Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

111–120 of 422 posts

Re: Turn off DoH, Firefox

#111
I think it's good Firefox are leading the way on DoH.

The ability to chose which DNS provider you query will be next on the feature list for Firefox I imagine.

Cloudflare have the same mindset to do something about the vulnerability of DNS to snooping (see their 1.1.1.1 app). Two companies with the same mindset. I'm hoping others follow them.

The article itself sounds paranoid and divides those that would rather trust private companies (with good intentions) against those that would rather trust their ISP/Government (also with good intentions).

Re: Turn off DoH, Firefox

#112
As a sysadmin and a user i dont see any problems with DoH, i can easily set a DNS entry[0] so that FF respects my company configuration. And as a user I've been using DoH for months, just not from cloudflare but from CZ NIC because the latency was slightly better. You can easily set your custom DoH provider with 2 clicks in the Options menu. Also for most users I see benefits, because most of them don't use VPNs on free wifis.

edit: I also think OS maintainers are the main problem here, none of this would've happened if they supported DoT or DoH themselves.

[0] https://support.mozilla.org/en-US/kb/configuring-networks-di...

Re: Turn off DoH, Firefox

#113
post #20

Earlier quoted context omitted.

> I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! I trust my ISP and government more than a US company I have no formal contract with and the US government. Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Fi…

> I trust my ISP and government more than a US company I have no formal contract with and the US government. You're not affected then, because the DoH rollout w/ Cloudflare as the default is only planned for the US.

That is not an argument, it is clear that this is supposed to be deployed by default.

Re: Turn off DoH, Firefox

#114
post #87
post #80

Earlier quoted context omitted.

> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services Not true. ISPs typically record and store netflow-like data, very rarely DNS-data (I'd say storing DNS data is even unusual). If ISPs are in a position to get more detailed than netflow data on you they resort to things like deep packet inspection (DPI), which doesn't rely on DNS,…

you too have ignored "it's trivial to change your DoH provider"

It's actually not, or am I somehow missing that this is a feature that Mozilla has announced as part of this move? Users who are not technical powerusers will not understand the real security implications of "Enable DNS over HTTPS", and right now I can't find a setting to change the provider anywhere in the settings dialogue, and about:config and enterprise policies are not something that regular users mess with.

Re: Turn off DoH, Firefox

#115
post #51
post #39

Earlier quoted context omitted.

Would it be hard to make pi-hole into a DoH provider so you could just point your browser at it? Or does that defeat the "just works" factor of the pi-hole?

Probably easier to just turn off DoH in Firefox. In a home LAN configuration, which I'd expect is the vast majority of Pi-hole setups, I don't think you'd really be gaining anything from DoH. And even if Pi-hole does support being a DoH server, you'd have to configure that in Firefox anyway.

Presumably you'd want DoH on the Pi-hole in the other direction, so that it's encrypting your DNS requests forwarded out to the Internet. But yeah, there'd be no reason to want to deal with certificates for your local network machines to do DoH from Pi-hole to PC.

Re: Turn off DoH, Firefox

#116
post #78

Earlier quoted context omitted.

Even worse, corporate intranet addresses get leaked. Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.

Corporations concerned about that should be blocking DoH anyway

Any device at home an go to http://nas and get on my nas, "http://desktop", "http://router", and "http://shed" and get on those.

How does that work in this bold new future? I'll have to register a domain name and add a bunch of A records for 192.168.0.1, but then it still won't work -- I'll have to do "http://desktop.mydomain.com".

Worse, while going to "shed" will work in chrome, it will fail in firefox. My guest network captive portal may well break too if someone visits with firefox.

Re: Turn off DoH, Firefox

#117
post #87
post #80

Earlier quoted context omitted.

> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services Not true. ISPs typically record and store netflow-like data, very rarely DNS-data (I'd say storing DNS data is even unusual). If ISPs are in a position to get more detailed than netflow data on you they resort to things like deep packet inspection (DPI), which doesn't rely on DNS,…

you too have ignored "it's trivial to change your DoH provider"

The average internet user probably has no idea what DNS or HTTPS are, let alone DoH (which even I as a technical user had forgotten existed before I read this post). Defaults matter a whole lot. I haven't formed a definitive opinion on DoH but either way saying "you can configure it so it doesn't matter" is not reasonable in my opinion.

Re: Turn off DoH, Firefox

#118
post #61
post #49

Earlier quoted context omitted.

> I don't think anyone believes CF will start selling data, that's not what the article argues. > Regardless, it's opt-out not opt-in. Which is against newer consumer protection laws such as GDPR. I understand the argument in theory.. but the reality is CF is a more trustworthy DNS provider than basically any consumer ISP in the EU.

This is where me and the author disagree with you. In most places in Europe there is a complete distrust of US companies and hosting anything on US soil. Historically we've seen many cases of US companies handing over data to US authorities (willingly or not).

This is not speculation it's first hand opinion, I am from the UK, i distrust all UK ISPs, their DNS is filth and they are suspected of working with GCHQ... I agree US companies and US law in general are worse for data protection than the EU, but on per company basis CF is more trustworthy and half of the purpose of their DNS is to attempt to provide more privicy.

Re: Turn off DoH, Firefox

#119
post #78

Earlier quoted context omitted.

...and a local HOSTS file. So now it will, by default, contact all the ad/tracking hosts that you configured to be blocked. "But now your DNS queries to those ad/tracking hosts are encrypted!" No. I don't care. I didn't want to connect to those hosts in the first place.

Even worse, corporate intranet addresses get leaked. Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.

Happy to see someone understands the real problem here!

Re: Turn off DoH, Firefox

#120

It's very disturbing to see the overreach that Mozilla has resorted to and the "privacy" argument (it was "security" before that...) being used to justify essentially ignoring system configuration. My ISP has more accountability than a company in another country. The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Exactly. If Mozilla…

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it.

I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts.

There is an argument that ensuring privacy in DNS could be done outside the browser. I think HTTPS is a good precedent for putting privacy in the scope of the browser; the browser should attempt to ensure that privacy expected by the user is established or it should refuse to operate.

I disagree with the solution of trusting Cloudflare, but privacy should be considered crucial to user safety in modern browser design decisions.

Post reply on HN