Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

541–550 of 777 posts

Re: Mozilla’s DNS over HTTPs

#541
post #411
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

It's also yet an other instance of the web browser taking over something that (IMO) ought to belong to the OS. Now with DoH if I have DNS issues I have to figure out if it's related to the browser's DNS or the system DNS. I can't use command line tools like dig or ping to troubleshoot the issue because it's not what the browser is doing. If DoH is so great I want to enable it for all my applications, not just my web…

Chrome is bootable already. ChromeOS. :P

Re: Mozilla’s DNS over HTTPs

#542
post #537
post #522

Earlier quoted context omitted.

Your ISP can still see the IPs that you are talking to... What are you talking about? They can even see the url even if you dont use them as your DNS

> They can even see the url Only for plaintext http. For ssl/https - the hostname/ip can leak with SNI, but should be safe with ESNI (encrypted SNI). The URL should be in the request, which comes after the TLS handshake (hence SNI, so that the server can pick a certificate before knowing the HTTP HOST header). SNI is a problem - but not much worse than the fact that a mitm can see who talks to who (IP) - IMNHO.

ESNI is not in use yet (or just doesn't work). Start up tcpdump and check yourself.

At best even it were currently use it only provides protection for sites which are hosted behind DOS mitigation services. (usually cloudflare...)

Re: Mozilla’s DNS over HTTPs

#543

Earlier quoted context omitted.

Cloudflare states the same thing. In fact, Cloudflare provides much more detail than Comcast/Xfinity [0]. And, personally, I actually believe Cloudflare. If I have to choose between the two companies it's a no brainer. This is Cloudflare's business, and their business relies on them upholding their privacy promise. Comcast/Xfinity has, in the past, engaged in DNS hijacking [1]. Comcast has had the worst ACSI score ov…

Cloudflare's business lost them over $100 million last year alone. The way they operate right now is not a viable business, and we have no idea what they will change when they need to become one.

Maybe you're new to the tech/security space, but the majority of companies operate at a loss as they grow and pivot their business. If you follow Cloudflare they've only recently begun to start to sell into the enterprise space with new products as in the SASE space and beyond their traditional DDoS/WAF/encryption plays. Even with those "legacy" products - Cloudflare never heavily sold into large enterprise compared to more notable names in the hardware security space that they now are beginning to compete with. Their business is evolving to include field sales that are aligned to selling in this manner, which is relatively new for Cloudflare (comparatively).

But just stating that Cloudflare is operating in the red currently isn't a justification for anything as it doesn't mean anything positive or negative without understanding their operational business model and targets.

I'm guessing your statement is making a leap by assuming that because Cloudflare is operating at a loss currently that they're going to sell your data against what they publicly state in their privacy policy? For a growth company - that would be one of the dumbest things for them to do. Because if they are caught in that lie they will sink themselves.

Re: Mozilla’s DNS over HTTPs

#544
post #410

The underlying issue is that a DoH provider can craft the DNS answers individual users get if it wants to. Think about it: a Firefox DoH user could get different DNS answers than other apps get on the same machine using standard DNS on port 53, if Google or Cloudflare wanted to, because they’re essentially talking to different versions of the internet. Remember, all of the properties that allows HTTPS to be trackable…

What DoH implementation sends cookies?

They all can; that’s built in to HTTPS. Whether they will, we’ll have to wait and see.

Re: Mozilla’s DNS over HTTPs

#545

Anybody have any stats on what percentage of websites and or percentage of global web-traffic hits websites that are hosted on their own personal unshared IP, vs those that are hosted on shared IPs? Because if 90% of websites are hosted on unshared IPs, then this whole thing about DoH and/or ESNI providing some sort of privacy is complete bunk. An ISP can still see exactly what website you're visiting when connecting…

Multiple downvotes because I pointed out that the whole promise of DoH is that it stops ISP's from being able to see and sell which websites you're visiting, but ISP's will still be able to see and sell which websites you're visiting, unless we stick most websites behind shared IPs.

I guess that's step 2 in "advancing" the web.

Re: Mozilla’s DNS over HTTPs

#546
post #537
post #522

Earlier quoted context omitted.

Your ISP can still see the IPs that you are talking to... What are you talking about? They can even see the url even if you dont use them as your DNS

> They can even see the url Only for plaintext http. For ssl/https - the hostname/ip can leak with SNI, but should be safe with ESNI (encrypted SNI). The URL should be in the request, which comes after the TLS handshake (hence SNI, so that the server can pick a certificate before knowing the HTTP HOST header). SNI is a problem - but not much worse than the fact that a mitm can see who talks to who (IP) - IMNHO.

ESNI is still in draft.

Re: Mozilla’s DNS over HTTPs

#547
post #345

Earlier quoted context omitted.

> Firefox DoH is snake oil, plain and simple... Correct me if I'm wrong, but the concern I have about browser-controlled DoH is that it seems like it could make it harder for a tech-savvy user to assert control over their own network. IIRC, most network-level ad-blocking operates at the DNS level. I've also personally blocked telemetry by setting my router's DNS proxy to resolve certain telemetry servers to 0.0.0.0.…

Firefox tries to recognize some personalized DNS servers and prefer them to DoH in cases where it finds them. The FAQ here suggests that work is ongoing and they are hoping tech-savvy DNS alternatives used for things like parental controls and ad blocking meet them somewhere in the middle in terms of making it easier to Firefox to auto-disable DoH when a user has explicitly opted in to more power user configurations.…

> you should be able to find the Firefox settings on your devices to disable DoH,

You should be able to find a buried config option to regain your privacy is _not_ a position that we should consider acceptable!

There are serious logistical challenges keeping the option off even at a household level.

At the moment it isn't difficult to block at the network level, but presumably they'll start evading those blocks eventually or otherwise the claim that this is intended to prevent monitoring by ISPs will seem pretty hollow.

Re: Mozilla’s DNS over HTTPs

#548
post #449
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

"Your ISP is literally selling this information right now in the US"

Your ISP will literally still be able to sell this information after DoH is rolled out. Because they can see what IPs you're connecting to and in most cases hostnames can be trivially and automatically determined knowing only the IP.

Unless we centralise HTTP through a handful of gateways like we're doing with DNS (hello Cloudflare). At which point, why even bother calling it the web anymore.

Re: Mozilla’s DNS over HTTPs

#549

I'm getting pretty pissed off the with the arrogance of US internet tech companies sidestepping formal protocol design & industry adoption because it isn't moving "fast enough" for them. Without ESNI, DoH is essentially meaningless for the class of privacy invaders it is supposed to combat against. By the time ESNI is out, DoT would have had enough time to mature and gain wide enough adoption. DoT is better because a…

Seems to be a trend lately. Google recently announced they will start blocking downloads from http websites. Doesn't sound like a bad idea -- but isn't this more a discussion for IETF as well?

Re: Mozilla’s DNS over HTTPs

#550
post #404

Earlier quoted context omitted.

Agreed. Unless that contract includes heavy penalties for selling and/or losing that data, its toothless nonsense. The fact that the contract hasn't been published is also problematic. If everything is above board, why hide?

To be fair, publishing contracts like that isn't a standard practice. That alone is a sufficient explanation. It still would be better if it were.

Mozilla isn't a standard company and this isn't a standard situation.
Post reply on HN