Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

671–680 of 777 posts

Re: Mozilla’s DNS over HTTPs

#671
post #649

Earlier quoted context omitted.

I think it's a good call out to keep in mind the guidelines, but technically the original comment also breaks guidelines. Two wrongs don't make a right, but I would suggest trying to avoid the appearance of personal bias when calling out guidelines infractions on a comment without also calling out infractions within the context equally.

It wasn't my intention to make an inflammatory comment. My statement was strongly worded, but it is my informed opinion as a subject matter expert: As someone who worked in ISP networking for over a decade, worked at Mozilla, and work on network protocol, I feel that I'm entitled to have a strongly stated opinion and I believe I substantiated it in my post. I'm also happy to have a polite discussion justifying it fur…

[deleted]

Re: Mozilla’s DNS over HTTPs

#672

Earlier quoted context omitted.

DoT only solves the SNI problem during the DNS request itself. It doesn't do a thing about the SNI during the request to the actual website, which is where all the privacy concerns are.

DoT only solves the SNI problem during the DNS request itself. It doesn't do a thing about the SNI during the request to the actual website, which is where all the privacy concerns are. Sure, but until we have encrypted SNI, which is in draft, meta data is going to leak, but that's a separate issue from either DoT or DoH. But because DoT doesn't use HTTPS, you don't get some of its downsides like using cookies for tr…

DoH (edit from DoT) doesn't use cookies, it is stateless. But your original comment didn't mention that anyway, it only mentioned SNI.

Re: Mozilla’s DNS over HTTPs

#673
post #614

Earlier quoted context omitted.

I think it's a good call out to keep in mind the guidelines, but technically the original comment also breaks guidelines. Two wrongs don't make a right, but I would suggest trying to avoid the appearance of personal bias when calling out guidelines infractions on a comment without also calling out infractions within the context equally.

I don't see how the GP comment broke the site guidelines. "Snake oil" is close to name-calling, but I don't think it's really over the line, and if we started moderating HN comments for that kind of thing, there would be a huge backlash from the community. Is there something else that I missed? These things are matters of degree in any case, and "what are you even talking about" is clear cut.

Specifically I was thinking about this:

> Don't be snarky. Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.

The original comment had equally strong phrasing on what amounts to an informed opinion:

> I'm so sad to see Mozilla move forward with this massive attack on user privacy.

The insinuation that this is an attack on user privacy is a bit of an escalation in description. In truth much of the following information describes a potential threat to user privacy, for it to be an attack one would have to provide evidence of intent.

> Firefox DoH is snake oil, plain and simple.

I would argue this statement could be construed as snarky (at least that is how I interpreted it).

Generally speaking, I don't consider myself an expert, but I do think I have a more informed opinion than most (and no doubt many HN readers have even better informed opinions than my own). And while I do see the merits behind the points raised in the original comment, I do think it could have been presented better.

Re: Mozilla’s DNS over HTTPs

#674
post #625

Earlier quoted context omitted.

I don't get how that's a swipe, it is not a rhetorical question, my intent there is to literally ask what he's talking about given the arguments made. I did not attack the commenter personally,"brigade" or an ad-hominem argument. I think you might be misunderstandig our conversation here, this being a text medium it is hard to comminicate tone and body language. It's not uncommon for me to say a phrase like in techni…

It's easy to get hung up on specific words, so it might be easier to consider meanings. What is the meaning of the phrase "What are you even talking about?" Is it a question? If so, what answer were you hoping for? If I take you at your word that it's not rhetorical, then I could replace your question with "what do you mean?" – however, if you don't know what the poster means, why does the rest of the comment continu…

It's not rhetorical and it is not literal either. A rephrase can be "what you are saying makes no sense for the reasons I am about to lay out and I would like it if you can address my points below, based on my understanding the argumets you made lack basic coherency, please tell me what you think of my counter-argument".

If this was a work email in a super-uptight place I would say something like that. Had I known that simple phrase I use all the time would be so controversial I would have avoided it or rephrased.

You chose to question my motives and assume the likely explanation is that I am atracking the person instead of their are argument. I am insinuating that their argument sounds ridiculous but I am not implying that as a fault of their intellect or personality but a lack of perspective where sharing my perspective might help them change an opinion.

I will not defend my personality and motives being questioned when I made no attempt to do so, I also did not the attack the person themselves in anyway. You should not assume malice. I think @dang saw me break rules in the past over one of the politcally charged threads and assumed it was in my personality. Feel free to review my post history on technical topics like this, I make best effort to avoid ad-hominem or anything resembling an insult. Presumption of malice itself is unfair.

I have nothing to gain by attacking anyone. And even if I did, you should look at the context od what I said after that phrase to find out what my intent was. If I don't promote myself or say anything against the person why are you assuming malice?

What about when I said "please try some threat modeling here" is that being snarky as well? It can be if you assume malice. I hope no such assumptions are made.

Either way, I did make a mistake: after years on HN, I keep forgeting that it is to be treates like a corporate/work environment. Two friends using my ever so controversial phrase would not assume malice or police for snarkiness, but two coworkers or paries of a business meeting/engagement would.

I will be careful to be more aware of the environment.

Oh, and not all discourse is interpersonal. It is done interpersonally but the subject of the discourse is does not have to be the other party themselves,their intellect or character (and was not the case in my response -- very obviously)

Re: Mozilla’s DNS over HTTPs

#675

Earlier quoted context omitted.

I'm surprised that they wouldn't block the DNS providers in your country though?

Just 2-3 years ago, normal DNS to CloudFlare or Google DNS were enough to bypass my ISP's DNS redirection. Then those got disabled and while I switched to DoH, many others switched to paid VPNs. Now they've moved up to SNI blocking. They may catch on to the trend and block DoH IPs too if DoH becomes popular.

Which country are you in/which countries do you see this happening in if you don’t mind me asking?

Re: Mozilla’s DNS over HTTPs

#676

Earlier quoted context omitted.

I'm surprised that they wouldn't block the DNS providers in your country though?

Won't help if cloudflare sticks the resolver on the same IP range as regular cloudflare sites. Countries would have to choose to block most of the internet.

I think China has demonstrated that countries are willing to do that.

Re: Mozilla’s DNS over HTTPs

#677

Earlier quoted context omitted.

Exactly. To control DoH we need to start to MITM all connections and block everthing else unless whitelisted.

For home network operators who value controlling the name resolution of devices they 'own' MITM won't be enough once embedded device manufacturers start using certificate pinning w/ DoH.

Obviously, there will be a choice not to buy them / keep them offline.

Re: Mozilla’s DNS over HTTPs

#678

Earlier quoted context omitted.

Won't help if cloudflare sticks the resolver on the same IP range as regular cloudflare sites. Countries would have to choose to block most of the internet.

I think China has demonstrated that countries are willing to do that.

China is a special case though. They're large enough to populate their own internet with things. Most countries aren't that large.

Re: Mozilla’s DNS over HTTPs

#679
post #487

Earlier quoted context omitted.

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

> I am always using the US-EN Firefox version because frankly why would I use translated software when I can understand and use the original. This is maybe not the topic of discussion, but the argument is that your computer is your tool, and the computer should speak your language and adapt itself to you, and not the other way around. For this reason I like and prefer software that speaks my native language! However,…

I absolutely loathe software in my native language. I will go out of my way to avoid it, because it makes everything more complicated.

Re: Mozilla’s DNS over HTTPs

#680
post #649

Earlier quoted context omitted.

I think it's a good call out to keep in mind the guidelines, but technically the original comment also breaks guidelines. Two wrongs don't make a right, but I would suggest trying to avoid the appearance of personal bias when calling out guidelines infractions on a comment without also calling out infractions within the context equally.

It wasn't my intention to make an inflammatory comment. My statement was strongly worded, but it is my informed opinion as a subject matter expert: As someone who worked in ISP networking for over a decade, worked at Mozilla, and work on network protocol, I feel that I'm entitled to have a strongly stated opinion and I believe I substantiated it in my post. I'm also happy to have a polite discussion justifying it fur…

I'm glad your intention was not malignant! I didn't mean to imply it was, truthfully I was just trying to also contribute to keeping discourse civil.

See my comment above about specific things that (I personally think) could have been phrased a bit better; I am not saying you're comment was unhelpful or deserves reprimand. Just wanted to point out to the comment(er) that both comments had aspects that could have been phrased a bit better and chastising one is not as helpful to improving discourse as providing complete feedback in the interest of being fair.

Disclaimer: I deleted a previous comment because on re-reading I think I meandered a bit and thought I could do better.

Post reply on HN