Earlier quoted context omitted.
> Formerly, I "opted out" of having a browser that phoned home my browsing traffic by using Firefox. Formerly your browser still "phoned home" to your default DNS provider, using an insecure protocol. I appreciate your concerns but, unless you run your own DNS server, you have to trust someone at some point.
I trust my own DNS provider much more than I trust Cloudflare to be honest. Also, most DNS requests over that “insecure protocol” happened over a single network hop or two and never left the infrastructure of the ISP. Cloudflare is now a public company and they need to aggressively monetize their services. Selling browsing data is a lucrative business and becoming “the” DNS provider for most users (while locking out…
Mozilla’s DNS over HTTPs
471–480 of 777 posts
Re: Mozilla’s DNS over HTTPs
#472I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…
It's a balance. Do you want your plaintext DNS request sent to starbucks or your local unsecured public wifi, or do you want it sent encrypted to your DoH server of choice?
Re: Mozilla’s DNS over HTTPs
#473Earlier quoted context omitted.
If you are going to that level of effort then why not just block the IPs of the marketing servers themselves?
That is an ineffective approach for a number of reasons. This is essentially a blacklist approach, and blacklist approaches are very weak. The number of such servers is in the several thousands, at least. They also move and new ones spin up, requiring constant updating of the blacklist. It's much more effective to take a whitelist approach or, what I do, just block the DNS lookups for them all. (That said, I do keep…
Re: Mozilla’s DNS over HTTPs
#474Earlier quoted context omitted.
I can use a VPN when browsing on those kind of networks.
That's fine for more technical users who are aware of how to mitigate this kind of issue, but then those same more technical users will also likely know how to disable DoH. For the majority of users who may not understand the risks around plain text DNS, there are advantages to it being encrypted.
Chrome a d IE are used by people that do not understand the risks around DNS
I use FF because I am / was tried of IE and Chrome telling me how I should use thier software, now Mozilla is making the same moronic choices for me instead of empowering users
DoH should be Opt-In, not Opt-Out
Re: Mozilla’s DNS over HTTPs
#475Questions I couldn’t find answers to in the post or linked info about the Trusted Resolver Program: What’s in it for the Cloudflare & NextDNS? Are they getting paid to handle this traffic or paying to have the opportunity to access this data? Can users outside the US opt-in? The comment about having “no plans” to enable this outside the USA seems a bit disingenuous. Hard to believe they built this program / feature a…
Collect data of course. Mozilla is very naive to trust that they won't collect data (be it personal or otherwise). Neither they nor the enduser can ensure that.
Re: Mozilla’s DNS over HTTPs
#476Earlier quoted context omitted.
I can use a VPN when browsing on those kind of networks.
That's fine for more technical users who are aware of how to mitigate this kind of issue, but then those same more technical users will also likely know how to disable DoH. For the majority of users who may not understand the risks around plain text DNS, there are advantages to it being encrypted.
Re: Mozilla’s DNS over HTTPs
#477The overhead of setting up and using an https connection is massive compared to DNS which can fit in a UDP transaction. Do they establish a connection and leave it open for a long period? Supporting that would be a big commitment on the part of the resolvers.
Small DNS queries and answers fit in one UDP packet, but larger ones don't and have to be retried as TCP. HTTPS/2 over TLS 1.3 (which is the baseline you should assume for these relatively new services) is one TCP setup plus potentially 0-RTT TLS on all but the first visit. 0-RTT is safe here because a DNS query is just a question with no side effects. Replay attacks (the risk 0-RTT incurs) don't do anything: Gumby:…
Re: Mozilla’s DNS over HTTPs
#478I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…
it removes many parties (some unknown) who have no legal oversight, and adds a select parties who are legally bound to respect your privacy.
> because the user's destination IPs remain unencrypted
This makes no sense. your ISP cannot see that you are visiting facebook because the IP shows up us cloudflare urrrghhh!
> At the moment you can disable this across your whole lan
now that is a "massive attack on user privacy"
Re: Mozilla’s DNS over HTTPs
#479I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…
Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…
https://corporate.comcast.com/stories/privacy-with-comcasts-...
Re: Mozilla’s DNS over HTTPs
#480I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…
For 1, you're spot on. For 2, the one thing that's missing from here is that we _know_ many ISPs are selling your data. I'm really uncertain why people are so determined to villify Cloudflare - who don't really stand to gain that much more useful info about you from this than they already have - and give a totally clear pass to their ISP despite years of proven bad behaviour. Yeah this (by default) uses CF's DoH serv…
that is absolutely untrue. Today they only have data for websites already using CloudFlare Services.
DoH they can info on ALL websites users for FF visit. and while their "contract" with mozilla requires they "anonymize" the data, they are admitted to collecting aggregate data which is VERY valuable in itself, plus I never trust companies when they say they will "anonymize" the data
Further I have not see what if any penalties are imposed on cloudfare for any violations of the "contract" they have with Mozilla, if there are no penalties then the contract is pointless and not an assurance of anything
As to why people villify Cloudflare, it is what CloudFlare represents that is a problem for people like me. The Internet is best serviced by decentralization. in the last 10 to 20 years we have seen and continue to see MASSIVE centralization of core infrastructure.
FF move here represents another step on that path. CloudFare already has too much of the net behind their infrastructure.
They are an inherit threat to the free and open web