Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

121–130 of 422 posts

Re: Turn off DoH, Firefox

#121

Does anyone knows why does mozilla think this is a good idea? Between each user sharing dns queries with their isps and everyone sharing dns queries with cloudflare it appears that it's obviously more secure the first approach even if none of them is really that great.

ISPs have proven themselves untrustworthy repeatedly, CloudFlare yet really hasn't. Not that I like the control they have, but it's honestly the fault of ISP's this has happened.

Cloudflare has taken sites offline before, in response to legal requests (CP) and social pressure (8ch). Whether it’s right to do it or not, Cloudflare has proven that it is not a neutral party.

Re: Turn off DoH, Firefox

#122
Disagree. Most users haven’t chosen their DNS server, so replacing one unchosen DNS server with another makes no practical difference. And DoH means that people snooping on your network can no longer spy on you.

Cloudflare has committed themselves to not track users via DNS requests, and only log what’s strictly necessary.

And if you distrust Cloudflare, you have a much bigger problem. Half the Internet routes through Cloudflare these days. If they wanted to spy on you, they have (potentially clear-text) access to a good chunk of your HTTPS traffic.

And as many others have pointed out, it’s a much better recommendation to have people change the DoH server to something else.

Re: Turn off DoH, Firefox

#123

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.

The other viable doh provider is google. Other’s timeout is simply not worth the request, in my experience. How does one choose from these two?

Re: Turn off DoH, Firefox

#124
post #93

Earlier quoted context omitted.

The point is that Cloudflare is a US company. From that perspective, where their servers are located is irrelevant.

Of course it is relevant. They claim US government has access to all the logs, this is simply not true.

Please provide some proof that a US company would not have to respond to US government requests. The location of the servers doesn’t matter.

Re: Turn off DoH, Firefox

#125
post #78

Earlier quoted context omitted.

Even worse, corporate intranet addresses get leaked. Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.

Corporations concerned about that should be blocking DoH anyway

How can you block it, if the browser itself is doing the communication, over https no-less?

DoH was made to stop censorship, which includes blocking; if you could just block it, then whats the point of DoH?

Re: Turn off DoH, Firefox

#126

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany).

Germany: Storing data for a limited period of time so that data pertaining to individuals can be requested on a case-by-case basis by law enforcement (we are talking Police, not all of government). Not a big deal.

U.S.: Highly developed and well resourced mass surveillance in operation on both the business side (surveillance capitalism) and government side (NSA). Privacy laws that protect only U.S.-based persons and declare data pertaining to foreign persons to be fair game. Big f*ing deal.

Re: Turn off DoH, Firefox

#127
post #31

Earlier quoted context omitted.

> I trust my ISP and government more than a US company I have no formal contract with and the US government. And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something b…

If you use your ISP's DNS servers, there is no intermediary between you and them.

[deleted]

Re: Turn off DoH, Firefox

#128
post #16

It seems like this change by Firefox would bypass a pi-hole. Am I understanding it correctly?

...unless you disable it. However you can configure firefox to use your pi-hole if you can get it serving dns over https. If that's not supported now I would expect it becomes supported very soon.

then some "brave" company like apple/mozilla removes the option to disable it

Re: Turn off DoH, Firefox

#129

Earlier quoted context omitted.

> the article deliberately buries that it's trivial to change your DoH provider While true for you or me, the vast majority of people will have this enabled by default - probably not even realising it's on

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

I'm fairly sure that most, even non-technical users understand fairly well that their ISP can snoop on their internet connection. On the other hand I doubt that my mom expects that when she connects to https://www.impots.gouv.fr/ her browser pings an american-owned server to get access.

Re: Turn off DoH, Firefox

#130

I hope to see a solution from Mozilla, is it known why they choose DoH with Cloudflare? It seems a bit strange from a company always focused on OSS.

There aren’t a whole bunch of companies that are able to provide a good DNS service world-wide. You’ll need high-reliability DNS servers co-located all over the world. Probably a multi-million dollar investment to get such a thing going, saying nothing of the running costs.
Post reply on HN