This misses the forest for the trees. In the UK ISPs are already legally mandated to log your web requests and provide them to the government. Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications. The fact that cloudflare is a US entity and thus not subject to UK law is the whole point.
> Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications And those who live under oppresive governments should not be an excuse to force those who don't to have their traffic routed through a property of an oppressive government. Yes, I know it's not about to be a default for non-US users yet. But "The UK people are getting screwe…
Turn off DoH, Firefox
151–160 of 422 posts
Re: Turn off DoH, Firefox
#152Earlier quoted context omitted.
It's actually not, or am I somehow missing that this is a feature that Mozilla has announced as part of this move? Users who are not technical powerusers will not understand the real security implications of "Enable DNS over HTTPS", and right now I can't find a setting to change the provider anywhere in the settings dialogue, and about:config and enterprise policies are not something that regular users mess with.
It's in Options/Preferences > Network Settings > Settings, scroll to the bottom and select Custom from the Use Provider dropdown. I added AdGuard's DNS over HTTPS address. https://dns.adguard.com/dns-query
But.
(1) There is no informed consent happening here, highlighting to a user, say in Europe, that this would lead to a U.S.-regulated entity knowing a lot about their browsing history. Regular users can't be expected to understand that that is what this setting implies but will think of "DNS over HTTPS" as technical mumbo jumbo that they don't need to pay attention to and that they should keep at default.
(2) The dropdown doesn't have any options besides Cloudflare. In order to use the "Other" option, the user would have to research URLs of providers on the Web, which seems like so much friction that few people will do this.
Re: Turn off DoH, Firefox
#153Re: Turn off DoH, Firefox
#154Earlier quoted context omitted.
privacy-wise, plaintext is the worst option possible.
I can think of something worse: sending all your DNS queries to an unregulated third party.
Re: Turn off DoH, Firefox
#155Earlier quoted context omitted.
And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?
I'm fairly sure that most, even non-technical users understand fairly well that their ISP can snoop on their internet connection. On the other hand I doubt that my mom expects that when she connects to https://www.impots.gouv.fr/ her browser pings an american-owned server to get access.
Re: Turn off DoH, Firefox
#156https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
The people fighting for the status quo probably know how to run their own resolver, even with DoH or DTLS. But Mozilla's conundrum is how to protect everyone 's privacy (and to a certain extent, security). DoH, despite all its flaws, attempts to do that by piggy-backing on already working infrastructure, so it seems like a good fit to move everyone to DoH. But then, they're the chicken-and-egg problem. How do you make sure people deploy local DoH resolvers if no browser enforces the move to DoH ? How do you make sure those resolvers are truthful, or even respect local law (having both is often impossible).
So, you need to compromise. I'd have preferred to have temporary non-profit third party entity handle this à-la-Letsencrypt, but Mozilla deemed its contract with Cloudflare sufficient to provide enough guaranties. Ideally, name resolution should be done closer to the user instead of being centralized like that. But by arguing instead of experimenting we just keep the status quo. Time will tell if this was a bad decision. But it's not as clear cut as this blog post says it is.
Re: Turn off DoH, Firefox
#157Earlier quoted context omitted.
privacy-wise, plaintext is the worst option possible.
I can think of something worse: sending all your DNS queries to an unregulated third party.
Re: Turn off DoH, Firefox
#158Earlier quoted context omitted.
So far I'm using NextDns.io at home, which is DoH and also applies ad-filtering. I haven't heard of any security concerns yet Disclaimer: I do not work or have any financial connection to that service
It will actually not be used anymore, because firefox avoids your local DoH setup.
> Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists.
> The organization said it's been asking ISPs and providers of network-based parental control solutions to add a "canary domain" to their blocklists. When Firefox will detect that this canary domain is blocked, it will disable DoH to prevent the feature to be used as a filter-bypassing solution.
https://www.zdnet.com/article/mozilla-to-gradually-enable-dn...
And I'm already set for the DoH switch https://i.imgur.com/GuP5a8F.png
Re: Turn off DoH, Firefox
#159How decisions are made in Mozilla? By whom? Is there public discussion beforehand?
The conclusion of the debate was that it vastly improves the privacy for most users. Which is why it shipped in Firefox.
Take that into account when you read (misleading, factually wrong) push-back like the original article.
Re: Turn off DoH, Firefox
#160Earlier quoted context omitted.
And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?
The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com…