Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

121–130 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#121
post #94

Earlier quoted context omitted.

The issue is each application implementing DoH themselves. Now any software which you wish to use your own DoH resolver would have to be configured individually. A better solution would have been for Mozilla to fund development of an enduser friendly DNS proxy application which would enable DoH system wide.

The ideal solution would be something that can be installed in any home router, but that's a non-starter because of total lack of home router configuration standards. Flashing a router is not user-friendly for anybody. The next best solution would be your suggestion, but that too is not practical unless it comes preinstalled on all OSes because the average user won't even know they need something called a DNS proxy.…

DNS-based censorship doesn't work well enough for governments to be useful, it's always just a first step towards much more aggressive censorship tech. You should not advice people to use DoH to circumvent censorship, Tor is a decent longer term solution, and so are private VPNs, proxies.

Although I find it suspicious that there is just DNS filtering on your ISPs side and no IP filtering. Is it at the stage where it's not even enforced, semi-voluntary censorship by ISPs? Otherwise once the government starts checking compliance it will force IP-based filtering too, where DNS filtering circumvention is useless. And governments don't care about how broad the filtering is. Russia, for example, blocked half of the internet once in an attempt to censor Telegram.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#122

Same story as always with Google "innovations": "hey, we're preventing DNS queries to go to your ISP who is selling it" (to go to our service instead so we can profit from it). It's scary that Moz sides with monopolies like Google and Cloudflare on this one.

In my Firefox settings I can choose any DoH provider I want, not just Cloudflare. Naturally something has to be set up as a default so it works. Why is adding DoH in the browser a bad thing?

Because if we’re replacing classic DNS with something new, it needs to be part of the OS.

Not reimplemented (and configured) per application. The user and OS should control the application, not the other way around.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#123

I'd personally prefer to be greeted with a screen providing me with the option of multiple DNS-over-HTTPS providers, and the option of not using one at all, than being silently forced into handing CloudFlare even more of my data.

How about to save time, we could have this choice only once, and that would apply to every application on the machine. Say it could even be handled by the OS itself!

And to save users even more time, not having to configure this per machine, we could have such assignment be an automatic part of the network infrastructure...

We could call it DHCP and DNS! How about it?

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#124

Earlier quoted context omitted.

The ideal solution would be something that can be installed in any home router, but that's a non-starter because of total lack of home router configuration standards. Flashing a router is not user-friendly for anybody. The next best solution would be your suggestion, but that too is not practical unless it comes preinstalled on all OSes because the average user won't even know they need something called a DNS proxy.…

DNS-based censorship doesn't work well enough for governments to be useful, it's always just a first step towards much more aggressive censorship tech. You should not advice people to use DoH to circumvent censorship, Tor is a decent longer term solution, and so are private VPNs, proxies. Although I find it suspicious that there is just DNS filtering on your ISPs side and no IP filtering. Is it at the stage where it'…

It is semi-voluntary and I don't think it's enforced for now - not heard of any end user getting punished by government for circumventing.

DoH is a simple solution that works for now. TorBrowser takes it to the other extreme - it's a good secure solution (I think), but not required as of now, and seen as slow with plugin and other usage restrictions. VPNs, proxies are not seen as good solutions because people prefer free to paid, and they are not as trusted as CF and Mozilla. Self-managed VPNs/proxies are not easy for the average person to setup.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#125

Earlier quoted context omitted.

The difference is, DNS-over-HTTPS seems to support cookies and identification. DNS only identified the IP of a person. So it’s clearly an upgrade for Google.

A really good presentation on the privacy implications of "modern DNS" by PowerDNS https://www.youtube.com/watch?v=V2F92orIEO8

> https://www.youtube.com/watch?v=V2F92orIEO8

So, given the talk, is the industry finally realizing what Mozilla, Cloudflare and Google are trying to pull off with DoH? I guess this is why the change of hearts from them and letting people block DoH within entire networks, hoping not to attract attention of how much control they want to take away.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#126
post #61

Earlier quoted context omitted.

Being in the same jurisdiction is bad: your ISP is THE place for your local law enforcement to get info on your browsing.

Yes. However with Cloudflare, now everyone would effectively be under the jurisdiction of the US which is not necessarily better.

Well, it's good if you live in a non-US-friendly country :)

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#127

Earlier quoted context omitted.

A local resolver using root hints and DNS-over-TLS would be a win for privacy and, at the same time, would not promote centralization of the Internet to DNS-over-HTTPS providers. It still suffers from the problem of overriding local network policy but it's better than just handing all the queries over to a single DoH provider.

How is DoT different from DoH? Do you have an issue with the format on the wire? Because otherwise you can use whichever resolver you want in either case.

I'm on mobile so rather than restate I'll just refer to a comment w/ a good link from an earlier discussion: https://news.ycombinator.com/item?id=19624136

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#128
post #112

Earlier quoted context omitted.

It's easier to switch ISPs than it is to just configure FireFox to use some other DoH provider?

So now we need to worry about making custom DNS config for every single app on a computer?! It’s absurd.

I feel like that’s a slippery slope that will probably never happen. Most likely you’ll have to configure your browser(s) and that’s it.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#129
post #115

Earlier quoted context omitted.

Sorry, I don't understand why this is. Can you not just set up your own DoH server, or use your ISP's (perhaps automatically via DHCP)? How is that different from what happens now, except the traffic is now encrypted?

To my knowledge, one of the defining characteristics of DoH is that it's not configured by the network. There is a default setting managed by Mozilla which the vast majority of users are expected to use (currently Cloudflare's resolver). You can choose to disable DoH or set your own resolver - however that has to be done manually for every installation of Firefox. Mozilla is offering a way for networks to signal "don…

Right? Because the core issue is that browser vendors (and eventually probably OS vendors) do not trust the local network operator. There will be GPO’s and Jamf profiles, and Ansible playbooks to configure this setting for the swarm of machines you ‘own’ but you are simply not a trusted party to any person that connects to your Wi-Fi access point.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#130
post #115

Earlier quoted context omitted.

To my knowledge, one of the defining characteristics of DoH is that it's not configured by the network. There is a default setting managed by Mozilla which the vast majority of users are expected to use (currently Cloudflare's resolver). You can choose to disable DoH or set your own resolver - however that has to be done manually for every installation of Firefox. Mozilla is offering a way for networks to signal "don…

Is this by design/intention, or just because DoH hasn't caught on yet so Mozilla is setting a sane default here? I can see how it would be a drawback if the network administrator had no way to configure the setting for all clients.

The network administrator shouldn’t be able to change any setting at all on client devices. That’s the point! If you can just direct clients to a malicious DoH server then the project has largely failed.

The device administrator should be the one making the choice about what resolvers to use.

Post reply on HN