Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

691–700 of 777 posts

Re: Mozilla’s DNS over HTTPs

#691
post #683
post #343

Earlier quoted context omitted.

My question is how does DoH contributes to that in practice/theory. If a malicious/incompetent app/device wants to access random servers with DoH they would need to include a DoH implementation and then DoH offer nothing more than VPNs. In this context I do not understand if you are worried to have wireguard installed on your connected devices. If you are talking about Firefox itself, then disable it. I sympathize wi…

> I do not understand how DoH changes things in a household settings. Imagine you run a PiHole or use a service like OpenDNS. It doesn't matter what you've chosen to use or block, what matters is that you've made a choice to utilize DNS filtering for certain things. You soon discover that some apps and devices don't respect your DNS decisions. They make money or derive other value through communications that are bloc…

My question is how is DoH different from contacting 1.1.1.1 over https and asking for DNS information without the DNS protocols.

I understand why people do not want this and want control over their own network, I find that a commendable goal. I do not understand how DoH specifically introduces anything new since you could already get DNS data from HTTPS API

Re: Mozilla’s DNS over HTTPs

#692

As a resident of a country whose government and ISPs heavily and habitually censor the Internet for political reasons, I for one truly appreciate Firefox's DoH. They should also enable 'network.security.esni.enabled' by default because the censors here have upgraded from DNS to SNI-based blocking. I get it that better solutions are possible, but got to teach people to first walk before teaching them to run. AFAIK, Ch…

Since they're apparently using Cloudflare, there will likely be censorship, too. It'll just be censorship that is deemed politically correct in the US / Western world, like cutting off sites like the Daily Stormer, 8chan etc.

Cloudflare has already done that before.

Re: Mozilla’s DNS over HTTPs

#693
post #487

Earlier quoted context omitted.

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

I'm an EU citizen as well. EU ISPs may not sell your data for advertising purposes but they do log your traffic in order to report it to local security agencies. I understand that in the EU we enjoy stronger privacy laws, however trusting your ISP, given they have the ability to link your traffic to your real name and address, is incredibly naive. For protecting privacy we need both laws and technology.

[deleted]

Re: Mozilla’s DNS over HTTPs

#694
post #665

Earlier quoted context omitted.

> you respond with how Linux users can set up unbound. Like, well argued! I did write, that DISTRIBUTIONS should set this up by default, not the users. And Microsoft could do the same for Windows, as could Apple (with almost zero effort) for MacOS-X

>For example on Linux you could do this with running a localhost instance of unbound Not seeing _distributions_ there

Look again. Topmost paragraph. I'll quote myself:

>> Because that's something that OS vendors could easily and trivially deploy with only minimal effort.

"OS vendors" aka "distribution creators"

And then in the 3rd paragraph, I wrote (sic!):

>> Just put that as out-of-the-box setup into default Linux distributions' installation:

Re: Mozilla’s DNS over HTTPs

#695
post #487

Earlier quoted context omitted.

Sorry for channeling the dude here but that is just, like your opinion man. I think many of the critical voices now are coming from the EU. We have data protection laws. The ISP can't just sell browsing data. That has been illegal since before we had data protection laws, that is actually legally the same as opening other people's letters and reading them. So ... different threat model over here. I am always using th…

> I am always using the US-EN Firefox version because frankly why would I use translated software when I can understand and use the original. This is maybe not the topic of discussion, but the argument is that your computer is your tool, and the computer should speak your language and adapt itself to you, and not the other way around. For this reason I like and prefer software that speaks my native language! However,…

From my point of view translated software often just means that googling errors is harder

Re: Mozilla’s DNS over HTTPs

#697

Earlier quoted context omitted.

I'm an EU citizen as well. EU ISPs may not sell your data for advertising purposes but they do log your traffic in order to report it to local security agencies. I understand that in the EU we enjoy stronger privacy laws, however trusting your ISP, given they have the ability to link your traffic to your real name and address, is incredibly naive. For protecting privacy we need both laws and technology.

Unless you always use VPN, they can still do that, even with DOH. And if you use VPN, they can see your traffic. Personally I trust my ISP more than some random VPN provider on the net.

First of all we are not talking about the trustworthiness of VPNs, that's a separate discussion entirely. And no, I don't trust my ISP more than I trust my VPN, but I understand your mistrust as VPNs are indeed not so private as they are marketed. But imo this is throwing the baby with the bathwater.

Go to Germany, download a movie either from the Pirate Bay or see one from one of the many illegal websites streaming content and prepare for a letter (delivered to your home address) with a huge fine and a legal threat within a month.

Not that I'm a huge fan of pirating content, even if some cases like Sci-Hub have the moral high grown, but this goes to show just how trustworthy an ISP is, in an EU country with some of the best privacy laws ... and in such cases a VPN is absolutely mandatory.

---

DoH hides your DNS queries — if you visit an HTTPS website, the traffic might be protected via HTTPS, but the domain name is clearly seen.

Of course, the ISP still sees the IP you're communicating with, but due to SNI and industry practices nowadays of putting websites behind CDNs, IPs don't necessarily reveal the website you're communicating with.

DoH also makes it harder for ISPs to block or redirect your access to certain websites. For instance it makes it harder to block Pirate Bay based on the whims of your local government. Now certainly Cloudflare can also be compelled to block websites like Pirate Bay, but the DoH service you're communicating with is customizable, you can pick whatever service you want and just like VPNs, I predict there will be plenty of privacy respecting services to choose from.

And DoH is not foolproof, it doesn't solve all of our privacy needs, it's just a piece of the puzzle, but a necessary one.

Re: Mozilla’s DNS over HTTPs

#698
post #687

Earlier quoted context omitted.

China is a special case though. They're large enough to populate their own internet with things. Most countries aren't that large.

If the ISP (or Nation) is willing to block google or cloudflare IP-ranges then you will have to be a moving target. Using tor and similar. For normal shitty ISPs thats not an option

Cloudflare and Google's dns resolvers got a lot of adoption bc they provided a way for normal people to get around censorship, but they're inherently censorable bc they're run by centralized companies. There are new initiatives aiming to create a distributed dns layer which are promising like https://handshake.org.

Re: Mozilla’s DNS over HTTPs

#699
post #530

Earlier quoted context omitted.

"Legally" is dubious. Intercepting any private wire communication is a clear violation of federal law (e.g. 18 U.S. Code § 2511), and a violation of the law in many states (e.g. CA PC 631). Unfortunately, the US government is one of the larger users of ISP surveillance activities, benefiting through the purchase of private data as well as using administrative subpoena to obtain the data collected by ISPs without due…

Are you sure about that? This passed in 2017 and I don't think it's been reversed: http://clerk.house.gov/evs/2017/roll202.xml

Wow, that's one polarized vote…

Re: Mozilla’s DNS over HTTPs

#700
post #611

Earlier quoted context omitted.

mike@blob:~$ host 208.80.153.224 224.153.80.208.in-addr.arpa domain name pointer text-lb.codfw.wikimedia.org. mike@blob:~$ openssl s_client -connect 208.80.153.224:443 2>&1 | openssl x509 -text|grep Subject: Subject: C = US, ST = California, L = San Francisco, O = "Wikimedia Foundation, Inc.", CN = *.wikipedia.org Yeah, our ISPs are going to be totally in the dark thanks to DoH. /s

> mike@blob:~$ host 208.80.153.224 224.153.80.208.in-addr.arpa domain name pointer text-lb.codfw.wikimedia.org. mike@blob:~$ openssl s_client -connect 208.80.153.224:443 2>&1 | openssl x509 -text|grep Subject: Subject: C = US, ST = California, L = San Francisco, O = "Wikimedia Foundation, Inc.", CN = *.wikipedia.org Yeah, our ISPs are going to be totally in the dark thanks to DoH. /s minjiexin.com resolves to the sam…

In this particular case, the ISPs db entry could simply be "customer visited either wikipedia.org or minjiexin.com", and that would be practically as good as before DoH.

Or the ISPs database could simply be of IP addresses connected to, and the purchaser of that database could apply identification based on which other IPs were connected to around a similar time.

If it's your argument that mapping IPs to "websites visited" is not 100% accurate, then of course you're correct... So what we need to do is figure out how accurate it is. Because if the answer to that question is 95%, then the whole value proposition of DoH flys out of the window. Why massively centralise DNS to just make a tiny dent in the problem?

If the answer to that question is 5% rather than 95%, then I guess that would mean we've centralised the web so far already behind gatekeepers like Cloudflare+Google+AWS+Microsoft, that it doesn't really matter if we go and centralise DNS for web usage in the same way, as the web is already fucked.

Post reply on HN