Live data from Hacker News

Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

arstechnica.com

141–150 of 211 posts

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#141
post #47

Earlier quoted context omitted.

How would encrypting DNS help me avoid Comcast MITMing my HTTP traffic to inject bandwidth cap notifications? Doesn't the system just inject a script tag into the appropriate place in the HTTP response?

HTTPS Everywhere + encrypted DNS blocks a huge chunk of what they can see without expending effort on you in particular

FYI if you block this notification (it requires the script tag to load and you to click an I AGREE TO PAY PER GB bullshit thing), you can no longer do UDP traffic and your TCP connections start getting reset.

I found this out the hard way, because I browse nearly all HTTPS sites, and uBlock blocks the injected malware script on the few plaintext sites and never really noticed.

Your IP changes into a shared Comcast-run squid proxy one, all TCP ports are no longer available other than 80/443 filtered through squid, all UDP is no longer available.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#142

> Mozilla in November accused ISPs of lying to Congress in order to spread confusion about encrypted DNS. Mozilla's letter to Congress criticized Comcast > NCTA cable lobby that Comcast belongs to wrote a letter to Congress objecting to Google's plans for encrypted DNS. Comcast gave members of Congress a lobbying presentation that claimed the encrypted-DNS plan would "centraliz[e] a majority of worldwide DNS data wit…

This says to me they've cleared the "but what about encrypted DNS in Firefox?" excuse from the boards so they can focus all their lobbying power fighting the only other encrypted DNS implementation (in Chromium.)

Comcast's anti-DoH argument doesn't work with Mozilla as an adversary. The basis of it is squarely anti-Google so having any other reputed organization backing DoH against them sinks that argument.

This is potentially a very evil move and Mozilla is not only complicit but actually aiding. Concerning.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#143

Earlier quoted context omitted.

> I'm really confused why Mozilla would agree to this. If it's anything like their CloudFlare deals, then Mozilla did this because they were able to secure contracts that provide additional privacy protections for Mozilla's customers that the parent company doesn't normally provide to end-users. In theory, those contracts should be enforceable in court. Whether or not you think the companies Mozilla contracts with wi…

Who are Mozilla's customers? Google are to a close approximation the only ones who pay them??

Customers = users. Mozilla offers paid features in Pocket and Firefox Private Network, and are looking to offer more premium tiers of services. Specifically, the customers who use or pay for FPN have additional privacy protections that CloudFlare doesn't offer to its own customers, despite FPN running on their network.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#144

Earlier quoted context omitted.

I don't understand why Mozilla should care or get involved at all into what Comcast thinks of them. Mozilla introduce a privacy feature in a free, open-source browser. Comcast bitches about it because it prevents them from doing shenanigans, essentially incriminating themselves and proving that the feature is both working as expected and necessary. Why does Mozilla need to care about Comcast's opinion on this, and tr…

> Why does Mozilla need to care about Comcast's opinion on this, and try to work out an "agreement" with them? Money.

You are being downvoted, but are not wrong. A lot of people confuse Mozilla the foundation with Mozilla the corporation, which is the profit seeking branch and the entity which holds the IP. They are different utilities with different goals. They hold similar contracts with Google and you would all do well to at very least become aware of their financial prospectus.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#145
post #88

Earlier quoted context omitted.

There is only a single "archive" that does not allow access to Cloudflare DNS users - not many. It is also exceedingly unlikely that you have greater density of anycast PoPs than Cloudflare's 200+. In your case, you have zero...

Even archive.today has given up on that crusade; I noticed a few days ago that they don't block me anymore (I use Cloudflare DNS) so they have to have stopped within the past couple weeks. So now AFAIK the number of sites that block DNS resolvers which do not forward edns-client-subnet is zero. As it should be.

They continue to attempt to try to associate your connections/use dns cookies. CtrlF 'pixel' when you are visiting one of their pages (not frontpage)

They also attempt to correlate .onion traffic.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#146
post #11

>Comcast told Ars yesterday that "Firefox users on Xfinity should automatically default to Xfinity resolvers under Mozilla's Trusted Recursive Resolver program, unless they have manually chosen a different resolver, or if DoH is disabled. How would this work? Is the detection done once, everytime firefox starts, or everytime the network changes? Would you ever get into a situation where you're not using comcast, but…

My understanding is that Comcast signs a legally-binding contract with Mozilla which imposes the requirements on them [0]. This obviously isn't perfect protection, but it substantially increases the risk of failing to adhere to the requirements. Mozilla claims "We intend to publicly document violations of this Policy and take additional actions if necessary." [1]. Presumably the additional actions include suing for d…

> Presumably the additional actions include suing for damages pursuant to the breach of contract.

Given that the sky is blue, and Comcast is Comcast, Mozilla should have some more funding pretty soon.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#147

Earlier quoted context omitted.

> With all due respect, I have personally had contracts with Comcast in the past and have experienced firsthand how well they honor those -- and I am certainly not the only one! Consumer contracts? Because Mozilla having a business contract with Comcast is certainly not the same as you having a consumer contract - Mozilla has the resources to drag Comcast to court should they be found to ignore the agreement.

Where can we read the contract?

The policy linked by the article is here: https://wiki.mozilla.org/Security/DOH-resolver-policy#Enforc...

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#148

Earlier quoted context omitted.

> Actually not only does Comcast say they don't do that... Just like they said they didn't forcibly reset BitTorrent connections (until they did). Just like they said they didn't silently institute bandwidth caps (until they did). Just like they said they didn't hijack NXDOMAIN responses (until they did). Just like they said they didn't intercept plain-text HTTP connections and inject their own traffic into them (unt…

> With all due respect, I have personally had contracts with Comcast in the past and have experienced firsthand how well they honor those -- and I am certainly not the only one! Consumer contracts? Because Mozilla having a business contract with Comcast is certainly not the same as you having a consumer contract - Mozilla has the resources to drag Comcast to court should they be found to ignore the agreement.

> Mozilla has the resources to drag Comcast to court

They do not. Look at Mozilla's 1099 for proof.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#149

Earlier quoted context omitted.

> With all due respect, I have personally had contracts with Comcast in the past and have experienced firsthand how well they honor those -- and I am certainly not the only one! Consumer contracts? Because Mozilla having a business contract with Comcast is certainly not the same as you having a consumer contract - Mozilla has the resources to drag Comcast to court should they be found to ignore the agreement.

This is a wildly bad take in my opinion. Comcast has proven themselves to be uninterested in adhering to their contractual obligations. You bet your ass they are 1) figuring out how to work around their contract with Mozilla without attracting legal attention, and 2) making contingency plans for winning any resulting lawsuit.

IANAL but I'm not even sure there would be a lawsuit, based on this policy document linked from the article: https://wiki.mozilla.org/Security/DOH-resolver-policy#Enforc...

It looks like the punishment for violating mozilla policies would simply be to remove Comcast from the trusted provider group...maybe. Not very impressive.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#150

Earlier quoted context omitted.

My understanding is that Comcast signs a legally-binding contract with Mozilla which imposes the requirements on them [0]. This obviously isn't perfect protection, but it substantially increases the risk of failing to adhere to the requirements. Mozilla claims "We intend to publicly document violations of this Policy and take additional actions if necessary." [1]. Presumably the additional actions include suing for d…

> Presumably the additional actions include suing for damages pursuant to the breach of contract. Given that the sky is blue, and Comcast is Comcast, Mozilla should have some more funding pretty soon.

I think it's more likely that Mozilla should be dragged into a prolonged and expensive lawsuit that Comcast has the legal might and connections to win pretty soon.
Post reply on HN