Earlier quoted context omitted.
> We continue to explore enabling DoH in other regions, and are working to add more providers as trusted resolvers to our program. DoH is just one of the many privacy protections you can expect to see from us in 2020. Cloudflare is just one of the initial providers and they indicate that they are adding more. Also, I'm assuming you can add your own custom provider based on the screenshot in the article. You can just…
> Cloudflare is just one of the initial providers and they indicate that they are adding more. Also, I'm assuming you can add your own custom provider based on the screenshot in the article. You can just disable the feature as well. Or go for https://firejaildns.wordpress.com/ - Linux workstation DoH proxy, more than 60 DoH providers. When you start, the proxy chooses one at random. You can also set the servers in Fi…
Mozilla’s DNS over HTTPs
661–670 of 777 posts
Re: Mozilla’s DNS over HTTPs
#662Earlier quoted context omitted.
People keep talking past each other on this because somehow DoH got conflated with Cloudflare. DoH is a protocol. It has better security than unencrypted DNS. (So do several others, like DNSCurve, DNSCrypt, or routing your DNS queries over a VPN.) The objection people have is not that it's encrypted, it's that Mozilla implemented it in the browser instead of the OS and thereby ignores the DNS you configured in your O…
If you're worried about your ISP snooping on you and tampering with DNS records, the tools we have today already offer better privacy and trust than DoH, DoT, DNSCurve or DNSCrypt. Just use a DNSSEC capable resolver in combination with a VPN. All other options today are effectively theater.
Between the recursive and authoritative DNS the VPN wouldn't exist, but if the attacker is there then DNSSEC is in trouble again because it still doesn't encrypt (no confidentiality). What can be used on that path is DNSCurve, because it does encrypt even where there isn't a VPN.
The majority of domains also aren't DNSSEC signed anyway, so it doesn't even authenticate them.
Re: Mozilla’s DNS over HTTPs
#663Earlier quoted context omitted.
Not technically, but you know what I mean.
In this forum, only you know what you mean until you write words. When you write a word like "hardcoded", which means a specific thing, is it not reasonable to expect people to think that you meant "not really hardcoded". As one of my favorite people told me once: words mean things. The words we use matter, as humans do not have telepathy.
Re: Mozilla’s DNS over HTTPs
#664Earlier quoted context omitted.
Is there an indication they are moving in that direction already? (Genuine non-sarcastic question) They've built up a considerable amount of good-will in developer communities. Is there some historical indicator with cloudfare that suggests they are going to blow it all on their path to monetization, or are we extrapolating from other VC backed companies (which may be an understandable position to take, but why?)
It's interesting how bubbles work. In my world, everyone has a story about how an obscure but interesting to surveil service that they were involved with was DDOS attacked and immediately cloudflare sales was showing up offering to mitigate the attack for free by MITMing their traffic. ... Even showing up on the IRC channels of open source projects. I've personally witnessed it three times. Even if it weren't for the…
Funnily enough Cloudflare supports DNS over Tor[1][2], and I think they are the only one. Please let me know if there are others!
[1] https://developers.cloudflare.com/1.1.1.1/fun-stuff/dns-over...
Re: Mozilla’s DNS over HTTPs
#665Earlier quoted context omitted.
I like how someone on HN tells you that ordinary users have no idea how to set up their own DNS servers and you respond with how Linux users can set up unbound. Like, well argued! There is also something poetic about how the people that know how and are inclined to set up their own unbound servers on their laptops are getting worse security than everyone else. That sparks joy for me.
> you respond with how Linux users can set up unbound. Like, well argued! I did write, that DISTRIBUTIONS should set this up by default, not the users. And Microsoft could do the same for Windows, as could Apple (with almost zero effort) for MacOS-X
Not seeing _distributions_ there
Re: Mozilla’s DNS over HTTPs
#666Earlier quoted context omitted.
Just 2-3 years ago, normal DNS to CloudFlare or Google DNS were enough to bypass my ISP's DNS redirection. Then those got disabled and while I switched to DoH, many others switched to paid VPNs. Now they've moved up to SNI blocking. They may catch on to the trend and block DoH IPs too if DoH becomes popular.
Frankly, if your ISP is that aggressive, your best bet is a VPN. DoT and DoH will always offer imperfect privacy even with widespread ESNI.
Re: Mozilla’s DNS over HTTPs
#667Earlier quoted context omitted.
> They can even see the url Only for plaintext http. For ssl/https - the hostname/ip can leak with SNI, but should be safe with ESNI (encrypted SNI). The URL should be in the request, which comes after the TLS handshake (hence SNI, so that the server can pick a certificate before knowing the HTTP HOST header). SNI is a problem - but not much worse than the fact that a mitm can see who talks to who (IP) - IMNHO.
ESNI is not in use yet (or just doesn't work). Start up tcpdump and check yourself. At best even it were currently use it only provides protection for sites which are hosted behind DOS mitigation services. (usually cloudflare...)
https://encryptedsni.com/ -> https://www.cloudflare.com/ssl/encrypted-sni/Re: Mozilla’s DNS over HTTPs
#668Earlier quoted context omitted.
It's interesting how bubbles work. In my world, everyone has a story about how an obscure but interesting to surveil service that they were involved with was DDOS attacked and immediately cloudflare sales was showing up offering to mitigate the attack for free by MITMing their traffic. ... Even showing up on the IRC channels of open source projects. I've personally witnessed it three times. Even if it weren't for the…
> So, I don't think cloudflare has amassed much goodwill at all, and that's even before getting into how their 'protection' made much of the internet unusable behind tor or other anonymization proxies. Funnily enough Cloudflare supports DNS over Tor[1][2], and I think they are the only one. Please let me know if there are others! [1] https://developers.cloudflare.com/1.1.1.1/fun-stuff/dns-over... [2] https://blog.clo…
Re: Mozilla’s DNS over HTTPs
#669Earlier quoted context omitted.
Good point. Sniffing traffic is orders of magnitude more expensive than simply logging DNS queries.
tcpdump -i any -s 1500 '(tcp[((tcp[12:1] & 0xf0) >> 2)+5:1] = 0x01) and (tcp[((tcp[12:1] & 0xf0) >> 2):1] = 0x16)' -nnXSs0 -ttt Is it though? This one liner works just fine for me on my gateway and is capturing quite a huge number of raw SNI names. 0x0110: c008 0016 0013 0010 000d c00d c003 000a ................ 0x0120: 00ff 0100 0113 0000 001d 001b 0000 186c ...............l 0x0130: 6f67 7369 6e6b 2e64 6576 6963 657…
But yes, it is possible.
One thing is though - TLS1.3 is getting more popular and so is session resumption. So even now quite a bit of traffic cannot be identified and it will get harder and harder.
Encrypting DNS requests is one required piece of the puzzle.
Re: Mozilla’s DNS over HTTPs
#670Earlier quoted context omitted.
I don't get how that's a swipe, it is not a rhetorical question, my intent there is to literally ask what he's talking about given the arguments made. I did not attack the commenter personally,"brigade" or an ad-hominem argument. I think you might be misunderstandig our conversation here, this being a text medium it is hard to comminicate tone and body language. It's not uncommon for me to say a phrase like in techni…
A polite way to say this would be "Can you clarify what your concern is?" or "Can you clarify what you're referring to?". The original phrase drips with disdain. If that's not the intended sentiment, then well, that's a challenge of conveying emotions in text. You could always include an emoji to better convey the meaning :-) Some phrases come with a built-in sentiment that people will assume exists unless it's overr…
I still maintain it was clearly not a swipe purely due to the fact that I made no attempts to attack the persons personality or intellect or to promote my own, as such my intellectual honesty and purity of intent should be given the benefit of the doubt.