Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

101–110 of 422 posts

Re: Turn off DoH, Firefox

#101
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

Are there any GDPR compliant entities there? Preferably some company/organization from Europe?

Re: Turn off DoH, Firefox

#102

Earlier quoted context omitted.

> the article deliberately buries that it's trivial to change your DoH provider While true for you or me, the vast majority of people will have this enabled by default - probably not even realising it's on

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com, even if the laws in the user's country forbid it.

Re: Turn off DoH, Firefox

#103
post #78

Earlier quoted context omitted.

...and a local HOSTS file. So now it will, by default, contact all the ad/tracking hosts that you configured to be blocked. "But now your DNS queries to those ad/tracking hosts are encrypted!" No. I don't care. I didn't want to connect to those hosts in the first place.

Even worse, corporate intranet addresses get leaked. Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.

Corporations concerned about that should be blocking DoH anyway

Re: Turn off DoH, Firefox

#104
post #55

I strongly support DoH as it prevents government snooping on the public. It’s really unhelpful that people like this attack Firefox over this issue. Stand strong Firefox against this.

One goes fishing where the fish is. There are dozens of large and hundreds of medium to small ISPs in the US. There's only one Cloudflare. That's where the resources to get the data would be concentrated. It has been demonstrated with PRISM. If Mozilla wants to play this game, it really should make DoH a visible top level choice for a user.

Most users don't understand DNS, HTTPS, or DoH. I think this decision overall is good, and for those who see and understand the possible issues, it's trivial to remedy.

Re: Turn off DoH, Firefox

#105
> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Not in applications!

You're right. But so are Mozilla.

Here we are 30 years into the web, and we're still using plain old DNS. DNS over TLS should have caught on, but it didn't. Apple and Microsoft had years to ensure it's implemented as standard, but they didn't.

The points this article makes - about DHCP options, about multiple providers, are very valid.

But they're also just talking shops.

The biggest problems here seems to be 1) DHCP can't give internal DOH servers. When I'm at home I want it landing on my own DOH server, but when I'm away I want to use a different one. 2) Internal DNS resolving falls to bits

Re: Turn off DoH, Firefox

#107
post #58

There are two points: 1. centralization of all dns lookups is worrisome 2. Dns should not be handled by applications. It should be handled by the operating system. I see a lot of people conflating the two in the comments.

> 2. Dns should not be handled by applications. It should be handled by the operating system. I agree with #1 but why it should be managed by the OS?

Because I don't want to have to manage 400 configs when I can manage 1.

Re: Turn off DoH, Firefox

#108
post #16

It seems like this change by Firefox would bypass a pi-hole. Am I understanding it correctly?

...unless you disable it. However you can configure firefox to use your pi-hole if you can get it serving dns over https. If that's not supported now I would expect it becomes supported very soon.

Re: Turn off DoH, Firefox

#109
post #61
post #49

Earlier quoted context omitted.

> I don't think anyone believes CF will start selling data, that's not what the article argues. > Regardless, it's opt-out not opt-in. Which is against newer consumer protection laws such as GDPR. I understand the argument in theory.. but the reality is CF is a more trustworthy DNS provider than basically any consumer ISP in the EU.

This is where me and the author disagree with you. In most places in Europe there is a complete distrust of US companies and hosting anything on US soil. Historically we've seen many cases of US companies handing over data to US authorities (willingly or not).

I think in most countries, government can approach domestic companies to hand over data in case of illegal action.

The problem with the US is that data is being used against you, like recent events have shown.

Re: Turn off DoH, Firefox

#110

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Don't oversimplify the issue.

> it's trivial to change your DoH provider

Cloudfare is the default.

Cloudfare is the only provider listed.

Cloudfare will be On by default, so it will be that for 99.999% of Firefox users.

That ain't right no matter how well intended it is.

Post reply on HN