Live data from Hacker News

Firefox 83 introduces HTTPS-Only Mode

blog.mozilla.org

471–480 of 525 posts

Re: Firefox 83 introduces HTTPS-Only Mode

#471
post #421

Earlier quoted context omitted.

Cool, that makes you one of the people that's going to keep DoH turned off. What's the problem?

The internet of crap will also use DoH and bypass my network settings. Also, it is only a matter of time before ads (and websites) start using it to bypass browser DNS: https://github.com/byu-imaal/dohjs

There is no reason they couldn't have done this without DoH being an available standard. Remember, DoH is just an ordinary HTTPS request. Anyone can hide almost anything in that, including their own homemade DNS.

Re: Firefox 83 introduces HTTPS-Only Mode

#472

Earlier quoted context omitted.

There is nothing about DNS over HTTPS that requires you to use one centralized provider, and unencrypted DNS has always been easier for large corporations, ISPs, and the government to sniff. I think people are just totally off-base on this. The instances of government/corporation reactions to DOH that we have seen suggest that untrustworthy organizations and governments largely oppose the change. They would not oppos…

Firefox made DoH to Cloudflare the default, right? This is not responsive to my argument that it will impact most Firefox users. Most people won't change their defaults. Defaults matter. And that goes double when you need to dink with your own DNS server to override this crap.

The kind of user who wouldn't change their default setting is probably already happily (or unknowingly) sending all their DNS traffic to their ISP.

I get your concern about cloudflare, but I can tell you right now which of the two options I would trust more with this data, and it's not Comcast/AT&T/Cox/

Re: Firefox 83 introduces HTTPS-Only Mode

#473

Earlier quoted context omitted.

You ensure that the content you serve is exactly what arrives on the reader's machine. The most prominent example is ISPs inject ads or messages. Search for "comcast injecting ads" to see some examples.

That sucks. If I know my ISP is doing that I would definetively change it.

This happens on the visitor's end. So it depends on the ISPs of individual visitors of your blog.

Re: Firefox 83 introduces HTTPS-Only Mode

#474
post #87

Earlier quoted context omitted.

I want my OS to do DNS - including DOH, not my browser. I want a single source for my DNS I want my network to tell me a DNS server to use. As I own my computer I can override that, but much of the time I want to use the network provided DNS server.

"I want a single source for my DNS." I don't like applications that do their own DNS resolution. I use a text-only browser that relies on the OS to do DNS resolution. But imagine your DNS is filtered. Would you still want only a single source, e.g., your ISP? In that case, wouldn't you want multiple sources? When in a DNS-filtered environment, e.g., a hotel, DOH outside the browser can actually be useful. For example…

I have a root hints dns sever running in my home environment. I'd prefer to control dns at os level. I also route my mobile devices through openvpn to cover when I'm not home. I control every aspect of all my devices network traffic.

Re: Firefox 83 introduces HTTPS-Only Mode

#475
post #341

Earlier quoted context omitted.

To me, HTTP is the wrong target. It would be much more interesting to replace IP, like Yggdrasil does (and I think gnunet, cjdns, hyperboria & others). If you IP is a cryptographic identifier: * It cannot be forged * Anyone can generate a new one on-demand * Every packet is authenticated, every packet can be encrypted * TLS becomes redundant However, the DNS part remains a hard one. How to securely link to websites y…

IP is even harder to replace, it is completely fossilized by this point and that is a feature. The challenge is not to replace the pipes but to build something meaningful using the pipes we have without too much added complexity: I built a realtime MMO stack using only HTTP/1.1 for network.

You can always build a transition infrastructure on the top of IP, like https did by coexisting with http, and a bit like gemini does (it has https://gemini.circumlunar.space/ at least).

Then build some links without it, and have the compatibility layer the other way. If there are compelling reasons to use the new protocol, it might gain some traction. Maybe we'll turn off IP, but probably not within a century, unless some organization acquires a tremendous amount of control over the Internet.

Re: Firefox 83 introduces HTTPS-Only Mode

#476
"we expect it will be possible for web browsers to deprecate HTTP connections and require HTTPS for all websites"

Thinks about the implications of this. It will be impossible to host any web content unless you get blessed by a well-known CA (packaged in the platform/browser CA store).

That's why we have Let's Encrypt, right? Yes, thanks to them.

Now imagine a future where Let's Encrypt goes away, for whatever reason.

Now it's impossible to host any web content without getting approved by a commercial CA.

Re: Firefox 83 introduces HTTPS-Only Mode

#477
post #388

Earlier quoted context omitted.

Just checked this yup. If I go to https://neverssl.com/ I get a warning explaining that this site doesn't have a certificate for neverssl.com but only for Cloudfront (presumably where it's hosted) But if I try to go to http://neverssl.com/ then I get the message explaining that the HTTPS site doesn't work, do I want the insecure HTTP one instead?

That kind of sucks because if a user misses the initial OS redirect for a captive portal login, the easiest way to get them back to the authentication page is to have them hit an http site. However, things like HSTS make that really hard to do without having a site that does NOT use https and defaulting to https is like having HSTS triggered on every site. Having to tell them to click through a non-https warning is a…

Captive Portals are the thing that sucks in this situation though.

If you offer "free" WiFi behind an annoying Captive Portal chances are I'll just use my 3G service if it works. Now, in my mind do you think I consider you offered me "free" WiFi? No, it was too annoying to use. So your competitor that didn't bother with a Captive Portal site and just posted their WiFi password on a chalkboard - they have free WiFi and you don't.

Re: Firefox 83 introduces HTTPS-Only Mode

#478
post #390

Earlier quoted context omitted.

This is incredibly bad for the health of the web. In kneejerk response to the invasion of privacy from world governments we're handing absolute control of the web back to those very governments. Everyone being forced to get permission from a centralized cert authority that is easily influenced, pressured, etc in order to host a visitable website is the end of the web as we know it. This is a slide into a total loss o…

I think you misunderstand how HTTPS works, there's no central root CS, nothing stops you from adding other trusted root certificate authorities. In fact, your browser trusts a few dozens of different ones, and companies routinely manage their own.

No, I'm just assuming that you're going to follow through on that thought and realize statistically no one does that for self signed certs except corporations which aren't human persons anyway.

Re: Firefox 83 introduces HTTPS-Only Mode

#479

Where you see security, I see control. A way to commoditize the launch of ideas and information. Maybe 30 years from now, they will not prohibit any type of communication that is not properly licensed and standardized. As they do with commercial imports and exports. In Brazil today when you buy a product from another state of the federation, the tax goes partly to the origin of the product shipped and partly to the d…

How does that commoditize the launch of ideas and information?

Introducing a commodity by-product into the cost of a website

Re: Firefox 83 introduces HTTPS-Only Mode

#480

Where you see security, I see control. A way to commoditize the launch of ideas and information. Maybe 30 years from now, they will not prohibit any type of communication that is not properly licensed and standardized. As they do with commercial imports and exports. In Brazil today when you buy a product from another state of the federation, the tax goes partly to the origin of the product shipped and partly to the d…

How does that commoditize the launch of ideas and information?

Introducing a commodity into the cost of a website
Post reply on HN