Earlier quoted context omitted.
ISPs have proven themselves untrustworthy repeatedly, CloudFlare yet really hasn't. Not that I like the control they have, but it's honestly the fault of ISP's this has happened.
some ISPs. The problem is that Mozilla is taking a very US-centric view of a product that is used worldwide.
Turn off DoH, Firefox
181–190 of 422 posts
Re: Turn off DoH, Firefox
#182Earlier quoted context omitted.
This has been tested and debated for months. Initial support for Firefox rolled out 9 months ago or so: https://miketabor.com/enable-dns-over-https-and-encrypted-sn... The conclusion of the debate was that it vastly improves the privacy for most users. Which is why it shipped in Firefox. Take that into account when you read (misleading, factually wrong) push-back like the original article.
> The conclusion of the debate Obviously debate is still on, as we see in here and in [0], and it looks like HN folks are not in favour of these integrations, including me. So question stands, how/why the debate was concluded, did all developers had a vote? Is there a link to discussion? [0] https://news.ycombinator.com/item?id=20927832
I have no idea why you think that random HN discussion afterwards (in response to an article filled with misinformation!) would have any bearing on how Firefox is developed.
https://www.mozilla.org/en-US/about/governance/
>Is there a link to discussion?
There's been about 1.5 year of extended discussion and iteration over DoH, yes. I'm sorry but there certainly isn't just a "single" link!
Re: Turn off DoH, Firefox
#183Up until now, you could use dig, nslookup and other tools to see how your computers resolves to help you figure stuff out.
Now what do you do?
also what happens when firefox uses this cloudflare, some other X application will start using Z, and the third Y.
Also I work, and used to work for many small shops (under 50 people) in different industries. Its standard practice to have internal domains, sometimes even having different things on the same domain (ie mail.comany.co is diffrenet server form inside and outside the network).
If you don't have AD (increasingly common here with apple and linux laptops being the 95% of users), you will have to go to each user on every device that has firefox and help him fix the settings.
I would say just block it at firewall level, but it's not trivial, without breaking sites that use cloudflare.
Re: Turn off DoH, Firefox
#184This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - that seems like less privacy.
And I am not looking forward to finding out the fun ways in which this will break our local DNS.
The idea that Cloudflare is in way more trustworty than my local ISP is at best naïve. All this creates is another huge centralized pool of data with no oversight whatsoever except the promise of some company that is currently growing fast, that they will not do anything with that data. Come the times when money becomes tight again, we'll see how well that promise holds up.
Sure, encrypting DNS is a good thing. But this is just like trying to make email more secure by using a 3rd party encryption gateway - all it does is moving around who to trust.
That's not privacy - that's just silly
Re: Turn off DoH, Firefox
#185Re: Turn off DoH, Firefox
#186Earlier quoted context omitted.
> I trust my ISP and government more than a US company I have no formal contract with and the US government. And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something b…
If you use your ISP's DNS servers, there is no intermediary between you and them.
Re: Turn off DoH, Firefox
#187Earlier quoted context omitted.
...unless you disable it. However you can configure firefox to use your pi-hole if you can get it serving dns over https. If that's not supported now I would expect it becomes supported very soon.
then some "brave" company like apple/mozilla removes the option to disable it
One option would be to worry about mozilla turning off the ability to disable this if they ever actually do that.
Re: Turn off DoH, Firefox
#188Earlier quoted context omitted.
> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https. You can disable dns-over-https if you don't want it enabled. Just go…
Thanks. I feel this should just be a setting on the settings screen. I use a PiHole DNS service at home which I want to keep using over this.
https://www.zdnet.com/article/how-to-enable-dns-over-https-d...
Edit: I've just checked and there is the ability in the settings screen to set a custom DoH provider. So once your pihole can do it you can set it there.
Re: Turn off DoH, Firefox
#189Earlier quoted context omitted.
This is already what happens. Your DNS queries have to go somewhere, and unless you control the DNS servers, there's a third party in the loop somewhere.
Not really, my DNS requests go to my ISP's DNS server. And the ISP sees the requests anyway since they are the one forwarding all the packets. Now, Cloudfare will see them too. (if this would come to my country).
Re: Turn off DoH, Firefox
#190Earlier quoted context omitted.
> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https. You can disable dns-over-https if you don't want it enabled. Just go…
> You can disable dns-over-https if you don't want it enabled. It was also possible to disable Ubuntu from sending your desktop searches to online retailers: * https://www.pcworld.com/article/2889895/how-to-stop-ubuntu-f... Just because something can be disabled does not necessarily mean it should be enabled by default in the first place.