Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

181–190 of 422 posts

Re: Turn off DoH, Firefox

#181

Earlier quoted context omitted.

ISPs have proven themselves untrustworthy repeatedly, CloudFlare yet really hasn't. Not that I like the control they have, but it's honestly the fault of ISP's this has happened.

some ISPs. The problem is that Mozilla is taking a very US-centric view of a product that is used worldwide.

True, I don't think it's ideal, but non-US entities are in slumber, there's still basically no deployment of more secure standards by ISPs. I'd send my ISP an e-mail about providing DoH but they can't even give me IPv6.

Re: Turn off DoH, Firefox

#182
post #159

Earlier quoted context omitted.

This has been tested and debated for months. Initial support for Firefox rolled out 9 months ago or so: https://miketabor.com/enable-dns-over-https-and-encrypted-sn... The conclusion of the debate was that it vastly improves the privacy for most users. Which is why it shipped in Firefox. Take that into account when you read (misleading, factually wrong) push-back like the original article.

> The conclusion of the debate Obviously debate is still on, as we see in here and in [0], and it looks like HN folks are not in favour of these integrations, including me. So question stands, how/why the debate was concluded, did all developers had a vote? Is there a link to discussion? [0] https://news.ycombinator.com/item?id=20927832

>it looks like HN folks are not in favour of these integrations, including me.

I have no idea why you think that random HN discussion afterwards (in response to an article filled with misinformation!) would have any bearing on how Firefox is developed.

https://www.mozilla.org/en-US/about/governance/

>Is there a link to discussion?

There's been about 1.5 year of extended discussion and iteration over DoH, yes. I'm sorry but there certainly isn't just a "single" link!

Re: Turn off DoH, Firefox

#183
One thing that concerns me greatly is debugging network problems.

Up until now, you could use dig, nslookup and other tools to see how your computers resolves to help you figure stuff out.

Now what do you do?

also what happens when firefox uses this cloudflare, some other X application will start using Z, and the third Y.

Also I work, and used to work for many small shops (under 50 people) in different industries. Its standard practice to have internal domains, sometimes even having different things on the same domain (ie mail.comany.co is diffrenet server form inside and outside the network).

If you don't have AD (increasingly common here with apple and linux laptops being the 95% of users), you will have to go to each user on every device that has firefox and help him fix the settings.

I would say just block it at firewall level, but it's not trivial, without breaking sites that use cloudflare.

Re: Turn off DoH, Firefox

#184

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between.

As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - that seems like less privacy.

And I am not looking forward to finding out the fun ways in which this will break our local DNS.

The idea that Cloudflare is in way more trustworty than my local ISP is at best naïve. All this creates is another huge centralized pool of data with no oversight whatsoever except the promise of some company that is currently growing fast, that they will not do anything with that data. Come the times when money becomes tight again, we'll see how well that promise holds up.

Sure, encrypting DNS is a good thing. But this is just like trying to make email more secure by using a 3rd party encryption gateway - all it does is moving around who to trust.

That's not privacy - that's just silly

Re: Turn off DoH, Firefox

#185
Also, do keep in mind that by using DoH, you're also rendering anything like Pi-Hole useless. The solution of course being to use DoH from the Pi-Hole device [0], picking your own provider and disabling it on Firefox. Only step you need to change is the part where upstream providers are given and use your own instead of Cloudflare's default.

[0] https://docs.pi-hole.net/guides/dns-over-https/

Re: Turn off DoH, Firefox

#186
post #31

Earlier quoted context omitted.

> I trust my ISP and government more than a US company I have no formal contract with and the US government. And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something b…

If you use your ISP's DNS servers, there is no intermediary between you and them.

Unless your ISP is running Huawei equipment. ;)

Re: Turn off DoH, Firefox

#187

Earlier quoted context omitted.

...unless you disable it. However you can configure firefox to use your pi-hole if you can get it serving dns over https. If that's not supported now I would expect it becomes supported very soon.

then some "brave" company like apple/mozilla removes the option to disable it

How do you imagine apple will remove an option from mozilla?

One option would be to worry about mozilla turning off the ability to disable this if they ever actually do that.

Re: Turn off DoH, Firefox

#188
post #142

Earlier quoted context omitted.

> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https. You can disable dns-over-https if you don't want it enabled. Just go…

Thanks. I feel this should just be a setting on the settings screen. I use a PiHole DNS service at home which I want to keep using over this.

It is. I just never use the settings screen. See here for how you toggle it, including screenshots. I would expect that the new version will be similar.

https://www.zdnet.com/article/how-to-enable-dns-over-https-d...

Edit: I've just checked and there is the ability in the settings screen to set a custom DoH provider. So once your pihole can do it you can set it there.

Re: Turn off DoH, Firefox

#189

Earlier quoted context omitted.

This is already what happens. Your DNS queries have to go somewhere, and unless you control the DNS servers, there's a third party in the loop somewhere.

Not really, my DNS requests go to my ISP's DNS server. And the ISP sees the requests anyway since they are the one forwarding all the packets. Now, Cloudfare will see them too. (if this would come to my country).

But your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.

Re: Turn off DoH, Firefox

#190

Earlier quoted context omitted.

> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https. You can disable dns-over-https if you don't want it enabled. Just go…

> You can disable dns-over-https if you don't want it enabled. It was also possible to disable Ubuntu from sending your desktop searches to online retailers: * https://www.pcworld.com/article/2889895/how-to-stop-ubuntu-f... Just because something can be disabled does not necessarily mean it should be enabled by default in the first place.

That's a really strange comparison. You know that mozilla has an agreement with cloudflare under which cloudflare has agreed not to log dns queries right?
Post reply on HN