Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
91–100 of 211 posts
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#92Earlier quoted context omitted.
> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…
> Actually not only does Comcast say they don't do that... Just like they said they didn't forcibly reset BitTorrent connections (until they did). Just like they said they didn't silently institute bandwidth caps (until they did). Just like they said they didn't hijack NXDOMAIN responses (until they did). Just like they said they didn't intercept plain-text HTTP connections and inject their own traffic into them (unt…
Consumer contracts? Because Mozilla having a business contract with Comcast is certainly not the same as you having a consumer contract - Mozilla has the resources to drag Comcast to court should they be found to ignore the agreement.
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#93Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…
> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…
It's a weird way to phrase "I work on this, we don't capture any information about customers site visits" or "I work on this we don't capture any information about domain lookups" or whatever.
When a customer gets a contract with Comcast are you saying the contract includes that Comcast will not filter/log their domain lookups in any way?
To others: what's the penalty of they breech that contract? Do they actual have anything at risk?
In UK ISPs couldn't make such a contract as the gov obliges DNS filtering of some domains, AIUI.
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#94Earlier quoted context omitted.
> Actually not only does Comcast say they don't do that... Just like they said they didn't forcibly reset BitTorrent connections (until they did). Just like they said they didn't silently institute bandwidth caps (until they did). Just like they said they didn't hijack NXDOMAIN responses (until they did). Just like they said they didn't intercept plain-text HTTP connections and inject their own traffic into them (unt…
> With all due respect, I have personally had contracts with Comcast in the past and have experienced firsthand how well they honor those -- and I am certainly not the only one! Consumer contracts? Because Mozilla having a business contract with Comcast is certainly not the same as you having a consumer contract - Mozilla has the resources to drag Comcast to court should they be found to ignore the agreement.
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#95I don't know how we can have privacy and Comcast in one sentence. We have a saying where I come from that translates roughly to "Putting the Wolf to Guard the Sheep". If you don't have any other option but to be with comcast my recommendation is to run Pi-Hole + DoH.
I do run PiHole. Any tips on how to do the `DoH` side of the equation? edit: this looks to do the trick: https://docs.pi-hole.net/guides/dns-over-https/
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#96Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#97Earlier quoted context omitted.
If Comcast sells DNS data now, they open themselves up to penalties from the both FTC and Mozilla. FTC because they enforce privacy policies, and Mozilla because of the contract they have. I would say this Mozilla changing the overall ecosystem for the better.
Do we know what the actual penalties are? I have trouble believing that they are of any substance. Additionally, I think it's safe to say that Comcast has years and years of experience in finding "loopholes" and/or other "workarounds" in its agreements. > I would say this Mozilla changing the overall ecosystem for the better. You obviously have much more faith in Comcast than I do. Let's hope you're right.
So long as the penalty is less than the value they derive from violating the agreement, they will abuse it.
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#98Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…
> I'm really confused why Mozilla would agree to this. If it's anything like their CloudFlare deals, then Mozilla did this because they were able to secure contracts that provide additional privacy protections for Mozilla's customers that the parent company doesn't normally provide to end-users. In theory, those contracts should be enforceable in court. Whether or not you think the companies Mozilla contracts with wi…
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#99Earlier quoted context omitted.
> Actually not only does Comcast say they don't do that... Just like they said they didn't forcibly reset BitTorrent connections (until they did). Just like they said they didn't silently institute bandwidth caps (until they did). Just like they said they didn't hijack NXDOMAIN responses (until they did). Just like they said they didn't intercept plain-text HTTP connections and inject their own traffic into them (unt…
> With all due respect, I have personally had contracts with Comcast in the past and have experienced firsthand how well they honor those -- and I am certainly not the only one! Consumer contracts? Because Mozilla having a business contract with Comcast is certainly not the same as you having a consumer contract - Mozilla has the resources to drag Comcast to court should they be found to ignore the agreement.
Comcast has proven themselves to be uninterested in adhering to their contractual obligations. You bet your ass they are 1) figuring out how to work around their contract with Mozilla without attracting legal attention, and 2) making contingency plans for winning any resulting lawsuit.
Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
#100Earlier quoted context omitted.
Only for sites with dedicated IPs. If they're hosted on some sort of cloud service then the ISP has to sniff the SNI data. And with ESNI coming to encrypt it that hole will be plugged soon.
That just means moving from the ISP in a prime position for snooping to various CDNs being in that prime position. You traded one master for another.
No. By definition, last mile ISP sees 100% of net-bound traffic. "Various CDNs" itself already represents a dilution of that view, and are not universal themselves. It's an inherent improvement even outside of other factors. But there are other factors, including a decrease in the level of natural monopoly. Last-mile ISPs often have zero effective competition, and even with one or two there are often high change over costs, longer term contracts involved, etc. The closer you get to the net's core however, the more bandwidth there is and the more players there are and in turn vastly more competition potential. That's not a guarantee sure, but it absolutely makes a difference. There's also a limiting factor principle at work: even if you do trust a given ISP, how does that help you avoid CDNs anyway?
It's the same reason that spinning up your own instance of an algo VPN on some VPS and funneling all your home and mobile traffic through that may have practical benefits. Sure in principle the VPS (or data center if you go on your own metal) provider could try spying as well. But competition there is fierce, the average technical level of users is higher, major business interests are involved in reputation, and swapping to another provider is utterly trivial. The incentives and business models for the likes of Amazon/DigitalOcean/Google/Microsoft/OVH/Scaleway/Vultr/[...] in their compute offerings are completely different from the likes of AT&T/Charter/Comcast/T-mobile/Verizon. So it is in fact reasonable to expect a difference in the level of shenanigans too, and hey, if not you can easily move, which also in turn makes it much easier as a practical matter to retaliate (sue), which virtuously further decreases the likelihood of shenanigans.