Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

491–500 of 777 posts

Re: Mozilla’s DNS over HTTPs

#491
post #449
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

> What are you even talking about?

Can you please edit swipes like that out of your comments when posting to HN? They break the site guidelines and provoke others into doing worse.

https://news.ycombinator.com/newsguidelines.html

Re: Mozilla’s DNS over HTTPs

#492

Earlier quoted context omitted.

That's fine for more technical users who are aware of how to mitigate this kind of issue, but then those same more technical users will also likely know how to disable DoH. For the majority of users who may not understand the risks around plain text DNS, there are advantages to it being encrypted.

"Good" VPNs also aren't usually/ever? free.

You can operate one on your home router, which can be negative-cost if you're also saving the rent on the ISP hardware.

Re: Mozilla’s DNS over HTTPs

#493
post #437

Earlier quoted context omitted.

DoH is an open standard. DoH is also better for the 99% of users who don’t care about DNS resolvers and use their standard, shoddy and privacy invasive ISP provided one.

Just because something is open doesn't mean that it's ok to push it on users at will. DoH is highly controversial and not a standard, there are only a handful of players that push it for their own benefit. Also, in most parts of the world people trust their local ISPs more than giant US corporations, you should not assume that everyone welcomes this centralization.

> in most parts of the world people trust their local ISPs more than giant US corporations

On what is this assertion based on?

I'm part of this world and I'm not a US citizen. I do not trust my local ISP, because they log and report traffic to local security agencies. It's bening at this point, tracking illegal activities, but they can connect whatever I do with my real name and address.

If I were to guess, in most parts of this world people don't have freedom of speech and fear repercussions from their government for their online activity.

The profiling that US companies do for serving better ads is essentially a first world problem, and a pretty irrelevant one for most people.

Also if we had such deep mistrust in US companies, first of all we shouldn't be using devices and operating systems built by US companies.

Re: Mozilla’s DNS over HTTPs

#494
Due to the Cloud Act, this is probably the end of Mozilla as a browser used in a business setting for non-US companies.

A naïve protocol capsuled inside a stupid and dangerous protocol.

Re: Mozilla’s DNS over HTTPs

#495
I'm getting pretty pissed off the with the arrogance of US internet tech companies sidestepping formal protocol design & industry adoption because it isn't moving "fast enough" for them. Without ESNI, DoH is essentially meaningless for the class of privacy invaders it is supposed to combat against. By the time ESNI is out, DoT would have had enough time to mature and gain wide enough adoption.

DoT is better because at least it's obvious if your ISP/Gov is blocking port 853 (at which point you install a VPN or run your own resolver somewhere and tunnel to it or swap provider or move country). Meanwhile you get all the usual benefits of decentralised DNS resolution and don't have to worry about the unforeseen overhead and bullshit DoH is going to spwan.

Firefox is an app for browsing websites. What business does it have pushing a half baked compromise solution that undermines core infrastructure, creates a false sense of privacy and introduces second order effects that will result in DNS lookups being centralised in to the hands of a few giant US corporations (at least changing to 1.1.1.1 or 8.8.8.8 was opt-in).

Also can't wait for the inevitable instances of Cloudflare deciding not to resolve certain domains (effectively becoming the de-facto arbitrator of what most FF users can and cannot see on-line). For a preview of that, try going to archive.is with 1.1.1.1 as your resolver.

Ultimately, all of this is moot anyway (even once ESNI arrives). Regardless of DNS, your device still needs to connect to an IP. Entities interested in where you are going will still be able to get reasonable insight by simply correlating IP addresses and CT logs (http://blog.seanmcelroy.com/2019/01/05/ocsp-web-activity-is-...). The only decent solution to this, and available right now, is a VPN (at which point DNS privacy is automatically solved for you).

If Paul Vixie thinks DoH is a bad idea then... it's a bad fucking idea: https://twitter.com/paulvixie/status/1053765281917661184

Re: Mozilla’s DNS over HTTPs

#496
post #428

Earlier quoted context omitted.

It's interesting how bubbles work. In my world, everyone has a story about how an obscure but interesting to surveil service that they were involved with was DDOS attacked and immediately cloudflare sales was showing up offering to mitigate the attack for free by MITMing their traffic. ... Even showing up on the IRC channels of open source projects. I've personally witnessed it three times. Even if it weren't for the…

This is the most convoluted conspiracy theory I've read so far this decade. You profess not to believe these theories, or at least not the first one. So why then repeat? It's just more untruths poisoning this debate, like any other going on these days. And how does Cloudflare get the blame in your telling of this story, when it's your unnamed sources "you've heard" believing paranoid stories? DDOS were a thing before…

> This is the most convoluted conspiracy theory I've read so far this decade.

You must not get out much. :)

> things are easy to notice with some saved twitter searches and a google alert?

They are not doing this through twitter searches or google alerts. They show up when there is absolutely no mention of it anywhere, even sometimes when the attack is largely ineffective. Expectations like yours-- that they could only discover them from public sources-- probably contributes to people believing the attacks originate from cloudflare.

They use sampled netflow data from ISP to detect large scale DDOS attacks (presumably buying the information from arbor networks or similar, where they don't have their own coverage).

Re: Mozilla’s DNS over HTTPs

#497

Earlier quoted context omitted.

If I sit any family member down in front of this comment, their eyes would glaze over. Not only is what you mention a PITA, it's impossible for most people.

AFAIK, when one turns on DoH, Firefox's trr.mode defaults to 2 . And that's the default behaviour most would want except for the ones using pi-hole et al.

Not sure about that; it will still send query to the open Internet first and only when it fails, it will query local resolver.

You have leaking internal hostnames there.

To be fair, it is difficult to make all parties satisfied there. I think that a bit more honesty during discussion would help.

Re: Mozilla’s DNS over HTTPs

#498

Earlier quoted context omitted.

> They e.g. also do nothing against data exfiltration by popular extensions although they have known that issue for years. This kind of sentiment compels mozilla into becoming an apple-like gatekeeper to a walled garden because people conflate the trustworthiness of extension authors with mozilla's trustworthiness, which leads to less software freedom, a single point of failure and a less diverse ecosystem.

There simply should not be an API that allows exfiltrating the URL history of a user and then send it to a remote backend, at least not without making this very, very explicit to the user (which they currently do not). You don't need to be a "gatekeeper to a walled garden", it's just necessary to have sensible APIs that respect users privacy. I think a browser that puts privacy as its primary feature should be able t…

This has nothing to do with an API. Any kind of extension that acts automatically (i.e. doesn't exclusively spring to life when clicking on an extension-specific button) will have to inspect the currently open tabs, page contents or network requests to decide whether it has to do its thing, which means it has access to this kind of information anyway and could exfiltrate it through standard web APIs (fetch/XHR).

This is not on mozilla, their current extension API surface already is much more limited than the old one (killing off some preexisting usecases in the process) and still has many ways to get this information.

It's kind of asking that git shouldn't have filesystem or network access.

Re: Mozilla’s DNS over HTTPs

#499

Earlier quoted context omitted.

If I sit any family member down in front of this comment, their eyes would glaze over. Not only is what you mention a PITA, it's impossible for most people.

I'm a programmer and I have no idea what OPs comment means. I keep meaning to learn about networking stuff, but there is always so many other things to learn and since I don't work with devops or networking stuff it hasn't really been a priority.

Don't take it in some wrong way, but most programmers have no idea about networking; for them, IP addresses are just some numbers.

Yes, are explaining to our colleagues what IP address, subnet, route, or interface are.

Re: Mozilla’s DNS over HTTPs

#500

Earlier quoted context omitted.

The Host header is encrypted when using HTTPS and the SNI is encrypted when using ESNI. In the best scenario (DoH + HTTPS + ESNI), ISPs only get the destination IP, not the destination domain.

The how many IP does pornhub.com have?

Quite a few, I guess, but you'd probably be more concerned about how many other domains share the same IP addresses rather than about how many IP addresses this domain resolves to. And the answer seems to be thousands of domains — which in this case doesn't help much as they seem to all be related, but which in other cases might (eg. shared hosting, CDNs…).
Post reply on HN