To the Mozillians that follow these threads, Shame on you for making studies like this opt-out. Look, I get that making it opt-in would reduce your sample size but this kind of thing isn't acceptable for a browser that's supposed to respect the user -- you're literally using dark patterns. Expressed consent should be the standard. You're targeting Nightly users, the very people who know enough to make an informed dec…
Firefox Nightly Secure DNS Experimental Results
11–15 of 15 posts
Re: Firefox Nightly Secure DNS Experimental Results
#12It's quite dissapointing how much outraged the initial announcement of DoH generated and then the results are mostly ignored. I find it quite exiciting tbh, the improvements seem to be far on the good side, it might help mobile users a lot (my mISP interferes with DNS to block VPN and tries to show ads if it fails to resolve an address). Of course they'll have to work making sure that privacy is preserved and poeple…
Re: Firefox Nightly Secure DNS Experimental Results
#13It's quite dissapointing how much outraged the initial announcement of DoH generated and then the results are mostly ignored. I find it quite exiciting tbh, the improvements seem to be far on the good side, it might help mobile users a lot (my mISP interferes with DNS to block VPN and tries to show ads if it fails to resolve an address). Of course they'll have to work making sure that privacy is preserved and poeple…
I missed the initial announcement, what was all the outrage about?
Re: Firefox Nightly Secure DNS Experimental Results
#14As an individual,this is great news for me. But for corporate use,this means having to intercept https unless you can turn DoH off via GPO or something. These days,credential and PII theft phishing is a huge concern. Without intercepting https,the only way to know if a user went to a phishing site is by logging DNS or relying on SNI(SNI encryption is being developed as well).
Though I will say inspecting DNS for phishing protection is like watching your front door to catch a burglar.
Re: Firefox Nightly Secure DNS Experimental Results
#15As an individual,this is great news for me. But for corporate use,this means having to intercept https unless you can turn DoH off via GPO or something. These days,credential and PII theft phishing is a huge concern. Without intercepting https,the only way to know if a user went to a phishing site is by logging DNS or relying on SNI(SNI encryption is being developed as well).
I'm sure it'll end up in https://github.com/mozilla/policy-templates/blob/master/READ... if it gets officially added and released. Though I will say inspecting DNS for phishing protection is like watching your front door to catch a burglar.
In essence,defenders need to monitor for and block attacker infrastructure.