Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

11–20 of 422 posts

Re: Turn off DoH, Firefox

#12
If the single DoH 'server' is the issue, wouldn't having a list of several 'servers' around the globe (hopefully in places where there isn't any form of censorship and preferably though non-commercial institutions) that the browser selects randomly solve this?

Re: Turn off DoH, Firefox

#13
post #9
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

I do trust my ISP and my government more than I trust CloudFlare.

Is your ISP in the US and your government the US government? The DoH rollout w/ Cloudflare is only planned for the US.

Re: Turn off DoH, Firefox

#14
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

> I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government!

I trust my ISP and government more than a US company I have no formal contract with and the US government.

Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Firefox users on my network.

Re: Turn off DoH, Firefox

#15
post #2

What they should do is offer several alternatives when enabling DoH (Cloudflare isn't the only DoH provider out there), and anto-detect if your ISP or local network supports it at the enterprise level. At least you can change the provider in about:config. I don't remember if you can do it through the settings page.

Yea, Preferences > Network Settings > Enable DNS over HTTPS

Can currently choose "Cloudfare (default)" or "Custom"

But I agree, a few more options on there would be good, and if they are turning it on by default, then there should be a setup page that appears to let you choose the provider or something

Re: Turn off DoH, Firefox

#17
post #9
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

I do trust my ISP and my government more than I trust CloudFlare.

It seems very American to me to trust a private actor such as CouldFlare more than your own government.

I feel like at least in Europe, a large majority of people would trust their government and local ISP much more than some company halfway over the world with basically no accountancy in your own country, especially an American one since it means your data is basically at the mercy of the US government.

Re: Turn off DoH, Firefox

#18
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

> I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! I trust my ISP and government more than a US company I have no formal contract with and the US government. Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Fi…

> I trust my ISP and government more than a US company I have no formal contract with and the US government.

And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something better.

> Also, there's the whole 'applications should not override system level settings' thing.

Hopefully, DoH will become a system level setting eventually.

Re: Turn off DoH, Firefox

#19
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

I live in Europe and I do trust my ISP (and government, which has a decent track record at enforcing GDPR).

Even with DoH, my ISP already sees all of my network traffic. My DNS queries will effectively be anonymized by their recursive name servers.

Re: Turn off DoH, Firefox

#20
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

> I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! I trust my ISP and government more than a US company I have no formal contract with and the US government. Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Fi…

> I trust my ISP and government more than a US company I have no formal contract with and the US government.

You're not affected then, because the DoH rollout w/ Cloudflare as the default is only planned for the US.

Post reply on HN