Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

681–690 of 777 posts

Re: Mozilla’s DNS over HTTPs

#681

Earlier quoted context omitted.

Just 2-3 years ago, normal DNS to CloudFlare or Google DNS were enough to bypass my ISP's DNS redirection. Then those got disabled and while I switched to DoH, many others switched to paid VPNs. Now they've moved up to SNI blocking. They may catch on to the trend and block DoH IPs too if DoH becomes popular.

Frankly, if your ISP is that aggressive, your best bet is a VPN. DoT and DoH will always offer imperfect privacy even with widespread ESNI.

VPNs are routinely blocked in China and elsewhere.

Re: Mozilla’s DNS over HTTPs

#682
post #487
post #449

Earlier quoted context omitted.

Your ISP is literally selling this information right now in the US. What are you even talking about? Use google if you don't like CF, or just disable it! Do a little threat modeling here please. Let's say CF sells this data, what do they know about you other than your IP and the sites you visit? While your ISP,employer,school,etc... Can tie that activity to you as a person. Being compelled legally? I did not know pri…

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

I'm an EU citizen as well.

EU ISPs may not sell your data for advertising purposes but they do log your traffic in order to report it to local security agencies.

I understand that in the EU we enjoy stronger privacy laws, however trusting your ISP, given they have the ability to link your traffic to your real name and address, is incredibly naive.

For protecting privacy we need both laws and technology.

Re: Mozilla’s DNS over HTTPs

#683
post #343
post #206

Earlier quoted context omitted.

I suppose my model is that every connected device and app, every web site someone visits, is malware. My household is full of things collecting data and passing it on to entities I don't wish to share that data with. How do I stop that when my ability to control what happens on my own network has been been reduced to Can access the Internet over 443, or not ?

My question is how does DoH contributes to that in practice/theory. If a malicious/incompetent app/device wants to access random servers with DoH they would need to include a DoH implementation and then DoH offer nothing more than VPNs. In this context I do not understand if you are worried to have wireguard installed on your connected devices. If you are talking about Firefox itself, then disable it. I sympathize wi…

> I do not understand how DoH changes things in a household settings.

Imagine you run a PiHole or use a service like OpenDNS. It doesn't matter what you've chosen to use or block, what matters is that you've made a choice to utilize DNS filtering for certain things.

You soon discover that some apps and devices don't respect your DNS decisions. They make money or derive other value through communications that are blocked by certain DNS-based filters, so they query 8.8.8.8 or some other DNS directly. You figure out how to make them respect your choice, through a combination of restricting DNS egress and DNAT at the router, and all is well again.

Mozilla and Chrome come along with DoH. That's alright. You can configure them not to. There's the canary domain, so you don't even need to configure browsers manually, tho I expect the canary will eventually go away -- it is destined to be "abused" by every entity in a position to get away with it.

What's going to come next is real the problem: Every entity which can benefit from being able to bypass DNS filters is going to move to DoH. It's in their best interests to do so. They don't need to respect the canary. You won't even be able to tell what they're doing because everything is encrypted with TLS and have pinned their certificates.

App will do it. Embedded devices will do it. Actual malware will do it.

This outcome is inevitable and that is my objection to the mere existence of DoH.

Re: Mozilla’s DNS over HTTPs

#684

Earlier quoted context omitted.

It asks the user if they want to allow an extension to "Access Browsing History" [1]. That seems pretty explicit and self-explanatory to me. [1] https://support.mozilla.org/en-US/kb/permission-request-mess...

No, it would be straightforward if they asked the user something like this: "Is it ok that this extension sends every single URL you open to an untrusted third party for processing? Please note that URLs might contain sensitive data like access tokens or session information." Even so, I don't think such an API should exist. And if you absolutely need to have something like this you should restrict it to domain inform…

Wasn't there a big story on HN about how chrome had disabled the ability for plugins to see your URLs and how adblocker plugin makers where up in arms about it?

Re: Mozilla’s DNS over HTTPs

#685

Earlier quoted context omitted.

DoT only solves the SNI problem during the DNS request itself. It doesn't do a thing about the SNI during the request to the actual website, which is where all the privacy concerns are. Sure, but until we have encrypted SNI, which is in draft, meta data is going to leak, but that's a separate issue from either DoT or DoH. But because DoT doesn't use HTTPS, you don't get some of its downsides like using cookies for tr…

DoH (edit from DoT) doesn't use cookies, it is stateless. But your original comment didn't mention that anyway, it only mentioned SNI.

From "The Big DNS Privacy Debate" [1]:

DoH shares the benefits and downsides of HTTPS. It sends out more trackable data than regular DNS, simply because HTTP supports things like headers and cookies. TLS session resumption functions as another tracking mechanism.

There’s a draft RFC [2] to address these and other privacy issues that weren't specified in the original RFC for DoH.

[1]: https://labs.ripe.net/Members/bert_hubert/the-big-dns-privac...

[2]: https://www.ietf.org/archive/id/draft-dickinson-doh-dohpe-00...

Re: Mozilla’s DNS over HTTPs

#686

Earlier quoted context omitted.

AFAIK, when one turns on DoH, Firefox's trr.mode defaults to 2 . And that's the default behaviour most would want except for the ones using pi-hole et al.

In general, yes, that solves the problem for local domains. But anyone who needs to do anything at all complicated is going to have trouble with this, not just Pi-Hole users. For example, take your average John Doe who uses Firefox. Not particularly technically competent. A new version of Firefox comes out, and all the Archive.is domains break. Who does he blame for that, and how does he solve the problem? What's hap…

> the admin of these domains returns fake addresses to Cloudflare from their authoritative DNS server

Well, this explains why Archive.is never works...

Re: Mozilla’s DNS over HTTPs

#687

Earlier quoted context omitted.

I think China has demonstrated that countries are willing to do that.

China is a special case though. They're large enough to populate their own internet with things. Most countries aren't that large.

If the ISP (or Nation) is willing to block google or cloudflare IP-ranges then you will have to be a moving target. Using tor and similar. For normal shitty ISPs thats not an option

Re: Mozilla’s DNS over HTTPs

#688
post #511
post #478

Earlier quoted context omitted.

> It sends all the users DNS queries to Cloudflare, adding a new party it removes many parties (some unknown) who have no legal oversight, and adds a select parties who are legally bound to respect your privacy. > because the user's destination IPs remain unencrypted This makes no sense. your ISP cannot see that you are visiting facebook because the IP shows up us cloudflare urrrghhh! > At the moment you can disable…

> who are legally bound to respect your privacy. Come on, this is an overstatement. They have a non-public contract with mozilla. What happens if they break it and get caught? Probably the only consequence is that firefox stops using cloudflare ... eventually. Look at what has happened with misbehaving CAs. The responses have ranged between nothing and removing them 5 years later. > your ISP cannot see that you are v…

> Look at what has happened with misbehaving CAs.

OK. Perhaps you have some examples in mind?

> The responses have ranged between nothing and removing them 5 years later.

Certainly you've got an example of "nothing" and of "removing them 5 years later" to start with, right?

DigiNotar is the most obvious example of a "misbehaving CA" that you might be concerned about. In June 2011 their services were broken into and they decided not to tell anybody. There were no technologies in place at that time which could detect problems like this without DigiNotar's assistance. At the end of August a google.com certificate issued this way was used to attack Iranian web users, but Google's Chrome browser had pinning protection (only for Google's own services) and so at this point it detected the attack in progress.

Mozilla shipped updated Firefox versions which distrusted DigiNotar's public root in about 48 hours (not "5 years") and over subsequent days distrusted the entire DigiNotar hierarchy including those parts the Dutch national government had insisted were fine (they were not fine).

The public reactions at the time mirror your incredulity by the way, people who grep'd their newly updated Firefox and discovered DigiNotar's CA certificate (in fact blacklisted explicitly) as "proof" of a conspiracy by Mozilla to send all their traffic to some scary foreign company.

Perhaps DigiNotar just isn't recent enough for you. So let's look at rather smaller deviations from the more recent past. In 2015 WoSign (a QiHoo 360 company which operated a CA) acquired the Israeli CA StartCom in secret. No significant countries have any mechanism in place to detect this (a potentially hostile acquisition of a private company) and so the browser vendors had no idea until mid-2016.

Not telling Mozilla about this was already a violation of both agreements (for WoSign and for StartCom). But in 2016 WoSign/ StartCom (now one shared controlling mind) minted new certificates using SHA-1 signatures for several outfits, notably an Australian financial services company named Tyro. Since new SHA-1 certificates were prohibited in browsers in 2016 these certificates were back-dated to appear they'd been issued in 2015, another violation of the rules. The Tyro cert was probably actually issued in June 2016.

After conducting an investigation which included having Israeli documents assessed by a Hebrew-speaking lawyer and a bunch of digital forensics work, by September of that year Mozilla was instituting partial distrust of WoSign and StartCom, and in 2017 the browser distrusted them entirely. Other vendors followed suit (very belatedly in the case of Microsoft).

Re: Mozilla’s DNS over HTTPs

#689
post #623
post #487

Earlier quoted context omitted.

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

No, it is not an opinion. It is technically accurate, but may not be relevant to your particular situation. Firefox is used outside of the EU. Speaking of which... > I am always using the US-EN Firefox version Wait, so you want the US version of Firefox to be tuned to EU legal policy?

I want the legal policy to be based on where I use it from, not which language I download. As a .nl citizen I personally hate language localization, set my locale to en_US.UTF-8, and always ensure I download the international versions of my browser. I would expect at the very least the legal policy to be tailored towards where I download it from, but preferably where I use it from.

Re: Mozilla’s DNS over HTTPs

#690
post #487

Earlier quoted context omitted.

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

I'm an EU citizen as well. EU ISPs may not sell your data for advertising purposes but they do log your traffic in order to report it to local security agencies. I understand that in the EU we enjoy stronger privacy laws, however trusting your ISP, given they have the ability to link your traffic to your real name and address, is incredibly naive. For protecting privacy we need both laws and technology.

Unless you always use VPN, they can still do that, even with DOH.

And if you use VPN, they can see your traffic.

Personally I trust my ISP more than some random VPN provider on the net.

Post reply on HN