Live data from Hacker News

Firefox 83 introduces HTTPS-Only Mode

blog.mozilla.org

451–460 of 525 posts

Re: Firefox 83 introduces HTTPS-Only Mode

#451
post #87

Earlier quoted context omitted.

I want my OS to do DNS - including DOH, not my browser. I want a single source for my DNS I want my network to tell me a DNS server to use. As I own my computer I can override that, but much of the time I want to use the network provided DNS server.

What you want would make censorship and surveillance easier against the vast majority of people. Networks I'm on shouldn't be able to tell which CloudFlare-hosted site I'm visiting, or to block some of them without blocking them all. Letting the network give me a DNS resolver instead of using a known-good one would allow exactly those bad things.

My perspective is this is my home network and this application is infringing on my freedom. I should have the right to monitor my network and my traffic. An application is a guest in my house/computer it does not set the rules.

Re: Firefox 83 introduces HTTPS-Only Mode

#452
post #214
post #44

Earlier quoted context omitted.

Fully support this argument and Mozilla's initiative. I work for a firewall co and we had taken a strategic decision to not allow plaintext traffic onto the internet (from cloud deployments). It's just lazy on the client or server operator's part to not have it so.

this breaks caching of simple objects that do not require content security

The browser can still see everything and still cache whatever it wants. Safari and likely others are turning off cross site caching anyway.

Re: Firefox 83 introduces HTTPS-Only Mode

#453

Earlier quoted context omitted.

How is this further centralising the Web? You can still use whatever DoH provider you want (and there's plenty of them); the choice just shouldn't be tied to the network you're on.

But you don't want it tied to a specific application either. It should be an OS level setting that lets you configure what DNS to use based on circumstance. This is possible today for power users (on Linux at least) and wouldn't be hard to implement for normal users.

This is a fair point, but the reality today is that basically every OS uses the network-provided DNS servers by default, so Firefox is completely right today to ignore the OS by default. If this ever changes such that it is common for the OS to use DoH instead of the network-provided DNS servers by default, then I'd agree that Firefox should follow the OS.

Re: Firefox 83 introduces HTTPS-Only Mode

#454

Earlier quoted context omitted.

What you want would make censorship and surveillance easier against the vast majority of people. Networks I'm on shouldn't be able to tell which CloudFlare-hosted site I'm visiting, or to block some of them without blocking them all. Letting the network give me a DNS resolver instead of using a known-good one would allow exactly those bad things.

My perspective is this is my home network and this application is infringing on my freedom. I should have the right to monitor my network and my traffic. An application is a guest in my house/computer it does not set the rules.

> I should have the right to monitor my network and my traffic.

The key is that if it's really your traffic, then you can easily reconfigure Firefox so that you can monitor it. The benefit of DoH is that if someone else is using Firefox on their own computer, you can't snoop on or hijack their DNS just because they're on your network.

Re: Firefox 83 introduces HTTPS-Only Mode

#455
There are a lot of confusing comments in here. Maybe I'm in the minority but I use chrome, which seems to default convert to https on any site that supports it, and will provide visible warnings when the site doesn't support https.

Also man in the middle attacks seem massively overblown. If you are sitting at home on your private network, the likelihood of a man in the middle attack is stunningly small, such that it's completely irrelevant - especially in regards to the likely trivial content being viewed over http.

Re: Firefox 83 introduces HTTPS-Only Mode

#456
post #263

Earlier quoted context omitted.

I think if the user wants that, they should choose to apply it. Not the network operator. Same as how I wouldn't want my network operator inspecting my HTTPS traffic for malware.

I'm not sure why HN won't allow me to reply to ori_b's question below you, however DoH in Firefox (and in Chrome) have clearly spelled out ways to disable it at the network level for those folks who are network operators and want to restrict it due to interference in filtering or split-horizon DNS. https://support.mozilla.org/en-US/kb/configuring-networks-di... Someone previously mentioned Pi-Hole. Pi-Hole provides t…

The main thing I don’t want is to send all my browsing data to Cloudflare or similar “public” DNS operator outside my jurisdiction.

Re: Firefox 83 introduces HTTPS-Only Mode

#458
post #416

Earlier quoted context omitted.

I think in 2020 we can declare that Californian companies dictate what you can and can't do on your computer, which DNS server to use and what goes through a VPN client and what does not. The same way they decide what is a fact, what is newsworthy and what you are allowed to read / post.

" Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. " https://news.ycombinator.com/newsguidelines.html

According to you it is a flamebait to have an observation? Ok, understood.

Re: Firefox 83 introduces HTTPS-Only Mode

#459

Earlier quoted context omitted.

Apps will make DOH requests from within their apps to avoid host-based DNS blocking.

The next step is blocking all the traffic from all apps and whitelist the IP addresses app by app. I did it on my Android phone, a couple of phones ago. I don't remember the name of the app. It could be done on a desktop or server OS too.

That sounds like a fun way to spend your life.

Re: Firefox 83 introduces HTTPS-Only Mode

#460
post #344

Earlier quoted context omitted.

Image decoders occasionally have RCE vulnerabilities.

I think the solution in this case is to not execute code in pictures rather than removing HTTP? Also I'm starting to suspect the downvoting feature is used a sadistic tool, just keeping karma up so you can punish people.

They don't intentionally execute any code, they do sometimes have a vulnerability that allows memory corruption in a way that can be exploited to run attacker-provided code.

If you're not familiar with this omnipresent class of exploit, I wouldn't hope for many people on HN to take your advice on whether a security measure is needed or not seriously. Even if your comments were underlined and flashing on the page instead of grayed out.

Post reply on HN