Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

711–720 of 777 posts

Re: Mozilla’s DNS over HTTPs

#711
post #443

As a resident of a country whose government and ISPs heavily and habitually censor the Internet for political reasons, I for one truly appreciate Firefox's DoH. They should also enable 'network.security.esni.enabled' by default because the censors here have upgraded from DNS to SNI-based blocking. I get it that better solutions are possible, but got to teach people to first walk before teaching them to run. AFAIK, Ch…

I wonder what the implications will be for TCP-over-DNS, which besides bypassing firewalls, can also provide anonymity in a different way.

TCP-over-DNS, together with the draft RFC for encrypted resolver to authoritative communication, altolows for more end-to-end style encryption. Clients could do their own secure resolving without relying on a central service.

Re: Mozilla’s DNS over HTTPs

#712
post #630

Earlier quoted context omitted.

"Your ISP is literally selling this information right now in the US" Your ISP will literally still be able to sell this information after DoH is rolled out. Because they can see what IPs you're connecting to and in most cases hostnames can be trivially and automatically determined knowing only the IP. Unless we centralise HTTP through a handful of gateways like we're doing with DNS (hello Cloudflare). At which point,…

Very limited with TLS. With webhosts, the PTR record means little. CDNs also obfuscate your destination. Shared hosting sites only care about the host field in the encrypted HTTP as well. Especially given the oversaturation of IPv4. Keep in mind, it's not just what you visit but how often as well and a lot other details (dns is cached)

> Very limited with TLS. With webhosts, the PTR record means little.

TLS+SNI sends the `Host` you are connecting to in plain text. eSNI is not yet widely deployed.

Centralizing DNS without centralizing HTTP (e.g. domain fronting) does not solve the leak of connection metadata.

Re: Mozilla’s DNS over HTTPs

#713

If you are a network administrator and want none of this, look at that: https://support.mozilla.org/en-US/kb/canary-domain-use-appli... Basically, make use-application-dns.net. return an error (any kind will do). Filter it in your recursor for example. Having the browser change a fundamental behaviour that used to stand for decades is highly problematic. If nothing else, it is the network administrator who should hav…

Has anyone verified that this actually works? My company's DNS administrators have already made this change. use-application-dns.net returns SERVFAIL when I run "dig" on my machine on the corporate network. But if I enable DNS over HTTPS in Firefox, it very clearly still uses the Cloudflare resolvers. We have some split-horizon zones set up (resolve to 10.x IP's internally, and public IP's externally). When I tick th…

If you did it explicitly, I think there are no heuristics.

https://bugzilla.mozilla.org/show_bug.cgi?id=1614751

Re: Mozilla’s DNS over HTTPs

#714

Earlier quoted context omitted.

First of all we are not talking about the trustworthiness of VPNs, that's a separate discussion entirely. And no, I don't trust my ISP more than I trust my VPN, but I understand your mistrust as VPNs are indeed not so private as they are marketed. But imo this is throwing the baby with the bathwater. Go to Germany, download a movie either from the Pirate Bay or see one from one of the many illegal websites streaming…

Sure in that case makes sense to use VPN. > I predict there will be plenty of privacy respecting services to choose from. Why, where is the money in there ? Sure there might be some, but many ? Call me cynic but I don't think google(one of the biggest public DNS servers atm) or clodflare(probably second biggest) are providing this service out of goodness of their harts. If you worry about DNS that much, running your…

I don't know why Google and Cloudflare provide this service and I don't really care, because it's irrelevant.

DoH is first of all a protocol. If you run your own DNS resolver at home, surely you'll be able to run your own DoH server too.

Also your requests will no longer be sent in clear text, which means that a Wifi administrator at your local coffee shop won't be able to see your queries and responses, which with the regular DNS protocol are in cleartext, in which case your home DNS server does not help — unless you're on your own network in full control of your router, or run your own VPN, communications with your home DNS resolver are just as vulnerable.

The value of something like DoH is clear, regardless of the motivation that Cloudflare and Google have for providing such a service for free.

---

Speaking of which, accessing pirated content is not the only case I worry about — another problem I have with my ISP is that they serve me a 404 Not Found page filled with ads on domains that aren't available. This is in an EU country.

Also back when HTTPS wasn't forced on Google, the searches were logged and people were automatically flagged for problematic queries and then potentially monitored for years. One of the topics that triggered automatic flagging was child sexual abuse — I know because I helped a local campaign, building an awareness website, etc, only to be informed of such practices by an acquaintance working for our internal security agency.

And while today this may happen for legitimate reasons, tomorrow it might happen for people criticizing the government. Look no further than countries like Turkey or Hungary.

Personally, coming from communism, I fear the nanny state more than I fear big companies from other countries.

Re: Mozilla’s DNS over HTTPs

#715
post #61

Earlier quoted context omitted.

> The comment about having “no plans” to enable this outside the USA seems a bit disingenuous The comment actually very clearly says "we do not have plans to roll out the feature in Europe or other regions at this time ". Also I have mixed feelings about this. On one hand yeah, encryption is great and someone sitting between me and my ISP will no longer be able to monitor my DNS queries. On the other hand I don't fee…

Why? If you know how to run your own pihole, you know how to turn off DoH? You're not being forced into this, a default setting is getting flipped and you're entirely free to go "no thanks" and flip it back, so if you trust whoever owns the IP that you're using as real, unencrypted DNS server, then just keep using that. Same as for folks who want to keep using unencrypted emails "because encrypted mail isn't fully en…

> DoH (in general, not Mozilla's problem)

Parsing the text helps with understanding it. And the fact that Mozilla allows me to flip back says nothing about those general cases. I do not expect everyone to give you the choice.

Re: Mozilla’s DNS over HTTPs

#716
post #219
post #61

Earlier quoted context omitted.

> The comment about having “no plans” to enable this outside the USA seems a bit disingenuous The comment actually very clearly says "we do not have plans to roll out the feature in Europe or other regions at this time ". Also I have mixed feelings about this. On one hand yeah, encryption is great and someone sitting between me and my ISP will no longer be able to monitor my DNS queries. On the other hand I don't fee…

You may find it noteworthy that Mozilla provides ways to configure this behavior as you please: https://github.com/mozilla/policy-templates#dnsoverhttps

> DoH (in general, not Mozilla's problem)

You may find noteworthy that my comment had 2 points. One where I don’t feel like DoH will bring much benefit in the browser today, and one where DoH in general will just give you, the user, even less control over what you’re sending out. I can’t imagine everyone giving you the option to switch, all the TRRs being actually trusted, or even being able to pick the TRR in most setups (IoT? Your random Google product?).

Re: Mozilla’s DNS over HTTPs

#717
post #165

Earlier quoted context omitted.

If you don't want DoH, you are not forced to use it. Yes its enabled by default, but it doesn't mean you cannot go into the settings menu and deactivate it.

Hmm, unless you're trying to control what comes in/out your home network .. in which case you're screwed. But you can switch it off in your own browser. I was a happy pihole user. I could choose to allow DNS lookups, and blacklist using OpenDNS. If I install Firefox at home, then I can't block problematic sites; and Cloudflare will use this to sell the idea to advertiser for TVs and such, so it looks like Google/Clou…

I also use PiHole at home, and lets be honest, if we know how to setup a PiHole, deactivating Firefox DoH is not going to be a problem for us.

DoH is not meant for us, it is meant for the average people who have no tech background. Just because it will cost us a few minutes to configure, we shouldn't deny the overall benefit it will bring to most.

Re: Mozilla’s DNS over HTTPs

#719

Earlier quoted context omitted.

FWIW, wrt 1: you can use dnscrypt and a bitbar plugin to have this at the OS level on Mac. It’s a faff to setup but once it works it really does work. https://www.dnscrypt.org/ Optional for menu icon: https://getbitbar.com/ and https://github.com/jedisct1/bitbar-dnscrypt-proxy-switcher

https://www.dnscrypt.info The .org is not legit.

So sorry, my bad. Mobile Google fail :( thanks for vetting !

Re: Mozilla’s DNS over HTTPs

#720
post #662

Earlier quoted context omitted.

If you're worried about your ISP snooping on you and tampering with DNS records, the tools we have today already offer better privacy and trust than DoH, DoT, DNSCurve or DNSCrypt. Just use a DNSSEC capable resolver in combination with a VPN. All other options today are effectively theater.

DNSSEC is the least useful of the lot. It only authenticates, doesn't encrypt, so it's not enough on its own, you have to use it in combination with a VPN. But the VPN would be enough on its own between the client and the recursive DNS, since it does both. Between the recursive and authoritative DNS the VPN wouldn't exist, but if the attacker is there then DNSSEC is in trouble again because it still doesn't encrypt (…

You're conflating privacy with trust. DNSSEC gives you trust, the VPN gives you "last mile" privacy. DoH is only designed for last mile so useless in encrypting the resolver chain between you and the root servers.

Currently there is no way to get a fully encrypted chain (the root servers would need to support DoT or something similar and they don't nor are there any plans for them to do so afaik).

So the best (form a privacy and trust PoV) you can achieve is as I've outlined: VPN together with a DNSSEC resolver (with verification enabled). Over time you can hope for DoT to gain wider adoption so more and more of the upstream resolver chain is encrypted.

Post reply on HN