Live data from Hacker News

My Chromecast Ultra would not start until I began answering 8.8.8.8

mailarchive.ietf.org

121–130 of 519 posts

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#121

I'm always shocked at how easy it is for people to fall into the "Google is evil!!1" trap on such trivial stuff (and funnily enough, much more serious privacy issues related to Google are ignored/downvoted). Hardcoded DNS servers are common. Extremely common in a bunch of IOT devices, given how broken some ISPs are. This is a non-story and the only reason it's being upvoted is because Google is doing it, and they als…

This isn't a case of an IOT device though. My Chromecast went through massive amount of trouble to use Google's DNS servers, to serve ads behind my pi-hole. It would respect all of my DHCP parameters, but silently ignore DNS settings. It was clearly intentional to serve ads. I had to set up a firewall to force it to use my DNS server. And eventually even that stopped working with an update (which themselves are reall…

I was going to post something similar. This is not an accident or a mistake. This was done on purpose.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#122
post #104

Earlier quoted context omitted.

Given the ratio of people who upvote stories based on their title without clicking through, I highly doubt that.

We don't know what that ratio is, as we don't track it, and I'm skeptical that anyone does.

shrugs I wasn't referring specifically to HN, nor was I trying to suggest I know the exact ratio. What I know is it's extremely unlikely that this story is being upvoted because of that given that 1. A lot of people upvote on title alone (I'll die on that hill); 2. Not many people know who Paul Vixie is; 3. Those that do might not notice the name in the UI/email (I certainly didn't).

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#123

Earlier quoted context omitted.

I'm not sure Im following why is HTTPS going to cause a shitload more problems?

Not HTTPS. DNS over HTTPS. If we create internet infrastructure (like DNS over HTTPS) which prevents network operators from actually operating their networks, I’m 100% confident we will find it has bad, unintended and irreversible consequences.

If by "network operators" you mean ISP's then I don't care. They have proven beyond a shadow of a doubt that they are malicious ones more often than not and I want them to be a dumb pipe NOT someone who is mucking around with my network. I will take being able to PICK who I trust my DNS with over being forced to use my ISP's any day of the week. One of those things I can change, one of them I cannot.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#124

Earlier quoted context omitted.

> bind it to it's own local dnsmasq or whatever and then send DNS onward to DHCP DNS servers supplied by your ISP... There's a reason for the push for DNS over HTTPS. This is looking at things and totally backwards. You have a local problem, a broken router and you suggest we fix this by changing how all edge nodes on the internet works. In the age of ever increasing, untrustworthy IOT-devices, you don’t solve this p…

I'm not sure Im following why is HTTPS going to cause a shitload more problems?

Because it's encrypted to the app rather than the endpoint's OS or local DNS, so it's more difficult for the system owner to override it or implement a systemic policy.

The performance characteristics are also rather unfortunate. TCP handshake + TLS handshake with multiple public key operations + TCP protocol overhead adds quite a lot of both latency and computation vs. UDP DNS. DoH is even worse. There would have been ways (e.g. DNSCurve) to get equivalent or better security with less latency and computation if it weren't for horrible middleboxes breaking everything they don't understand.

And all that complexity is attack surface.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#125

I've seen this been done before, and IME it's reasonable behavior. I've seen so many instances of computers configured with DNS servers which are extremely slow, or provide garbage results, that adding a known good DNS server to the list, and then parallel resolving across all of them is a perfectly legitimate thing to do.

Case in point, I was getting NXDOMAIN for mailarchive.ietf.org until I switched to 8.8.8.8 from my work's DNS.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#126
post #25

Earlier quoted context omitted.

Unless you want your own dns server used at all times.

But why would you care about that? You're already connecting to Google's service, YouTube, so what does it change to use Google's DNS to resolve it? What is the circumstance where you'd care about not using Google's DNS but then connect to a Google service anyway? If Chromecasts allowed arbitrary web browsing, I would maybe see your point -- but they don't.

One reason to care is that https://pi-hole.net is DNS-based.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#127

DNAT 8.8.8.8:53 back to your own DNS server.

Came here to say exactly this. Why even make a fuss about it? Bro, do you even NAT?

The argument is Google can record what you're sending your Chromecast. Well, (sorry for the crudeness) no shit... You're using Google hardware. If you're going to act like the DoD and not use Huawei switches, then don't use Huawei switches.

If you so choose, you must look at Google as malevolent as the US DoD would see an attacking nation state, and actively do things about it (like not buy their hardware). Otherwise, shut yo trap.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#129
It's not new, and but limited to Chromecast Ultra, I detected this from several Android devices (phones) pre-Pie and configured my firewall to redirect those requests to my own DNS.

Regardless of their reason, many of us don't want to use Google DNS and the just using their control over these devices to force people to 8.8.8.8/8.8.4.4.

I haven't checked how Pie behaves yet but it provides an option in the UI to specify private DNS.

Also, I found some time ago, and am not sure if it's still the case, but some of their first-party apps hard coded Google DNS, so seeing one at the system level was irrelevant.

Re: My Chromecast Ultra would not start until I began answering 8.8.8.8

#130

Earlier quoted context omitted.

I can't really entertain the suggestion that pi-holes are considered by Google as a serious-enough threat that they'd go through this trouble just to fuck with it. Seriously, think about the venn diagram of Chromecast users and pi-hole users. It looks a lot like a tennis ball being dropped into the sun.

At a maximum rate of $58 per tenis ball: https://www.statista.com/statistics/195680/share-of-keywords...

Mesothelioma cost 319$ 5 years ago and I'm pretty sure it's only gone up since then: https://www.adgooroo.com/the-most-expensive-keywords-in-paid...
Post reply on HN