Live data from Hacker News

Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

arstechnica.com

151–160 of 211 posts

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#151
post #59

Earlier quoted context omitted.

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

Respectfully, Comcast has an ATROCIOUS privacy record. Full stop. A quick search came up with [1] [2] [3]. Your employer actively and repeatedly abuses the privacy and trust of its customers. It also lobbies for damaging policies. I do not trust Comcast. Firefox associating itself with Comcast makes me trust Firefox significantly less. [1] https://oag.ca.gov/news/press-releases/attorney-general-kama... [2] https://ww…

> Your employer... It also lobbies for damaging policies.

To be sure, jlivingood isn't just some enterprise grunt with an opinion, but VP of Technology Policy & Standards.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#152
post #100

Earlier quoted context omitted.

> You traded one master for another. No. By definition, last mile ISP sees 100% of net-bound traffic. "Various CDNs" itself already represents a dilution of that view, and are not universal themselves. It's an inherent improvement even outside of other factors. But there are other factors, including a decrease in the level of natural monopoly. Last-mile ISPs often have zero effective competition, and even with one or…

You have a contractual relation with your ISP and they're in your jurisdiction so at least in theory you have legal recourse. Advocating for ESNI on the other hand means argueing for more centralization towards entities which are far more removed from you where you have little recourse. So as far as incentives go they may be more beholden to some law enforcement agency than you the non-customer. There are difference,…

I think you bring up good points but your takeaway is 180 off.

Different jurisdiction means less likely to be answerable to your local government should they be oppressive.

The fact you don't have a contractual relationship with a CDN is a good thing because it becomes trivial simply to stop using them, should the need arise. Don't like Cloudflare? block them. Your choice of websites will be reduced greatly but you still have an operational internet connection.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#153
post #59

Earlier quoted context omitted.

Respectfully, Comcast has an ATROCIOUS privacy record. Full stop. A quick search came up with [1] [2] [3]. Your employer actively and repeatedly abuses the privacy and trust of its customers. It also lobbies for damaging policies. I do not trust Comcast. Firefox associating itself with Comcast makes me trust Firefox significantly less. [1] https://oag.ca.gov/news/press-releases/attorney-general-kama... [2] https://ww…

> Your employer... It also lobbies for damaging policies. To be sure, jlivingood isn't just some enterprise grunt with an opinion, but VP of Technology Policy & Standards.

I'm the queen of England.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#154

Earlier quoted context omitted.

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

> Actually not only does Comcast say they don't do that... Just like they said they didn't forcibly reset BitTorrent connections (until they did). Just like they said they didn't silently institute bandwidth caps (until they did). Just like they said they didn't hijack NXDOMAIN responses (until they did). Just like they said they didn't intercept plain-text HTTP connections and inject their own traffic into them (unt…

On top of that, I'm totally mystified by what would cause this sudden change of heart from Comcast. Why do they want to provide this "service" to users, if they supposedly don't get anything out of it? If they're not profiting off the data, why not just let Firefox users connect to Cloudflare for DNS, as they're already doing to access 50% of the popular sites out there?

Why fight Mozilla to let them provide a service which is only going to cost them money to run?

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#155
post #144

Earlier quoted context omitted.

> Why does Mozilla need to care about Comcast's opinion on this, and try to work out an "agreement" with them? Money.

You are being downvoted, but are not wrong. A lot of people confuse Mozilla the foundation with Mozilla the corporation, which is the profit seeking branch and the entity which holds the IP. They are different utilities with different goals. They hold similar contracts with Google and you would all do well to at very least become aware of their financial prospectus.

Which is why I insist on running my own fork off FF, stripping and adding stuff as I see fit, and compiling it myself.

Those who don't are subjected to the whims of either the foundation or corproation of Mozilla.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#156
post #59

Earlier quoted context omitted.

Respectfully, Comcast has an ATROCIOUS privacy record. Full stop. A quick search came up with [1] [2] [3]. Your employer actively and repeatedly abuses the privacy and trust of its customers. It also lobbies for damaging policies. I do not trust Comcast. Firefox associating itself with Comcast makes me trust Firefox significantly less. [1] https://oag.ca.gov/news/press-releases/attorney-general-kama... [2] https://ww…

> Your employer... It also lobbies for damaging policies. To be sure, jlivingood isn't just some enterprise grunt with an opinion, but VP of Technology Policy & Standards.

Do you have a link for this? This is a pretty big difference in disclosure.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#157
post #111

I'm confused. For me, a major selling point of DoH is it hides DNS queries from your ISP, which has detailed personal information about you. And if you're locked into Comcast, you're operating with completely eroded trust from the get-go. Clearly, DNS statistics are extremely valuable to Comcast, or they would not have engaged with Mozilla to get back the data, nor would they have raised hell with Congress. I would n…

Mozilla cannot enable one provider by default. People already complained that Cloudflare was initially the only choice. Users at the moment are expected to choose their provider anyway. This deal is about Mozilla picking Comcast by default for Comcast customers. This is essentially as if they'd be using the network's default, because Comcast is the network's default already, being what people get via DHCP. They can a…

Having just done a Firefox install recently, the UX when prompted to enable DoH on first run did not set the expectation of choosing a provider.

Is there something you can point to that speaks to that expectation?

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#158

Earlier quoted context omitted.

Comcast's ASNs and networks are documented in ARIN's WHOIS database and various route registries. Hell, Comcast probably publishes a list on their own web site. So, yeah, Mozilla can easily determine if a user is on the Comcast network just from their IP address. Also, while Comcast actually has a bunch of DNS servers spread across the country, I believe that nowadays they're mostly "promoting" the use of 75.75.75.75…

> So, yeah, Mozilla can easily determine if a user is on the Comcast network just from their IP address. I mean, how can the determine it's a Comcast DNS server configured on my network? I might be a Comcast customer w/ a custom DNS server configured. If it's a fixed IP check, I suppose that list is in the browser.

What makes you think they are doing that? To jlgaddis's point, they are likely checking what IP address you are coming from over the public Internet. They can see who operates it, and knows that it's Comcast. Then they change the options in your browser.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#160
post #134

Tin foil hat time but I can't help feeling a lot of things promoted as privacy solutions like VPNs and DoH are just aggregating data in a handful of locations so it is easier to intercept. Sure they have privacy policies but are they worth the paper they are written on when state actors are bound by a totally different set of rules? I recently changed my local dnssec resolver to forward to quad9 and cloudflare using…

Indeed. As it stands, trust is merely being shifted from one set of parties (ISPs) to another set (big DNS/CDN providers). Apparently that's attractive enough to a lot of people who prefer to send their queries to a foreign company than to their own ISP, but has it changed anything fundamental?
Post reply on HN