers it to do an attack) then all the hosts will connect to the malicious external domain and not the correct host in the internal network. Local hosts should be resolved FIRST. Also cloudfare this way gets the DNS names of your internal hosts, you are leaking information that otherwise…
If you have a problem with Cloudflare, go setup your own, it's just BIND9 with some SSL certs.
Re: Mozilla’s DNS over HTTPs
#433Earlier quoted context omitted.
Firefox by default is configured with a fallback option, where if resolution would fail, it will fallback to the system-provided DNS servers. So your internal TLDs are safe. Additionally, if you've setup Firefox to be installed with Firefox for Enterprise, DoH is disabled by default and you've got nothing to worry about. DOH is able to be configured through GPO as well, allowing the use of a custom server.
And that is even more dangerous, it would mean that if for some reason an identical domain extists on the internet (or somebody registers it to do an attack) then all the hosts will connect to the malicious external domain and not the correct host in the internal network. Local hosts should be resolved FIRST. Also cloudfare this way gets the DNS names of your internal hosts, you are leaking information that otherwise…
Re: Mozilla’s DNS over HTTPs
#434Earlier quoted context omitted.
> I really have come to the conclusion that privacy is just a marketing feature for Mozilla. They e.gg. also do nothing against data exfiltration by popular extensions although they have known that issue for years. I thought about this recently, and the move to HTTPS-Everywhere is the biggest issue here. In the old days, you could have something like the @guard firewall on Windows, which could examine all outgoing HT…
HTTPS intercepting proxies ("middle boxes") are commonly deployed in the corporate world. Firefox-- and internet protocols themselves-- makes many concessions to avoid gratuitously breaking these things. For free software, squid ssl-bump works, though is something of a pain to configure!
Or to look at it from another perspective, if you do this then in configuring the browser to accept it (typically, adding a private CA as trusted) you agree that you broke the browser's provided security promises and are happy without them.
In principle this can be safe if the middlebox you use has its finger on the pulse (usually dubious) and you're applying security updates to the middlebox as you would a browser or other outward facing software. So far I've never seen one I'd trust.
Re: Mozilla’s DNS over HTTPs
#435Earlier quoted context omitted.
If you use the nextdns DoH provider in Firefox you can actually configure your own adblocking domains even when you're moving around across networks. Just FYI
> If you use the nextdns DoH provider in Firefox you can actually configure your own adblocking domains even when you're moving around across networks. Uh. Doesn't this prove that Firefox's DOH implementation is sending strong per-user identifying information to the server?
If you’re hitting cloudflare, it’s just hitting the regular endpoint so no user identifying information.
Re: Mozilla’s DNS over HTTPs
#436Earlier quoted context omitted.
And that is even more dangerous, it would mean that if for some reason an identical domain extists on the internet (or somebody registers it to do an attack) then all the hosts will connect to the malicious external domain and not the correct host in the internal network. Local hosts should be resolved FIRST. Also cloudfare this way gets the DNS names of your internal hosts, you are leaking information that otherwise…
You should only use a domain you own or something that isn't routable. You can't blame FF for that
Re: Mozilla’s DNS over HTTPs
#437Earlier quoted context omitted.
> We continue to explore enabling DoH in other regions, and are working to add more providers as trusted resolvers to our program. DoH is just one of the many privacy protections you can expect to see from us in 2020. Cloudflare is just one of the initial providers and they indicate that they are adding more. Also, I'm assuming you can add your own custom provider based on the screenshot in the article. You can just…
99 % of users won’t touch default values, so it’s not a valid excuse. I really have come to the conclusion that privacy is just a marketing feature for Mozilla. They e.g. also do nothing against data exfiltration by popular extensions although they have known that issue for years. If they’re really serious about privacy they should have waited to implement DoH as an open standard and allow more DNS providers to suppo…
Re: Mozilla’s DNS over HTTPs
#438Earlier quoted context omitted.
Draft only. OpenSSL doesn't support it - because it's still a draft. So as of now, ESNI does not provide anything.
It is moving forward, albeit slowly. With or without DoH/DoT, non encrypted SNI is a problem, and DoH/DoT have privacy improvements in their own right.
In every DoH/DoT discussion there is someone who mentions ESNI, but without major level support this is a vague promise. Of course DNS encryption is still useful even without ESNI.
Re: Mozilla’s DNS over HTTPs
#439I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…
https://old.reddit.com/r/pfBlockerNG/comments/d3p1gf/doh_ser...
Re: Mozilla’s DNS over HTTPs
#440Earlier quoted context omitted.
> What’s in it for the Cloudflare & NextDNS? It gives them a competitive advantage in DNS industry against other B2B providers, such as NS1.
How? Surely the only way that's possible is if they derive data about users, which they can then sell .. which is what Mozilla claim to be preventing.
Running a public DNS service allows Cloudflare and NextDNS to provide faster and smoother DNS updates to their B2B customers by avoiding third-party DNS resolvers and caches.