Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

621–630 of 777 posts

Re: Mozilla’s DNS over HTTPs

#621

Earlier quoted context omitted.

That's not a good counterargument. Why you ask? Because that's something that OS vendors could easily and trivially deploy with only minimal effort. For example on Linux you could do this with running a localhost instance of unbound, and having a DHCP client hook script updating unbound's configuration for domain specific authorative DNS servers based on the DHCP options for nameserver and domain name. Just put that…

I like how someone on HN tells you that ordinary users have no idea how to set up their own DNS servers and you respond with how Linux users can set up unbound. Like, well argued! There is also something poetic about how the people that know how and are inclined to set up their own unbound servers on their laptops are getting worse security than everyone else. That sparks joy for me.

> you respond with how Linux users can set up unbound. Like, well argued!

I did write, that DISTRIBUTIONS should set this up by default, not the users.

And Microsoft could do the same for Windows, as could Apple (with almost zero effort) for MacOS-X

Re: Mozilla’s DNS over HTTPs

#622
post #561
post #556

Earlier quoted context omitted.

It's absolutely not hardcoded.

Not technically, but you know what I mean.

In this forum, only you know what you mean until you write words. When you write a word like "hardcoded", which means a specific thing, is it not reasonable to expect people to think that you meant "not really hardcoded".

As one of my favorite people told me once: words mean things. The words we use matter, as humans do not have telepathy.

Re: Mozilla’s DNS over HTTPs

#623
post #487
post #449

Earlier quoted context omitted.

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

No, it is not an opinion. It is technically accurate, but may not be relevant to your particular situation.

Firefox is used outside of the EU. Speaking of which...

> I am always using the US-EN Firefox version

Wait, so you want the US version of Firefox to be tuned to EU legal policy?

Re: Mozilla’s DNS over HTTPs

#624
post #473

Earlier quoted context omitted.

Don't those disadvantages apply just the same to your blacklisting of marketers' DNS servers?

Indeed they do, which is why that's not a sufficient defense all by itself. The next level up is to block the DNS lookups that happen when the spies are trying to find their servers. That's what DoH prevents.

I think maybe you misunderstood what I'm asking.

Why couldn't such a spy just hardcode their own DNS server IP address, rather than using your network provided DNS server? If the answer is that you'll blacklist the spy's DNS servers, then how is that any different than the situation with DoH?

DoH isn't adding any value for the spy unless you are doing deep packet inspection of any packet that contains DNS data.

Re: Mozilla’s DNS over HTTPs

#625
post #491
post #449

Earlier quoted context omitted.

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

> What are you even talking about? Can you please edit swipes like that out of your comments when posting to HN? They break the site guidelines and provoke others into doing worse. https://news.ycombinator.com/newsguidelines.html

I don't get how that's a swipe, it is not a rhetorical question, my intent there is to literally ask what he's talking about given the arguments made. I did not attack the commenter personally,"brigade" or an ad-hominem argument. I think you might be misunderstandig our conversation here, this being a text medium it is hard to comminicate tone and body language. It's not uncommon for me to say a phrase like in technical arguments with people I get along with very well. This is a technical discourse not a interpersonal one, my disagreement is with the supposed factual statements not the person as such how can it be a swipe against them?

That said, I will avoid that specific phrase on this site as you asked.

Re: Mozilla’s DNS over HTTPs

#626
post #449

Earlier quoted context omitted.

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

Note that US ISP "Comcast/Xfinity" does not, so at the very least, that's one safe harbor amidst the rest. https://corporate.comcast.com/stories/privacy-with-comcasts-...

That's a blog post, not a privacy policy. Not to mention the phrasing still allows for them to do this, as long as the information isn't personally identifiable.

Re: Mozilla’s DNS over HTTPs

#627

Earlier quoted context omitted.

AFAIK, when one turns on DoH, Firefox's trr.mode defaults to 2 . And that's the default behaviour most would want except for the ones using pi-hole et al.

In general, yes, that solves the problem for local domains. But anyone who needs to do anything at all complicated is going to have trouble with this, not just Pi-Hole users. For example, take your average John Doe who uses Firefox. Not particularly technically competent. A new version of Firefox comes out, and all the Archive.is domains break. Who does he blame for that, and how does he solve the problem? What's hap…

> the admin of these domains returns fake addresses to Cloudflare from their authoritative DNS server

Why?

Re: Mozilla’s DNS over HTTPs

#628
post #614

Earlier quoted context omitted.

I think it's a good call out to keep in mind the guidelines, but technically the original comment also breaks guidelines. Two wrongs don't make a right, but I would suggest trying to avoid the appearance of personal bias when calling out guidelines infractions on a comment without also calling out infractions within the context equally.

I don't see how the GP comment broke the site guidelines. "Snake oil" is close to name-calling, but I don't think it's really over the line, and if we started moderating HN comments for that kind of thing, there would be a huge backlash from the community. Is there something else that I missed? These things are matters of degree in any case, and "what are you even talking about" is clear cut.

Person a: I like the blue stuff in oranges Person b: what are you even talking about? Oranges do not have a blue inside.

Now what is a swipe about this or breaking a guidline. It did give the impression ( to me at least) as if I was being picked on. But I think in reality you probably misunderstood the tone and intent. Of course this is just my opinion, what you say is the law here and I intend to abide.

Re: Mozilla’s DNS over HTTPs

#629
post #411
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

It's also yet an other instance of the web browser taking over something that (IMO) ought to belong to the OS. Now with DoH if I have DNS issues I have to figure out if it's related to the browser's DNS or the system DNS. I can't use command line tools like dig or ping to troubleshoot the issue because it's not what the browser is doing. If DoH is so great I want to enable it for all my applications, not just my web…

You can definitely do DNS over HTTPS/TLS for everything if you run your own DNS server, either locally or somewhere on your network. I do this, and it works great, both methods have their own advantages and disadvantages of course.

Re: Mozilla’s DNS over HTTPs

#630
post #449

Earlier quoted context omitted.

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

"Your ISP is literally selling this information right now in the US" Your ISP will literally still be able to sell this information after DoH is rolled out. Because they can see what IPs you're connecting to and in most cases hostnames can be trivially and automatically determined knowing only the IP. Unless we centralise HTTP through a handful of gateways like we're doing with DNS (hello Cloudflare). At which point,…

Very limited with TLS. With webhosts, the PTR record means little. CDNs also obfuscate your destination. Shared hosting sites only care about the host field in the encrypted HTTP as well. Especially given the oversaturation of IPv4.

Keep in mind, it's not just what you visit but how often as well and a lot other details (dns is cached)

Post reply on HN