Live data from Hacker News

NextDNS Joins Firefox’s Trusted Recursive Resolver

blog.mozilla.org

1–10 of 146 posts

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#2
Interesting, I wasn't aware of Mozilla's Trusted Recursive Resolver program (https://wiki.mozilla.org/Security/DOH-resolver-policy).

> The following providers have contractually agreed to abide by these policy requirements: [Cloudflare, NextDNS]

Are these agreements made public?

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#5
> Our trusted recursive resolver program aims to standardize requirements for three areas: limiting data collection and retention from the resolver, ensuring transparency for any data retention that does occur, and limiting any potential use of the resolver to block access or modify content.

This seems like a win overall, and I'm glad that they're pushing to build a list of trusted resolvers. It sounds like they've got some sort of contract ensuring they don't use the data, so that's a positive.

That said, given that Windows 10 is going to going to start supporting DoH natively, I'm not sure I understand the reasoning to use Mozilla's chosen DNS providers, rather than the system default.

It seems a bit like enabling a proxy or VPN by default- Even if Mozilla trusts the proxy provider, routing traffic to unneeded third parties seems somewhat user-hostile.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#6
post #3

Is there going to be an option in FF to select which “trusted partner” to use? And an option to use a provider not in their list?

Or an option to randomize it per request with the ability to remove / blacklist specific partners. Now that would be great.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#8
post #2

Interesting, I wasn't aware of Mozilla's Trusted Recursive Resolver program ( https://wiki.mozilla.org/Security/DOH-resolver-policy ). > The following providers have contractually agreed to abide by these policy requirements: [Cloudflare, NextDNS] Are these agreements made public?

[deleted]

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#9
post #2

Interesting, I wasn't aware of Mozilla's Trusted Recursive Resolver program ( https://wiki.mozilla.org/Security/DOH-resolver-policy ). > The following providers have contractually agreed to abide by these policy requirements: [Cloudflare, NextDNS] Are these agreements made public?

Gov agencies requests still take precedence over any such agreements don't they?

In other words, I would add some canary that nobody forced them to break rules of those contracts.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#10
I never heard of NextDNS.

I am appalled.

From their site: https://nextdns.io

> See what's happening on your devices with in-depth Analytics and real-time Logs.

> Protect your kids and control what they can access online.

Their pricing page is also extremely troubling.

> We may adjust this later on based on actual costs at scale, but it will follow this logic.

What the hell is this Mozilla... This is not a company you should be dealing with. They tell you up front that they log and monitor... They also aren't at scale, and have to learn lessons the hard way with outages.

Mozilla is dead to me now.

Edit:

As others have pointed out, Mozilla's own policies: https://wiki.mozilla.org/Security/DOH-resolver-policy

Transparency Requirements, section 2.

Where on earth is a transparency report for NextDNS? They were started in March, and I would think that Mozilla would check their requirements before giving the 'lets add them.'

Post reply on HN