Live data from Hacker News

Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

arstechnica.com

171–180 of 211 posts

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#171

Earlier quoted context omitted.

Do you have a link for this? This is a pretty big difference in disclosure.

https://blog.mozilla.org/blog/2020/06/25/comcasts-xfinity-in... Compare the username to the "Vice President, Technology Policy and Standards at Comcast Cable" in this blog post.

Thanks!

To save people the click.

User name in question: jlivingood

> Jason Livingood, Vice President, Technology Policy and Standards at Comcast Cable.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#172

Earlier quoted context omitted.

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

It is entirely possible for one group (or incentive) within Comcast's organization to work towards that goal, and another group or incentive within Comcast to work against it. Some things that make me trust this claim: - That privacy policy - That contract - Association with trustworthy brands like Mozilla - Work on encrypted DNS - Consumer trust could theoretically be financially valuable to them - Basic morals of C…

I am a Comcast employee myself, but these opinions are my own:

I appreciate your comment as you clearly and accurately frame that good people work there, Comcast earned its reputation with its actions, and that there may be competing interests / morals at play.

I can’t predict the future to say what wins out, but I feel like there are competing interests at play internal to the org. There are the business/markets, and then there is technology, products and experience pieces too.

an aside: I am somewhat disappointed to see a HN thread so populated with groupthink “Comcast is bad!” I’d expect that on theVerge comment board or YouTube comments. sigh

Anyways, I hear that the wake up call was probably about the time that the time warner merger fell through. I haven’t worked for them that long. It takes time to shift an org as large as Comcast to come to terms with the public’s resentment. I can say that, in my experience on the inside, the fundamental attitudes are very consumer friendly. I’m on the tech/product side of the house and we just want to make great stuff. Reliable, scalable entertainment and home automation kind of things, ya know? Comcast strives to be an admired company. So yeah, guess its work is cut out for it! Everything is designed today with accessibility and privacy at the outset. There’s a massive amount of truly brilliant engineers, developers, QA folks etc. working there. Not saying your distrust in Comcast wasn’t earned, however I believe conditions are not what they once were, thus some negative sentiments may be outdated today.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#173
post #148

Earlier quoted context omitted.

> Mozilla has the resources to drag Comcast to court They do not. Look at Mozilla's 1099 for proof.

Mozilla took Verizon to court.

Link? When was this? I'm only aware of Verizon suing Mozilla in 2017.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#174

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

You work(ed) on IPv6 as well, right? You get all the fun projects. :-)

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#175
post #168

Earlier quoted context omitted.

An IP address is often less specific than a hostname, and will become less useful over time due to IPv4 address space exhaustion and concentration of internet services among a small number of cloud providers. Widespread use of DOH therefore makes it harder for ISPs and middleboxes to interfere without collateral damage. It's far from perfect, but it'll help.

You might want to read this study on that topic: "What can you learn from an IP?" https://irtf.org/anrw/2019/slides-anrw19-final44.pdf

Interesting reference, thanks. I’m surprised there are so many site-unique IPs. Fingerprinting is less compelling in the case of blocking (I think?) but is certainly still a privacy problem.

Ultimately, all security is about raising the cost for attackers, and I think it’s a good thing that DOH will make middleboxes more expensive and less accurate. It would be a mistake to pitch it as being even close to a perfect solution to any problem, though.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#176

Earlier quoted context omitted.

An IP address is often less specific than a hostname, and will become less useful over time due to IPv4 address space exhaustion and concentration of internet services among a small number of cloud providers. Widespread use of DOH therefore makes it harder for ISPs and middleboxes to interfere without collateral damage. It's far from perfect, but it'll help.

Provided we get eSNI everywhere too, or it is easy for middlemen to sniff out your actual hostname even though the IP may be shared with thousands/millions of other hosts.

Yep, I’m assuming that will happen eventually.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#177
post #128

Earlier quoted context omitted.

Surely damages will be approximately zero? There has to be something else to sway Comcast's executives to abide by the contract, surely. Like the CEO agrees to forfeit an amount equal to their previous years total earnings, from all sources, ... that would be an interesting contract!

If Comcast breaks the contract then Mozilla will simply change the default back to Cloudflare DNS.

Out of the pot into the fire.

24 years ago a group of Stanford students started Architext. They took a few million from Kleiner Perkins, called themselves Excite, and started a search engine and internet provider. They were a good, ethical, well ran technology company. Over the years bits and pieces were chopped up and merged and acquired and spun off based on what generated shareholder value. Parts of that old soul live in on now in the current Comcast.

The same thing will happen to Cloudflare. Matthew Prince will move on, or retire, or get hit by a bus. The board will be taken over by an activist investor. It will get merged with ExxonTacoBell, which also now owns the 2nd largest ad network. They will figure out the data gold mine the company built under total ethical pretenses, and the stock price will triple. There isn't a damn thing a single current Cloudflare employee can do to stop it except stop participating in the centralization of the internet behind a single MitM proxy.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#178

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

From the article:

> Comcast's version of DNS over HTTPS (DoH) will be turned on by default for Firefox users on Comcast's broadband network

> Comcast is the first ISP to join Firefox's Trusted Recursive Resolver (TRR) program

> Cloudflare and NextDNS were already in Mozilla's program

> which requires encrypted-DNS providers to meet privacy and transparency criteria and pledge not to block or filter domains by default

I believe Firefox must not turn on Comcast's DoH as default even for Comcast ISP users. They ought to show some kind of first time prompt.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#179

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

> Comcast sniffs / records / tracks their user's DNS traffic

what if the are your dns server?

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#180

Earlier quoted context omitted.

It is entirely possible for one group (or incentive) within Comcast's organization to work towards that goal, and another group or incentive within Comcast to work against it. Some things that make me trust this claim: - That privacy policy - That contract - Association with trustworthy brands like Mozilla - Work on encrypted DNS - Consumer trust could theoretically be financially valuable to them - Basic morals of C…

I am a Comcast employee myself, but these opinions are my own: I appreciate your comment as you clearly and accurately frame that good people work there, Comcast earned its reputation with its actions, and that there may be competing interests / morals at play. I can’t predict the future to say what wins out, but I feel like there are competing interests at play internal to the org. There are the business/markets, an…

I am sure there are some good people working at your company, and you may be one of them. But that is not really relevant here. It is the actions of the enterprise as a whole that count.

> I am somewhat disappointed to see a HN thread so populated with groupthink “Comcast is bad!”.

What I see in many comments is specific reference to cases where Comcast betrayed the public's trust. You can call it groupthink, but I get the impression the bad rep is well-earned.

Trust leaves on horseback, and comes back on foot. More work to do to convince those who doubt you. Happy to hear you are working on that.

Post reply on HN