Earlier quoted context omitted.
I want my OS to do DNS - including DOH, not my browser. I want a single source for my DNS I want my network to tell me a DNS server to use. As I own my computer I can override that, but much of the time I want to use the network provided DNS server.
What you want would make censorship and surveillance easier against the vast majority of people. Networks I'm on shouldn't be able to tell which CloudFlare-hosted site I'm visiting, or to block some of them without blocking them all. Letting the network give me a DNS resolver instead of using a known-good one would allow exactly those bad things.
Firefox 83 introduces HTTPS-Only Mode
451–460 of 525 posts
Re: Firefox 83 introduces HTTPS-Only Mode
#452Earlier quoted context omitted.
Fully support this argument and Mozilla's initiative. I work for a firewall co and we had taken a strategic decision to not allow plaintext traffic onto the internet (from cloud deployments). It's just lazy on the client or server operator's part to not have it so.
this breaks caching of simple objects that do not require content security
Re: Firefox 83 introduces HTTPS-Only Mode
#453Earlier quoted context omitted.
How is this further centralising the Web? You can still use whatever DoH provider you want (and there's plenty of them); the choice just shouldn't be tied to the network you're on.
But you don't want it tied to a specific application either. It should be an OS level setting that lets you configure what DNS to use based on circumstance. This is possible today for power users (on Linux at least) and wouldn't be hard to implement for normal users.
Re: Firefox 83 introduces HTTPS-Only Mode
#454Earlier quoted context omitted.
What you want would make censorship and surveillance easier against the vast majority of people. Networks I'm on shouldn't be able to tell which CloudFlare-hosted site I'm visiting, or to block some of them without blocking them all. Letting the network give me a DNS resolver instead of using a known-good one would allow exactly those bad things.
My perspective is this is my home network and this application is infringing on my freedom. I should have the right to monitor my network and my traffic. An application is a guest in my house/computer it does not set the rules.
The key is that if it's really your traffic, then you can easily reconfigure Firefox so that you can monitor it. The benefit of DoH is that if someone else is using Firefox on their own computer, you can't snoop on or hijack their DNS just because they're on your network.
Re: Firefox 83 introduces HTTPS-Only Mode
#455Also man in the middle attacks seem massively overblown. If you are sitting at home on your private network, the likelihood of a man in the middle attack is stunningly small, such that it's completely irrelevant - especially in regards to the likely trivial content being viewed over http.
Re: Firefox 83 introduces HTTPS-Only Mode
#456Earlier quoted context omitted.
I think if the user wants that, they should choose to apply it. Not the network operator. Same as how I wouldn't want my network operator inspecting my HTTPS traffic for malware.
I'm not sure why HN won't allow me to reply to ori_b's question below you, however DoH in Firefox (and in Chrome) have clearly spelled out ways to disable it at the network level for those folks who are network operators and want to restrict it due to interference in filtering or split-horizon DNS. https://support.mozilla.org/en-US/kb/configuring-networks-di... Someone previously mentioned Pi-Hole. Pi-Hole provides t…
Re: Firefox 83 introduces HTTPS-Only Mode
#457Judging from the comments here, they really should've added the word "optional" in the title.
Re: Firefox 83 introduces HTTPS-Only Mode
#458Earlier quoted context omitted.
I think in 2020 we can declare that Californian companies dictate what you can and can't do on your computer, which DNS server to use and what goes through a VPN client and what does not. The same way they decide what is a fact, what is newsworthy and what you are allowed to read / post.
" Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. " https://news.ycombinator.com/newsguidelines.html
Re: Firefox 83 introduces HTTPS-Only Mode
#459Earlier quoted context omitted.
Apps will make DOH requests from within their apps to avoid host-based DNS blocking.
The next step is blocking all the traffic from all apps and whitelist the IP addresses app by app. I did it on my Android phone, a couple of phones ago. I don't remember the name of the app. It could be done on a desktop or server OS too.
Re: Firefox 83 introduces HTTPS-Only Mode
#460Earlier quoted context omitted.
Image decoders occasionally have RCE vulnerabilities.
I think the solution in this case is to not execute code in pictures rather than removing HTTP? Also I'm starting to suspect the downvoting feature is used a sadistic tool, just keeping karma up so you can punish people.
If you're not familiar with this omnipresent class of exploit, I wouldn't hope for many people on HN to take your advice on whether a security measure is needed or not seriously. Even if your comments were underlined and flashing on the page instead of grayed out.