Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

471–480 of 777 posts

Re: Mozilla’s DNS over HTTPs

#471

Earlier quoted context omitted.

> Formerly, I "opted out" of having a browser that phoned home my browsing traffic by using Firefox. Formerly your browser still "phoned home" to your default DNS provider, using an insecure protocol. I appreciate your concerns but, unless you run your own DNS server, you have to trust someone at some point.

I trust my own DNS provider much more than I trust Cloudflare to be honest. Also, most DNS requests over that “insecure protocol” happened over a single network hop or two and never left the infrastructure of the ISP. Cloudflare is now a public company and they need to aggressively monetize their services. Selling browsing data is a lucrative business and becoming “the” DNS provider for most users (while locking out…

If Cloudflare sells their customer data then wont they be sued by Mozilla for breach of contract?

Re: Mozilla’s DNS over HTTPs

#472
post #352
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

It's a balance. Do you want your plaintext DNS request sent to starbucks or your local unsecured public wifi, or do you want it sent encrypted to your DoH server of choice?

I want to not see further centralization of Core Internet Infrastructure to CloudFlare

Re: Mozilla’s DNS over HTTPs

#473
post #366

Earlier quoted context omitted.

If you are going to that level of effort then why not just block the IPs of the marketing servers themselves?

That is an ineffective approach for a number of reasons. This is essentially a blacklist approach, and blacklist approaches are very weak. The number of such servers is in the several thousands, at least. They also move and new ones spin up, requiring constant updating of the blacklist. It's much more effective to take a whitelist approach or, what I do, just block the DNS lookups for them all. (That said, I do keep…

Don't those disadvantages apply just the same to your blacklisting of marketers' DNS servers?

Re: Mozilla’s DNS over HTTPs

#474
post #382

Earlier quoted context omitted.

I can use a VPN when browsing on those kind of networks.

That's fine for more technical users who are aware of how to mitigate this kind of issue, but then those same more technical users will also likely know how to disable DoH. For the majority of users who may not understand the risks around plain text DNS, there are advantages to it being encrypted.

This has always been a poor argument. Especially for FF which is mainly used by Technical people

Chrome a d IE are used by people that do not understand the risks around DNS

I use FF because I am / was tried of IE and Chrome telling me how I should use thier software, now Mozilla is making the same moronic choices for me instead of empowering users

DoH should be Opt-In, not Opt-Out

Re: Mozilla’s DNS over HTTPs

#475
post #175

Questions I couldn’t find answers to in the post or linked info about the Trusted Resolver Program: What’s in it for the Cloudflare & NextDNS? Are they getting paid to handle this traffic or paying to have the opportunity to access this data? Can users outside the US opt-in? The comment about having “no plans” to enable this outside the USA seems a bit disingenuous. Hard to believe they built this program / feature a…

Collect data of course. Mozilla is very naive to trust that they won't collect data (be it personal or otherwise). Neither they nor the enduser can ensure that.

Mozilla doesn't trust. That's what the legal team is for. All this stuff is covered by contracts and audits.

Re: Mozilla’s DNS over HTTPs

#476
post #382

Earlier quoted context omitted.

I can use a VPN when browsing on those kind of networks.

That's fine for more technical users who are aware of how to mitigate this kind of issue, but then those same more technical users will also likely know how to disable DoH. For the majority of users who may not understand the risks around plain text DNS, there are advantages to it being encrypted.

"Good" VPNs also aren't usually/ever? free.

Re: Mozilla’s DNS over HTTPs

#477
post #59

The overhead of setting up and using an https connection is massive compared to DNS which can fit in a UDP transaction. Do they establish a connection and leave it open for a long period? Supporting that would be a big commitment on the part of the resolvers.

Small DNS queries and answers fit in one UDP packet, but larger ones don't and have to be retried as TCP. HTTPS/2 over TLS 1.3 (which is the baseline you should assume for these relatively new services) is one TCP setup plus potentially 0-RTT TLS on all but the first visit. 0-RTT is safe here because a DNS query is just a question with no side effects. Replay attacks (the risk 0-RTT incurs) don't do anything: Gumby:…

Thanks. I hadn't followed the development of 0-RTT which allows the server to tear down the connection.

Re: Mozilla’s DNS over HTTPs

#478
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

> It sends all the users DNS queries to Cloudflare, adding a new party

it removes many parties (some unknown) who have no legal oversight, and adds a select parties who are legally bound to respect your privacy.

> because the user's destination IPs remain unencrypted

This makes no sense. your ISP cannot see that you are visiting facebook because the IP shows up us cloudflare urrrghhh!

> At the moment you can disable this across your whole lan

now that is a "massive attack on user privacy"

Re: Mozilla’s DNS over HTTPs

#479
post #449
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

Note that US ISP "Comcast/Xfinity" does not, so at the very least, that's one safe harbor amidst the rest.

https://corporate.comcast.com/stories/privacy-with-comcasts-...

Re: Mozilla’s DNS over HTTPs

#480
post #2

I think this is generally a good thing. Two questions I've often seen surface on HN though weren't answered: 1. Isn't this better implemented at the OS level? 2. Isn't centralisation to two DoH providers more centralised than five large ISPs? Others are probably better suited to answer, but the answers I can think of: 1. Yes, but it is not, so this solution is second-best. If Operating Systems decide to tackle this p…

For 1, you're spot on. For 2, the one thing that's missing from here is that we _know_ many ISPs are selling your data. I'm really uncertain why people are so determined to villify Cloudflare - who don't really stand to gain that much more useful info about you from this than they already have - and give a totally clear pass to their ISP despite years of proven bad behaviour. Yeah this (by default) uses CF's DoH serv…

>who don't really stand to gain that much more useful info about you from this than they already have

that is absolutely untrue. Today they only have data for websites already using CloudFlare Services.

DoH they can info on ALL websites users for FF visit. and while their "contract" with mozilla requires they "anonymize" the data, they are admitted to collecting aggregate data which is VERY valuable in itself, plus I never trust companies when they say they will "anonymize" the data

Further I have not see what if any penalties are imposed on cloudfare for any violations of the "contract" they have with Mozilla, if there are no penalties then the contract is pointless and not an assurance of anything

As to why people villify Cloudflare, it is what CloudFlare represents that is a problem for people like me. The Internet is best serviced by decentralization. in the last 10 to 20 years we have seen and continue to see MASSIVE centralization of core infrastructure.

FF move here represents another step on that path. CloudFare already has too much of the net behind their infrastructure.

They are an inherit threat to the free and open web

Post reply on HN