Live data from Hacker News

Thai Database Leaks 8.3B Internet Records

rainbowtabl.es

1–10 of 79 posts

Re: Thai Database Leaks 8.3B Internet Records

#2
> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy.

Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist.

Unless this feature starts being turned on by default in routers and popular software, the average user's DNS lookups will not be protected.

Re: Thai Database Leaks 8.3B Internet Records

#3
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

> Unless this feature starts being turned on by default in routers and popular software

Firefox has DoH turned on by default for US-based users. Unfortunately being US-only, it won't protect Thai users just yet. Especially considering the fact that Thai ISPs have known to be hijacking port 53 and NXDOMAIN since forever[1] with ISP in the article being one of the biggest offender.

It might also worth nothing that PDPA, Thailand's equivalent of GDPR, is to become in effective in two days (May 27th) so this incident will be... interesting.

[1]: Starting in early 2000s, with NIPA (that I never see anybody uses), who aim to provide IDN-enabled Thai domain names by providing NXDOMAIN-hijacking services to ISP

Re: Thai Database Leaks 8.3B Internet Records

#4
post #3
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

> Unless this feature starts being turned on by default in routers and popular software Firefox has DoH turned on by default for US-based users. Unfortunately being US-only, it won't protect Thai users just yet. Especially considering the fact that Thai ISPs have known to be hijacking port 53 and NXDOMAIN since forever[1] with ISP in the article being one of the biggest offender. It might also worth nothing that PDPA…

I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec.

I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server).

I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.

Re: Thai Database Leaks 8.3B Internet Records

#5
This is something that the average user fails to understand. One thing is saying I don't care they check on what I visit but once you aggregate enough information, it can become something of a "Big Brother".

With enough DNS data I can assure you I can see when you leave to work, get back, determine the moment when you leave for vacation and no one is home, etc.

Re: Thai Database Leaks 8.3B Internet Records

#7
Solution for this is to tunnel the traffic through encrypted connection to servers in countries that respect persons privacy(if that is true nowadays). The easiest way is to use WireGuard, easy to set up uses only one port and have clients for many devices.

Re: Thai Database Leaks 8.3B Internet Records

#8
post #5

This is something that the average user fails to understand. One thing is saying I don't care they check on what I visit but once you aggregate enough information, it can become something of a "Big Brother". With enough DNS data I can assure you I can see when you leave to work, get back, determine the moment when you leave for vacation and no one is home, etc.

You wouldn't even need DNS data, just how much Internet traffic a specific connection or device is using is enough to determine these things.

Re: Thai Database Leaks 8.3B Internet Records

#9
post #4
post #3

Earlier quoted context omitted.

> Unless this feature starts being turned on by default in routers and popular software Firefox has DoH turned on by default for US-based users. Unfortunately being US-only, it won't protect Thai users just yet. Especially considering the fact that Thai ISPs have known to be hijacking port 53 and NXDOMAIN since forever[1] with ISP in the article being one of the biggest offender. It might also worth nothing that PDPA…

I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec. I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server). I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.

Have you been able to find a trustworthy public DoT resolver?

I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?

Re: Thai Database Leaks 8.3B Internet Records

#10
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

DoH just moves the logging from Thai telecom and moves it to Cloudflare (or, whoever you set up as your DoH server, but most likely Cloudflare), no?

I trust CF much more than my ISP, but it makes the potential leak much worse...

edit: On the other hand, DoH makes DNS requests independent of ISP, which is nice. ISPs are often monopoly by nature.

Post reply on HN