Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

521–530 of 777 posts

Re: Mozilla’s DNS over HTTPs

#521

The most important thing this prevents are DNS based MITM attacks where they intercept your request and send you an IP address they control.

DNSSEC anyone? Or DNSCurve, or DNSCrypt.

DNSSEC does nothing to provide DNS privacy, nor does it address MITM attacks between endpoints (your phone and laptop) and DNS servers; it's a server-to-server protocol. DNSSEC is moribund; practically no important sites run it.

DNSCurve/DNSCrypt are directly competitive with DoH, but in a post-DoH world, both are probably dead-letter standards.

Re: Mozilla’s DNS over HTTPs

#522
post #449
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

Your ISP can still see the IPs that you are talking to... What are you talking about? They can even see the url even if you dont use them as your DNS

Re: Mozilla’s DNS over HTTPs

#523

Earlier quoted context omitted.

If I sit any family member down in front of this comment, their eyes would glaze over. Not only is what you mention a PITA, it's impossible for most people.

I'm a programmer and I have no idea what OPs comment means. I keep meaning to learn about networking stuff, but there is always so many other things to learn and since I don't work with devops or networking stuff it hasn't really been a priority.

Most of that comment is Mozilla BS and not networking stuff.

--Someone with a decent understanding of networking

Re: Mozilla’s DNS over HTTPs

#525

Earlier quoted context omitted.

This has nothing to do with an API. Any kind of extension that acts automatically (i.e. doesn't exclusively spring to life when clicking on an extension-specific button) will have to inspect the currently open tabs, page contents or network requests to decide whether it has to do its thing, which means it has access to this kind of information anyway and could exfiltrate it through standard web APIs (fetch/XHR). This…

Well, I was part of a team that proved that one of the most popular Firefox extensions (Web of Trust) stole and monetized user data, archiving every single URL a user opened and selling it to anyone who was willing to pay (the journalists I worked with even got a free sample containing the data of 3 million people). The extension was then banned for a few weeks before being reinstated, and happily continues to exfilt…

> I can think of several ways to drastically improve the privacy of web extensions by providing audit logging or more fine-grained control over permissions.

You were talking about API surface though. Neither of these things are API surface in itself. They are after the fact, informing the user what it can do and what it did with those APIs.

> It's just pointless to have the most advanced content blocking mechanisms when you allow browser extensions to circumvent them all.

I don't think so. It's not pointless. It just means you need to trust more than mozilla, you ALSO need to trust the extensions, just like you need to trust many other things in your system. The error here is assuming that everything should be reducible or can be reduced to a single source of trust.

> There are countless studies that show most non-expert users don't know what is happening with their data and are not able to judge the risks they're taking when installing software like browser extensions.

Perhaps. But if you follow that argument then you end up with a locked-down system with little flexibility, which I was referring to as apple-style walled garden. Some people may value such a thing, but I wouldn't use or recommend firefox if it became something like that. I would flee in terror.

Also consider that privacy is not an exclusive goal for mozilla: https://www.mozilla.org/en-US/about/manifesto/details/#princ...

Principles 2, 5 and 6 would be endangered by a single global actor (no matter how benevolent) being in control of your software.

Re: Mozilla’s DNS over HTTPs

#526
post #303

Earlier quoted context omitted.

It's far easier for ISPs to scrape up your DNS queries (they run the resolver) than it is for the to make correlations based on IP addresses, especially with multiple websites hosted on the same IP.

Soon to be resolved by IPv6 everywhere.

Isn't it the opposite? With DoH, ISPs now have another incentive not to boost IPv6 adoption.

Re: Mozilla’s DNS over HTTPs

#527

Earlier quoted context omitted.

> you have to trust someone at some point. Give me a non-profit infra provider than I can donate to, similar to Let's Encrypt. Let's call it "Let's Resolve", give it a non-profit charter and org style, with transparency, governance, and strong privacy protections. Mozilla could even be one of the sponsors of such an org, thereby ensuring the values it supports are adhered to. Open Street Map runs on a budget of ~$100…

Quad9 ( https://www.quad9.net/ ) exists and is a 501(c)(3) DNS provider with a relatively reasonable privacy policy. It supports direct DNS resolving and has DOH servers available. The problem is not so much the lack of available infrastructure but the lack of awareness of alternatives existing, so everyone ends up just using the known defaults (google or cloudflare mostly)

Brilliant. Tremendous this exists already. Someone get this to Mozilla!

Re: Mozilla’s DNS over HTTPs

#528

Earlier quoted context omitted.

There simply should not be an API that allows exfiltrating the URL history of a user and then send it to a remote backend, at least not without making this very, very explicit to the user (which they currently do not). You don't need to be a "gatekeeper to a walled garden", it's just necessary to have sensible APIs that respect users privacy. I think a browser that puts privacy as its primary feature should be able t…

It asks the user if they want to allow an extension to "Access Browsing History" [1]. That seems pretty explicit and self-explanatory to me. [1] https://support.mozilla.org/en-US/kb/permission-request-mess...

No, it would be straightforward if they asked the user something like this:

"Is it ok that this extension sends every single URL you open to an untrusted third party for processing? Please note that URLs might contain sensitive data like access tokens or session information."

Even so, I don't think such an API should exist. And if you absolutely need to have something like this you should restrict it to domain information by default, cutting away the path.

I can understand that Google might not care much about this (Chrome itself is a data collection platform), but I really don't get why Mozilla is so lenient about it as well, as their main differentiator has been user privacy for years.

Re: Mozilla’s DNS over HTTPs

#529

Earlier quoted context omitted.

> Even if browsers didn't use DoH, other devices could. Precisely so. > I don't think it makes sense to bemoan the newfound existence of safer infrastructure for everyone just because devices you don't like can also use that infrastructure. I'm not. First, I don't think this is actually a "safer infrastructure" compared with other DNS encryption schemes, because it opens a new hole. Second, this isn't about "devices…

> First, I don't think this is actually a "safer infrastructure" compared with other DNS encryption schemes, because it opens a new hole. Browsers are completely correct to treat the network as hostile in their default configurations, unless explicitly configured to trust something. More prevalent end-to-end encryption is a good thing. And DoH makes it easier to get encrypted DNS requests through without having them…

> More prevalent end-to-end encryption is a good thing.

I agree -- I am not arguing against more prevalent e2e crypto at all.

> If an encrypted DNS scheme is blockable by you, it's blockable by an ISP.

Perhaps, but it's also possible (unless you're using DoH) to evade those blocks without a great deal of difficulty.

I'm not arguing with anything you've said here, really. I'm just pointing out that the way that DoH works means that there is a security hole that makes it very easy for marketers and other spies to evade your protections against them.

So yes, DoH brings some security gains. But at the same time, it also brings some security losses. Whether that tradeoff is good for you should be a decision you can make -- but again, due to the way DoH works, you no longer have that choice available to you without going to extreme measures like I have.

Re: Mozilla’s DNS over HTTPs

#530

Earlier quoted context omitted.

I trust my own DNS provider much more than I trust Cloudflare to be honest. Also, most DNS requests over that “insecure protocol” happened over a single network hop or two and never left the infrastructure of the ISP. Cloudflare is now a public company and they need to aggressively monetize their services. Selling browsing data is a lucrative business and becoming “the” DNS provider for most users (while locking out…

American ISPs can and do sell your data legally. I don't really trust my ISP (I run my own DNS server at home and tunnel its requests over to a cloud VM), but I trust Cloudflare even less.

"Legally" is dubious. Intercepting any private wire communication is a clear violation of federal law (e.g. 18 U.S. Code § 2511), and a violation of the law in many states (e.g. CA PC 631).

Unfortunately, the US government is one of the larger users of ISP surveillance activities, benefiting through the purchase of private data as well as using administrative subpoena to obtain the data collected by ISPs without due process or meaningful oversight.

This creates a conflict of interest which I believe is preventing the US from zealously enforcing existing criminal law which would be otherwise sufficient to significantly reduce surveillance by communications providers.

Post reply on HN