Live data from Hacker News

Encrypted Client Hello

blog.cloudflare.com

31–40 of 219 posts

Re: Encrypted Client Hello

#31

Earlier quoted context omitted.

You're absolutely right, Cloudflare will still see it. That doesn't make this a bad improvement though. You don't have to use Cloudflare to support it, but it helps obscure which site is being visited by the nature of Cloudflare hosting so many different sites. So what does this actually protect against? Who will this benefit? Mostly people in censored countries and companies. This removes the last piece of informati…

I agree that this is generally a good thing, and that DoH is an absolutely shitty thing, but I think the poster here was taking exception to this statement: "no one except for the user and the website will be able to determine which website was visited" That, I think we can all agree, is patently untrue. Cloudflare shouldn't be publishing blatant deceptions.

Author here - definitely not trying to be deceptive! I've amended the sentence you mentioned to be more clear.

Re: Encrypted Client Hello

#32
post #10

Earlier quoted context omitted.

> This removes the last piece of information that can be used to block HTTPS traffic based on the site your visiting without being a party to the exchange. And that will cause blocks by IP. It's not like authorities in those countries care that much if a user can't access a not-blocked site, as long as they can't access a blocked one.

The point of efforts like this is exactly to make selective blocking infeasible. This will force the bad guys to choose between blocking nothing and blocking everything, and with the exception of North Korea, most aren't willing to do the latter.

Nope, the bad guys don't care that much.

Re: Encrypted Client Hello

#33

Earlier quoted context omitted.

It takes our control over our networks away from us and gives it to random applications, to Trojans, to viruses, to adware purveyors, to advertisers. It makes the assertion that because SOME of us don't know how to change our DNS servers, they (Mozilla, Cloudflare, other proponents of DoH) need to take control away from us and need to send our DNS lookups to, usually, them. The justifications are ridiculous, but the…

> It takes our control over our networks away from us Taking control away from the owner of networks is a good thing. Control is supposed to reside with the owner of endpoints . To see why, imagine if your ISP started to MITM all of your connections that went over their network. > don't know how to change our DNS servers It's not a case of "don't know how". It's a case of "can't, because even if you change the settin…

That's an incorrect oversimplification.

It takes control away from the owner of networks, even when we're the owner of those networks. Should DoH start to become more common, blocking it will become a Sisyphean task.

It takes control away from the owner of endpoints. Sure, you can go and change the settings in Firefox to turn off DoH after they've turned it on without asking and without telling us, but what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS? So yes, your statement about control residing with the endpoints is correct, but DoH removes control, doesn't add it.

For the case of "can't, because even if you change the setting, $evil_isp will hijack the queries anyway", that's FUD. There are many, many better ways to deal with evil ISPs.

Encouraging the world to send all of their DNS lookups to a centralized entity like Cloudflare (who, by every right, are precisely in a position to be an evil ISP) is such an incredibly shortsighted idea that I have to think that you haven't thought out the implications of a world where DoH is dominant.

If you care to learn, consider things without DoH: you can edit your hosts file. You can choose your DNS servers. You can run a local recursive resolving DNS server. You can block ads and advertisingware using your DNS server and/or something like Pihole. You can block all DNS queries to the outside world on your network so that they all go through your own resolvers.

Next, consider a world where DoH is commonplace: you have no control over DNS lookups on your own system. Your only choice is to not run binaries that might do things you don't like. Want to block ads or adware, or adult sites, or conspiracy sites, or any of a number of other things on the Windows system that your child uses? Now Edge doesn't let you. Want to block the Trojans and phishing sites that Google serves through their ad network? Chrome doesn't let you. "Just don't run binaries that do that" is one heck of an ask for people who don't know how to set their own DNS or who have an evil ISP.

You can block common DoH servers, until Cloudflare puts them on the same address as the endpoints for their millions of hosting customers. But what happens when apps do DoH lookups using random Amazon AWS or Google Cloud servers? How do you block them? Do you block ALL https?

You see, you'd give up freedom, and have everyone else give up their freedom, for some abstract "safety" from ISPs that use your DNS data. You'd apply a shitty fix for 1% of the people to 100% of the people, rather than create tools for the 1% to circumvent their evil ISPs.

The fact that you'd choose this makes me think that either you want big, evil companies like Cloudflare to win, or you really don't understand the issues.

Just like this article above does a good job explaining the lack of security in the cloud, we really could use a good article explaining how completely inane the idea of DoH is.

Re: Encrypted Client Hello

#34

I feel like this is only possible because Cloudflare is already so huge. If this becomes widely adopted, anyone who wants to offer "private" access to their site will have to move through Cloudflare. This can't be good.

A lot of shared hosting providers would also be able to implement this. Bringing the benefits of ECH's anti-snooping to many end-users outside of CloudFlare.

Individual servers hosting one single website won't benefit much though. Unless you do encrypted split-DNS, I guess.

Re: Encrypted Client Hello

#35

This just sounds like a less private Tor.

Just like Dropbox is an improvement over FTP with SVN?

I'm only half-joking though. ECH is already being widely enabled in clients, it will exceed Tor's adoption massively. Not as private, but (much more) usable.

Re: Encrypted Client Hello

#36
Naive question, In 2023 how does DNS-over-HTTP (DoH) affect things like the Cisco Distributed Director / F5 3-DNS where DNS is used to control which datacenters customer traffic is going to? Is this still a technology smaller sites can use?

Re: Encrypted Client Hello

#37

It seems like the same result could easily be achieved by widespread Domain Fronting support (e.g set sni to cloudflare-sekrit.com and Host: header to the actual domain). Can someone explain why this wasn't adopted more widely (I know CF, for example, disabled theirs)?

I believe CF and others buckled under pressure from major websites which didn't want to be used as fronts for other website's traffic. ECH fixes this because individual sites get to opt-in to using it.

You could just as easily make df opt-in. Another way is to use “fake” cloudflare-df.com sni just like they are doing with cloudflare-ech.com outer sni

Re: Encrypted Client Hello

#38

Earlier quoted context omitted.

> It takes our control over our networks away from us Taking control away from the owner of networks is a good thing. Control is supposed to reside with the owner of endpoints . To see why, imagine if your ISP started to MITM all of your connections that went over their network. > don't know how to change our DNS servers It's not a case of "don't know how". It's a case of "can't, because even if you change the settin…

That's an incorrect oversimplification. It takes control away from the owner of networks, even when we're the owner of those networks. Should DoH start to become more common, blocking it will become a Sisyphean task. It takes control away from the owner of endpoints. Sure, you can go and change the settings in Firefox to turn off DoH after they've turned it on without asking and without telling us, but what happens w…

> but what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS?

Exfiltration has always been a problem. But it's not a good reason to make MITM possible.

Network control should not give control over endpoints any degree more than is necessary to deliver packets from point A to B. We can't trust them with more.

> [...] Now Edge doesn't let you.

That's blatantly false for normal endpoints though. Be it an AV or parental controls, an endpoint administration will have that ability to intercept.

If an endpoint doesn't let you do thay then to be honest, you've already lost the battle. Even simple HTTPS is not really filterable.

> Just like this article above does a good job explaining the lack of security in the cloud, we really could use a good article explaining how completely inane the idea of DoH is.

What is actually inane is the amount of implicit trust and control given to networks right now. Your network might be a nice wonderland, but many aren't.

Re: Encrypted Client Hello

#39

Earlier quoted context omitted.

That's an incorrect oversimplification. It takes control away from the owner of networks, even when we're the owner of those networks. Should DoH start to become more common, blocking it will become a Sisyphean task. It takes control away from the owner of endpoints. Sure, you can go and change the settings in Firefox to turn off DoH after they've turned it on without asking and without telling us, but what happens w…

> but what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS? Exfiltration has always been a problem. But it's not a good reason to make MITM possible. Network control should not give control over endpoints any degree more than is necessary to deliver packets from point A to B. We can't trust them with more. > [...] Now Edge doesn't let you. That's blatantly false for…

People own their networks when they're not out in public. Again, solving for a problem with public networks by forcing shortcomings on to all networks is shortsighted and ill conceived.

"But it's not a good reason to make MITM possible" is disingenuous. Avoiding DoH doesn't make MITM possible, just as adding DoH doesn't save us from MITM. It does, though, save apps / Trojans from MITM, particularly when we're the ones who want to be in the middle :P

"That's blatantly false for normal endpoints though. Be it an AV or parental controls, an endpoint administration will have that ability to intercept."

Go ahead and tell me how to remove Edge, or how to have Windows open links in other browsers, without involving third party software that forces this, then tell me how "endpoint administration" is something we can expect of people who can't set their own DNS (or who have evil ISPs and can't set up any of a number of other ways to circumvent said evil ISPs).

You didn't address the real meat of the issue: Why is avoiding one issue - ISPs tracking DNS - worth all the bad things that come with it? The only explanation that makes sense to me is that it's worth it to companies that want to control as much as they can, like Cloudflare.

"What is actually inane is the amount of implicit trust and control given to networks right now." So instead of teaching people how and encouraging them to make their networks better, you'd rather divest some of that trust to companies like Cloudflare, and to every application / Trojan writer? Right - because the amount of data collection in software isn't a problem at all. We just need to trust them, and they'll do right by us.

You've made my point for me that you, and other apologists for DoH, haven't really thought things through, have you?

Re: Encrypted Client Hello

#40

Earlier quoted context omitted.

> It takes our control over our networks away from us Taking control away from the owner of networks is a good thing. Control is supposed to reside with the owner of endpoints . To see why, imagine if your ISP started to MITM all of your connections that went over their network. > don't know how to change our DNS servers It's not a case of "don't know how". It's a case of "can't, because even if you change the settin…

That's an incorrect oversimplification. It takes control away from the owner of networks, even when we're the owner of those networks. Should DoH start to become more common, blocking it will become a Sisyphean task. It takes control away from the owner of endpoints. Sure, you can go and change the settings in Firefox to turn off DoH after they've turned it on without asking and without telling us, but what happens w…

> It takes control away from the owner of networks, even when we're the owner of those networks.

My point is that even when you are the owner of a network, you shouldn't have control of traffic on it between endpoints that you don't own either of.

> what happens when applications and Trojans start doing DoH lookups, skipping our system's configured DNS?

The Trojans could just hardcode the IP instead, so blocking DoH wouldn't magically guarantee you could catch them with DNS.

> So yes, your statement about control residing with the endpoints is correct, but DoH removes control, doesn't add it.

Which programs specifically don't let the user disable DoH? If none, then how does its presence remove control?

> For the case of "can't, because even if you change the setting, $evil_isp will hijack the queries anyway", that's FUD. There are many, many better ways to deal with evil ISPs.

Such as? How would you solve the specific problem of an evil ISP hijacking DNS?

> centralized entity like Cloudflare (who, by every right, are precisely in a position to be an evil ISP)

ISPs tend to have regional monopolies, but DoH servers don't. If Cloudflare becomes evil, you can just switch to some other DoH server.

> If you care to learn, consider things without DoH: you can edit your hosts file. You can choose your DNS servers. You can run a local recursive resolving DNS server. You can block ads and advertisingware using your DNS server and/or something like Pihole. You can block all DNS queries to the outside world on your network so that they all go through your own resolvers.

All but the last thing is still possible with DoH, and it's a good thing that it breaks the last thing, since doing that would affect other people's endpoints too.

> Next, consider a world where DoH is commonplace: you have no control over DNS lookups on your own system.

How do you figure? DoH is still configurable.

> Your only choice is to not run binaries that might do things you don't like.

I already don't.

> Want to block ads or adware, or adult sites, or conspiracy sites, or any of a number of other things on the Windows system that your child uses? Now Edge doesn't let you. Want to block the Trojans and phishing sites that Google serves through their ad network? Chrome doesn't let you.

Those are still easy: just point at a DoH server that does those blocks, the same way you'd point at an insecure DNS server that does them today.

> You can block common DoH servers, until Cloudflare puts them on the same address as the endpoints for their millions of hosting customers. But what happens when apps do DoH lookups using random Amazon AWS or Google Cloud servers? How do you block them? Do you block ALL https?

It's a good thing that network-level blocking of DoH is hard.

> You see, you'd give up freedom, and have everyone else give up their freedom, for some abstract "safety" from ISPs that use your DNS data. You'd apply a shitty fix for 1% of the people to 100% of the people, rather than create tools for the 1% to circumvent their evil ISPs.

What freedom am I giving up? What harm does DoH do to regular people?

Post reply on HN