Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

111–120 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#111
post #94

Earlier quoted context omitted.

DoH does not imply centralization in any way. Any trusted party can provide their own DoH endpoint. I can run my own DoH server on a cheap VPS hosted in another country. I live in an increasingly oppressive regime. Most of the blocking is done at DNS level. DoH is a great solution. Slamming DoH because they can anyway spy one way or another is a poor argument.

The issue is each application implementing DoH themselves. Now any software which you wish to use your own DoH resolver would have to be configured individually. A better solution would have been for Mozilla to fund development of an enduser friendly DNS proxy application which would enable DoH system wide.

The ideal solution would be something that can be installed in any home router, but that's a non-starter because of total lack of home router configuration standards. Flashing a router is not user-friendly for anybody.

The next best solution would be your suggestion, but that too is not practical unless it comes preinstalled on all OSes because the average user won't even know they need something called a DNS proxy. I don't see OS vendors agreeing to preinstall it. Additionally, AFAIK, popular OSes like Android and iOS prior to some versions don't even allow such system-wide DNS proxy configurations.

The practical approach left then is to implement it in browsers, solving it at least for the most common use case on all devices. Everybody knows how to download and install and use browsers. In a discussion forum I frequent, average users ask for ISP censorship bypass solutions all the time. Since Chrome does not support DoH yet, among all the possible solutions - VPN, Tor, SSHproxy - using another browser is actually the most user-friendly, least expensive, most performant option. It helps that it's Mozilla's product because their trust perception is higher than Google/MS/Apple/VPN providers.

I feel Mozilla's taken a good approach overall within the scope of their area of expertise.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#112
post #95

Earlier quoted context omitted.

> Most people don't have their own DNS server, so their DNS traffic is already who-knows-what server with who-knows-what monetization in place (plus its in plaintext, so the rest of the internet gets it too). I know perfectly well who operates my DNS server: My ISP. If they are doing shady stuff, I can sue them, raise awareness or switch providers. I can't do the same with hardwired DoH endpoints.

It's easier to switch ISPs than it is to just configure FireFox to use some other DoH provider?

So now we need to worry about making custom DNS config for every single app on a computer?! It’s absurd.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#113
post #5

I didn't see it mentioned in the article. Has Mozilla said whose servers they will be sending unsuspecting users queries to by default? (IIRC, it was Cloudflare previously. Any reason to believe this has changed?) --- If, like me, you already have a solution in place you are happy with and don't like the idea of others (deciding they know what's best for you and) circumventing it, simply ensure that your existing res…

If true that DoH can be disabled at network level, ad-blocking solutions like pihole should probably implement it by default. Anyone have any idea if this is the case? That would at least save me a lot of trouble and work.

Already implemented in the latest dnscrypt-proxy version.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#114
post #31

Why don't they rather include a resolver in Firefox ? This way, no privacy problems, you're directly contacting authoritarive servers. And you don't rely on a single dns-over-https provider. Is the latency a big problem there? I would say that with caching it is not too bad.

A local resolver using root hints and DNS-over-TLS would be a win for privacy and, at the same time, would not promote centralization of the Internet to DNS-over-HTTPS providers. It still suffers from the problem of overriding local network policy but it's better than just handing all the queries over to a single DoH provider.

How is DoT different from DoH? Do you have an issue with the format on the wire? Because otherwise you can use whichever resolver you want in either case.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#115
post #97

Earlier quoted context omitted.

I think the underlying issue is absolutely a power struggle. Until recently, the general understanding was that each network operator was responsible for the clients inside their network - and therefore also had the ability to set the network's configuration. In 99.99% of the cases, this included access to nonlocal sites on other, public network's, aka "the web", but this was nowhere technically required. Browsers an…

Sorry, I don't understand why this is. Can you not just set up your own DoH server, or use your ISP's (perhaps automatically via DHCP)? How is that different from what happens now, except the traffic is now encrypted?

To my knowledge, one of the defining characteristics of DoH is that it's not configured by the network.

There is a default setting managed by Mozilla which the vast majority of users are expected to use (currently Cloudflare's resolver). You can choose to disable DoH or set your own resolver - however that has to be done manually for every installation of Firefox.

Mozilla is offering a way for networks to signal "don't use DoH here" as described in this article, but Mozilla is intending this to be used for certain specific scenarios only (parental controls and corporate networks) and reserves the right to ignore the signal if it is misused.

To my knowledge, there is no "DoH" entry in DHCP, where a network could specify a local DoH resolver. All articles I've read about it also very much treat it like an application-level protocol, as opposed to the old mechanism where resolution was done centrally by the OS. If this approach is continued, then every application would have to decide for itself which resolver it uses.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#116
post #94

Earlier quoted context omitted.

DoH does not imply centralization in any way. Any trusted party can provide their own DoH endpoint. I can run my own DoH server on a cheap VPS hosted in another country. I live in an increasingly oppressive regime. Most of the blocking is done at DNS level. DoH is a great solution. Slamming DoH because they can anyway spy one way or another is a poor argument.

The issue is each application implementing DoH themselves. Now any software which you wish to use your own DoH resolver would have to be configured individually. A better solution would have been for Mozilla to fund development of an enduser friendly DNS proxy application which would enable DoH system wide.

Meanwhile, dnscrypt-proxy, that has been doing exactly that since 2011, is still looking for help with developing MacOS and Android user interfaces.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#117
post #115

Earlier quoted context omitted.

Sorry, I don't understand why this is. Can you not just set up your own DoH server, or use your ISP's (perhaps automatically via DHCP)? How is that different from what happens now, except the traffic is now encrypted?

To my knowledge, one of the defining characteristics of DoH is that it's not configured by the network. There is a default setting managed by Mozilla which the vast majority of users are expected to use (currently Cloudflare's resolver). You can choose to disable DoH or set your own resolver - however that has to be done manually for every installation of Firefox. Mozilla is offering a way for networks to signal "don…

Is this by design/intention, or just because DoH hasn't caught on yet so Mozilla is setting a sane default here?

I can see how it would be a drawback if the network administrator had no way to configure the setting for all clients.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#118
post #3

At first, I was sceptical of DNS over HTTPS and thought that it gave Cloudflare, who already control too much access over the internet, even more control. However, other DNS providers are available. For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. [1] https://developers.google.com/speed/public-dns/docs/doh/ [2] https://www.quad9.net/doh-quad9-dns-servers/

There are many more secure public resolvers than Google and Quad9 : https://dnscrypt.info/public-servers

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#119
post #3

At first, I was sceptical of DNS over HTTPS and thought that it gave Cloudflare, who already control too much access over the internet, even more control. However, other DNS providers are available. For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. [1] https://developers.google.com/speed/public-dns/docs/doh/ [2] https://www.quad9.net/doh-quad9-dns-servers/

The difference is, DNS-over-HTTPS seems to support cookies and identification. DNS only identified the IP of a person. So it’s clearly an upgrade for Google.

A really good presentation on the privacy implications of "modern DNS" by PowerDNS https://www.youtube.com/watch?v=V2F92orIEO8

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#120

Same story as always with Google "innovations": "hey, we're preventing DNS queries to go to your ISP who is selling it" (to go to our service instead so we can profit from it). It's scary that Moz sides with monopolies like Google and Cloudflare on this one.

At the end, you still need to trust the resolver.

There is a proposal to improve this. Resolves won't know client IPs any more: https://github.com/DNSCrypt/dnscrypt-protocol/blob/master/AN...

Reference client and server implementations should be ready in the next few days.

Post reply on HN