Live data from Hacker News

Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

arstechnica.com

81–90 of 211 posts

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#81
post #50

> "Adding ISPs in the TRR program paves the way for providing customers with the security of trusted DNS resolution, while also offering the benefits of a resolver provided by their ISP such as parental control services and better optimized, localized results," the announcement said. What? No! Why would DNS have "optimized, localized results"?

> Why would DNS have "optimized, localized results"? Any content that is CDN-based (which is most content) dynamically responds to DNS queries based on network and geographic location - to support CDN localization. In this way, Akamai for example knows the end user is in Boston on a Comcast network and will send the recursive DNS server a dynamic response that points to a directly-connected local-to-Boston content se…

Any serious CDN is doing that with anycast, not with geodns which has tons of drawbacks.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#84

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

Mozilla loves partnerships. They don't have to be revenue streams. They just preferably have to be hostile to user freedom.

Mozilla needs to fix the internal incentives that lead to this situation.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#85

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

It is entirely possible for one group (or incentive) within Comcast's organization to work towards that goal, and another group or incentive within Comcast to work against it.

Some things that make me trust this claim:

- That privacy policy

- That contract

- Association with trustworthy brands like Mozilla

- Work on encrypted DNS

- Consumer trust could theoretically be financially valuable to them

- Basic morals of Comcast employees

Some things that make me distrust it:

- Cultivated an infamous litany of consumer abuses

- Lobbied for regulations to harm consumers

- Engaged in regulatory capture with the FTC/FCC

- Have continually profited from their abusive business practices, and continue to profit in spite of atrocious levels of consumer trust

I believe that Comcast only wants to respect user privacy insofar as it helps them maintain a facade of trustworthiness and retain customers. If they ever get the opportunity to back out of that privacy-conscious posturing and turn it into money, I think history has proven that the winner of those two internal groups is clearly going to be the money side not the moral side.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#86

Earlier quoted context omitted.

> Route DNS to trusted non-profit entities. I'm sure you know this, but some readers might not. DNS is totally insecure. Even if you change your DNS server from the default to 1.1.1.1 or whatever, your ISP can and does still read and/or intercept these requests. This sort of interference is absolutely trivial to implement, even at scale. Don't think it isn't happening to you.

... which is exactly why DoH is gaining attention. But I keep wondering: Can't the ISP trivially correlate the accessed IP addresses with their corresponding sites even without DNS query data?

Trivial in the individual case is not trivial at scale.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#87
post #45

Earlier quoted context omitted.

Only for sites with dedicated IPs. If they're hosted on some sort of cloud service then the ISP has to sniff the SNI data. And with ESNI coming to encrypt it that hole will be plugged soon.

That just means moving from the ISP in a prime position for snooping to various CDNs being in that prime position. You traded one master for another.

Let's try the one that hasn't eagerly and willingly (that we know of) gone against their users.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#88
post #10

Earlier quoted context omitted.

> It's not a lie. Cloudflare is the nameserver, and the CDN. So after resolution the end user still has just a Cloudflare IP. > In 2011 Google wrote an IETF draft to send Client IP information using the EDNS0 extension and this is usually called ‘edns-client-subnet’. As a DNS client, it means that a truncated version of your IP address will be added into the DNS request. The DNS server will use this truncated IP addr…

There is only a single "archive" that does not allow access to Cloudflare DNS users - not many. It is also exceedingly unlikely that you have greater density of anycast PoPs than Cloudflare's 200+. In your case, you have zero...

Even archive.today has given up on that crusade; I noticed a few days ago that they don't block me anymore (I use Cloudflare DNS) so they have to have stopped within the past couple weeks.

So now AFAIK the number of sites that block DNS resolvers which do not forward edns-client-subnet is zero. As it should be.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#89
post #45

Earlier quoted context omitted.

That just means moving from the ISP in a prime position for snooping to various CDNs being in that prime position. You traded one master for another.

Let's try the one that hasn't eagerly and willingly (that we know of) gone against their users.

That heavily depends on who those parties are. E.g. a european might trust their local ISP (subject to GDPR) more than an american CDN (subject to the cloud act and NSLs).

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#90

Earlier quoted context omitted.

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

If Comcast sells DNS data now, they open themselves up to penalties from the both FTC and Mozilla. FTC because they enforce privacy policies, and Mozilla because of the contract they have. I would say this Mozilla changing the overall ecosystem for the better.

What good is a contract between Mozilla and Comcast to me if Mozilla is unwilling to notice/care/sue when Comcast breaks that contract because Mozilla has a financial incentive to turn a blind eye?
Post reply on HN