Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

591–600 of 777 posts

Re: Mozilla’s DNS over HTTPs

#591

In order for Cloudflare (or anyone) to be a part of this program they have to comply with a particular set of rules. Limiting data. Your DNS data can reveal a lot of sensitive information about you, and currently DNS providers aren’t subject to any limits on what they can do with that data; we want to change that. Our policy requires that your data will only be used for the purpose of operating the service, must not…

> just like they can do with any of the ISPs There is a 3rd option: Operating your own recursive resolver.

I've found this harder and harder over the years. My usual MOD was installing and configuring the caching-nameserver BIND package in rpm-based RHEL-downstream distros and MaraDNS in everything else. I've just kind of given up because reasons but I'm still very supportive of any of these kinds of efforts.

Re: Mozilla’s DNS over HTTPs

#592
post #468

Earlier quoted context omitted.

I dont use my ISP as my DNS provider, I have a custom setup using PiHole and other methods to provide secure DNS Resolution Firefox should not be forcing this shit on me, time to search for yet another browser that will respect users. Mozilla is clearly more interested in commercial viability via their partnerships with large corporations (like CloudFlare) then in protecting Users

The only way to solve the ISP DNS inspection problem is by one of: * Using DoH. For this to work with PiHole, you need to have a DoH resolver on the device, and then instruct the PiHole to recurse to that resolver instead - possibly your own in a VM somewhere? * Using a permanent encrypted VPN to your own machine in the cloud and routing all DNS through that, then recursing to some DNS that you trust. * Write your ow…

DNS over TSL (DoT) is a much better alternative to DoH, at least when it comes to the ability to be tracked.

For example, because it’s not using HTTP, there are no cookies or SNI to worry about.

More at https://news.ycombinator.com/item?id=22418005.

Re: Mozilla’s DNS over HTTPs

#593
post #449
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

> Your ISP is literally selling this information right now

No, mine is not.

> Use google if you don't like CF

Google is no better.

> or just disable it!

It is never okay to hijack my DNS lookups. Posting a note someplace about how it can be restored does not change the fact that you hijacked it, and does not make it okay.

> This is not adding a new party that can surveil you

Given that the DoH provider is a new party with which most of my requests had no contact before, that is an absurd claim.

> this is reducing risk by separating who can see your DNS from who can see your traffic.

No, it is not. My ISP can still see the domain names of sites I visit, via both SNI and OCSP. They can also deduce the same information in most cases, via address correlation. (Thankfully, I chose an ISP that respects privacy.)

This change quietly hands my lookups over to another party as well. If I hadn't noticed the announcement, or didn't have enough technical knowledge to fully understand and revert the change before it went live, my lookups would be pwned.

> The idea is to have eSNI ubiquity to where TLS traffic will conceal the sites you visit

I don't care what your idea is for the future. It doesn't exist today, so is not relevant to what you have done today.

(And even if it did, it would not excuse hijacking my DNS lookups.)

Re: Mozilla’s DNS over HTTPs

#594

Earlier quoted context omitted.

> ...it is a PITA, especially when roamining and you want to resolve hostnames available only in local networks. Not really. If you're not blackholing traffic at the dns-layer via DoH, set Firefox's trr.mode to 2 . Per documentation, at the cost of additional latency incurred, system-level / network-level resolvers should pick up the slack, provided they've been set as appropriate via DHCP or otherwise. Ref: https://…

If I sit any family member down in front of this comment, their eyes would glaze over. Not only is what you mention a PITA, it's impossible for most people.

That's a bit unfair, because this comment was obviously not addressed to the mere mortal. For you family member, a "how to" with a lot of screenshots and red arrows is probably more appropriate.

Re: Mozilla’s DNS over HTTPs

#595

Earlier quoted context omitted.

I'm surprised that they wouldn't block the DNS providers in your country though?

Just 2-3 years ago, normal DNS to CloudFlare or Google DNS were enough to bypass my ISP's DNS redirection. Then those got disabled and while I switched to DoH, many others switched to paid VPNs. Now they've moved up to SNI blocking. They may catch on to the trend and block DoH IPs too if DoH becomes popular.

Frankly, if your ISP is that aggressive, your best bet is a VPN. DoT and DoH will always offer imperfect privacy even with widespread ESNI.

Re: Mozilla’s DNS over HTTPs

#596

Questions I couldn’t find answers to in the post or linked info about the Trusted Resolver Program: What’s in it for the Cloudflare & NextDNS? Are they getting paid to handle this traffic or paying to have the opportunity to access this data? Can users outside the US opt-in? The comment about having “no plans” to enable this outside the USA seems a bit disingenuous. Hard to believe they built this program / feature a…

After eSNI becomes mainstream, network level ad blocking will be extremely difficult. My guess is there will be a huge ad blocking subscription play in the future.

They’re usurping control and calling it a privacy enhancement so they can sell the control back to us with per user per month pricing.

Re: Mozilla’s DNS over HTTPs

#597
post #449

Earlier quoted context omitted.

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

> Your ISP is literally selling this information right now No, mine is not. > Use google if you don't like CF Google is no better. > or just disable it! It is never okay to hijack my DNS lookups. Posting a note someplace about how it can be restored does not change the fact that you hijacked it, and does not make it okay. > This is not adding a new party that can surveil you Given that the DoH provider is a new party…

They're not doing it in secret. Use a different browser if you don't like it, or fork it.

Mozilla have made a value judgement that DoH is more useful to end users than the supposed privacy loss. You're free to disagree, but neither of you is objectively correct.

Re: Mozilla’s DNS over HTTPs

#598
post #428

Earlier quoted context omitted.

It's interesting how bubbles work. In my world, everyone has a story about how an obscure but interesting to surveil service that they were involved with was DDOS attacked and immediately cloudflare sales was showing up offering to mitigate the attack for free by MITMing their traffic. ... Even showing up on the IRC channels of open source projects. I've personally witnessed it three times. Even if it weren't for the…

This is the most convoluted conspiracy theory I've read so far this decade. You profess not to believe these theories, or at least not the first one. So why then repeat? It's just more untruths poisoning this debate, like any other going on these days. And how does Cloudflare get the blame in your telling of this story, when it's your unnamed sources "you've heard" believing paranoid stories? DDOS were a thing before…

Pre Snowden you might have had a point.

Re: Mozilla’s DNS over HTTPs

#599
post #597

Earlier quoted context omitted.

> Your ISP is literally selling this information right now No, mine is not. > Use google if you don't like CF Google is no better. > or just disable it! It is never okay to hijack my DNS lookups. Posting a note someplace about how it can be restored does not change the fact that you hijacked it, and does not make it okay. > This is not adding a new party that can surveil you Given that the DoH provider is a new party…

They're not doing it in secret. Use a different browser if you don't like it, or fork it. Mozilla have made a value judgement that DoH is more useful to end users than the supposed privacy loss. You're free to disagree, but neither of you is objectively correct .

> or fork it

Seems like this is where things are going. None of the main browsers respect users enough today to the point that they might not even stay usable without forking.

Re: Mozilla’s DNS over HTTPs

#600
post #205
post #178

Earlier quoted context omitted.

DOH can also be implemented on every server.

People keep talking past each other on this because somehow DoH got conflated with Cloudflare. DoH is a protocol. It has better security than unencrypted DNS. (So do several others, like DNSCurve, DNSCrypt, or routing your DNS queries over a VPN.) The objection people have is not that it's encrypted, it's that Mozilla implemented it in the browser instead of the OS and thereby ignores the DNS you configured in your O…

If you're worried about your ISP snooping on you and tampering with DNS records, the tools we have today already offer better privacy and trust than DoH, DoT, DNSCurve or DNSCrypt.

Just use a DNSSEC capable resolver in combination with a VPN. All other options today are effectively theater.

Post reply on HN