Live data from Hacker News

Encrypted Client Hello

blog.cloudflare.com

81–90 of 219 posts

Re: Encrypted Client Hello

#81
post #70

Earlier quoted context omitted.

Nothing is wrong with DoH. When people complain about it, it's generally because they like being able to successfully perform the kind of attacks it's meant to prevent, e.g., censorship and surveillance of traffic between endpoints they own neither of, just because the traffic passes through their network.

Are you familiar with https://pi-hole.net/ ? In my house I want DNS resolution to be performed by my own DNS resolver ( https://github.com/NLnetLabs/unbound ), after I block ad domains. DoH circumvents that.

I agree with you, but the counterargument that'll be made against you is "you should be doing that on the endpoints".

That counterargument ignores the fact that you can be the owner of an endpoint but not be permitted, by manufacturer's policy, to control the software running inside. That's what you get for purchasing a proprietary device.

So, as the network operator and owner of the endpoints in the world of DoH (and pinned certificates), you end up being left with the decision to "vote with your wallet" and simply not purchase devices that don't afford you influence on name resolution (or whatever functionality we're talking about)

The counterargument goes on to say that the manufacturers of these sealed-box devices can functionally do this today anyway simply by implementing their proprietary name resolution (content delivery, etc) protocol.

It was all fun while it lasted.

Re: Encrypted Client Hello

#82

I'm not seeing it. It looks contradictory what they're saying. > This means that whenever a user visits a website on Cloudflare that has ECH enabled, no one except for the user and the website will be able to determine which website was visited. But if you look at the inner/outer SNI part: > The outer SNI is a common name that, in our case, represents that a user is trying to visit an encrypted website on Cloudflare.…

When you visit a site on Cloudflare today, both Cloudflare and your ISP see the domain name. With ECH, only Cloudflare will.

When I visit a more local website only my ISP and the site's ISP will see the domain name. With default browser setting some, probably overseas, entity that I didn't trust and didn't choose gets my request, ignoring my system configuration and without asking.

Re: Encrypted Client Hello

#83

I'm not seeing it. It looks contradictory what they're saying. > This means that whenever a user visits a website on Cloudflare that has ECH enabled, no one except for the user and the website will be able to determine which website was visited. But if you look at the inner/outer SNI part: > The outer SNI is a common name that, in our case, represents that a user is trying to visit an encrypted website on Cloudflare.…

Did they fix it? Now it reads,

> This means that whenever a user visits a website on Cloudflare that has ECH enabled, no one except for the user, Cloudflare, and the website owner will be able to determine which website was visited.

Re: Encrypted Client Hello

#84

This is going to make it even more of a pain to do egress filtering on networks/systems we administer. I want to be able to allow list sites with dynamic IPs. The existing solutions for doing this by examining SNI are already often bypassable by forging the SNI (looking at you, AWS Network Firewall).

You're supposed to do that kind of filtering on the endpoint. If it's possible anywhere else, then it could be used to censor other people's computers.

I'm afraid you only take into account private use.

On-endpoint filtering is not enough on a large scale. In a network with expected high level of security I don't trust the endpoint and censoring them is a feature, there is no moral or legal expectation of privacy, but data integrity would be nice.

Re: Encrypted Client Hello

#85

This is going to make it even more of a pain to do egress filtering on networks/systems we administer. I want to be able to allow list sites with dynamic IPs. The existing solutions for doing this by examining SNI are already often bypassable by forging the SNI (looking at you, AWS Network Firewall).

You're supposed to do that kind of filtering on the endpoint. If it's possible anywhere else, then it could be used to censor other people's computers.

I see your point, but on my network I want that ability.

I want to have my tv connect to YouTube, but not phone Sony/Samsung/whoever.

I want to be able to setup a pihole to block adds independently of the browser/device being used.

Re: Encrypted Client Hello

#86

Earlier quoted context omitted.

> People own their networks when they're not out in public. Again, solving for a problem with public networks by forcing shortcomings on to all networks is shortsighted and ill conceived. It's not just being out in public. Even when you're home, you're still at the mercy of your ISP. > Go ahead and tell me how to remove Edge, or how to have Windows open links in other browsers What does preventing use of Edge have to…

"Even when you're home, you're still at the mercy of your ISP." No, I'm not. If you think I am, then you don't understand networking. "What does preventing use of Edge have to do with DoH?" If you can't have basic control of programs on your own computer, tell me how you're going to control programs' use of DoH. "You've yet to convincingly point out a single bad thing that actually comes from DoH." I've named many: w…

> "Even when you're home, you're still at the mercy of your ISP." No, I'm not. If you think I am, then you don't understand networking.

If your ISP dropped all packets on port 53 that contained a response for example.com, how would you circumvent that and learn its IP otherwise?

> "What does preventing use of Edge have to do with DoH?" If you can't have basic control of programs on your own computer, tell me how you're going to control programs' use of DoH.

Name a single program (other than unambiguous malware that nobody would ever be okay with being installed at all) that always uses DoH regardless of any configuration by a local administrator.

> "You've yet to convincingly point out a single bad thing that actually comes from DoH." I've named many: we lose the ability to block ads, adware, Trojan CaC, spyware, et cetera. We lose the privacy of our own DNS lookups. Your suggestion seems disingenuous.

There are DoH resolvers that do ad and malware blocking. Moving DNS from cleartext to an encrypted protocol is certainly not losing privacy.

> "You can't make public Wi-Fi or your ISP's network better no matter how knowledgeable you are." No - YOU can't or don't want to, because you don't understand networking. People who want to can, though, and this is what I'd encourage, instead of enshittifying the Internet by believing companies like Cloudflare when they tell us our ISPs suck and we should just trust them instead.

How are you proposing that people make other people's networks better? And are you saying that Americans' ISPs don't suck?

Re: Encrypted Client Hello

#87
post #72

Earlier quoted context omitted.

You're absolutely right, Cloudflare will still see it. That doesn't make this a bad improvement though. You don't have to use Cloudflare to support it, but it helps obscure which site is being visited by the nature of Cloudflare hosting so many different sites. So what does this actually protect against? Who will this benefit? Mostly people in censored countries and companies. This removes the last piece of informati…

> I still think DoH is hot garbage and the way it has been implemented across browsers is an atrocity. Not sure if it's a hot garbage, but I don't see why it's better than DoT or DoQ, except maybe a use case for censored countries. DoT is faster and can be abstracted away from from HTTP. Presumably, DoH is more privacy preserving, because it runs on the same port and looks just like the rest HTTPS traffic. But I thin…

> I don't see why it's better than DoT or DoQ, except maybe a use case for censored countries.

This feels like saying "I don't see why we need oxygen in the atmosphere, except for people needing to breathe." Being able to overcome censorship is a huge win and is more than sufficient for DoH to be better than DoT, etc.

> Also, we are moving from your ISP knowing too much about you to Cloudflare knowing too much about you. It's one of the biggest DoH DNS services, often they see unencrypted HTTPs traffic, they also an exit node for iCloud Private Relays. ISP is left out, but Cloudflare seems to be able to consolidate this knowledge.

The key making DoH still a net win in spite of that is that your ISP has the mapping from your source IP to your real-life identity, but DoH providers like CloudFlare don't.

Re: Encrypted Client Hello

#88
post #62
post #13

Earlier quoted context omitted.

What is wrong with DoH?

This is a power struggle, which I do not believe is really even on purpose by the people involved. We used to have a decentralised Internet with a truly open and engineering-led garden of interoperable protocols. However during the past decade and a half we've seen a massive change. We find ourselves in a situation where only https matters. It's a catch 22 type of situation, where anything else better be able to tunn…

DoH doesn't make the Internet any more centralized. Just as with insecure DNS servers, anyone can run DoH servers too, and there are a lot of public ones: https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-av...

Re: Encrypted Client Hello

#89

Earlier quoted context omitted.

> browsers try to resolve a particular name with the system DNS and then turn of DoH if it resolves in a particular way I agree that's the wrong way to let DoH be turned off, exactly for the reason you describe. It should only be possible for DoH to be disabled by, e.g., the local user manually going into settings or by Group Policy. > What you should have is a router, which hands itself out as the DNS server via DHC…

> I agree that's the wrong way to let DoH be turned off, exactly for the reason you describe. It should only be possible for DoH to be disabled by, e.g., the local user manually going into settings or by Group Policy. DHCP is group policy for network configuration. If you're connecting to a network where you don't trust the DHCP server then don't use DHCP for DNS or use a VPN. > The problem with that is that I don't…

> DHCP is group policy for network configuration.

The real Group Policy only affects computers that a local administrator explicitly joined to a domain. DHCP shouldn't have any such control since it's not trusted.

> If you're connecting to a network where you don't trust the DHCP server then don't use DHCP for DNS

But that's exactly what people are complaining that Firefox enabled.

> The application default needs to be the system DNS and the device default needs to be DHCP so the device owner can feasibly change them.

Once every common end-user OS has default-on DoH, then that would be better, but until then, I think individual programs using DoH on their own is a net benefit.

Re: Encrypted Client Hello

#90

Earlier quoted context omitted.

> People own their networks when they're not out in public. People rent their networks from one, maybe two area options. The consumer networks want to completely control router hardware these days and these days charge extra rental fees for owned hardware instead of rented hardware. (It's fascinating that they can legally get away with that.) Some of the biggest consumer networks have already proven they are happy to…

Trust is hard, yes. Cloudflare might not be going for the low hanging fruit such as injecting ads, but they clearly want to be a monopoly around whom the Internet recentralizes. Moving DNS from an ISP, who we pay and with whom we have legal contracts, to a company that does things, supposedly, for altruistic reasons, with whom we do NOT have contracts, doesn't fix anything. It makes things worse. The solution is to r…

> The solution is to remove DNS from your ISP and run it yourself

This doesn't work because if you run your own recursive DNS server, it will make insecure requests to all of the authoritative servers, and so your ISP can hijack them all. And DNSSEC will keep you from getting sent to the wrong domain, but won't help you figure out the right domain.

Post reply on HN