Live data from Hacker News

What’s Next in Making Encrypted DNS-over-HTTPS the Default

blog.mozilla.org

21–30 of 191 posts

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#21
> Fall back to operating system defaults for DNS when split horizon configuration or other DNS issues cause lookup failures.

I hope we'll be given the opportunity to disable this, or at the very least show a warning (similar to cert warnings?) that something's off.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#22

The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.

The article explicitly mentions the way to tell applications including Firefox not to disregard the OS DNS: blocking a canary domain. It even links to detailed instructions. Frankly, given how much trouble I've had with systemd's DNS meddling, I look forward to applications taking DNS under their own control.

It's a bad idea what it end up starting a cycle where every big application uses their own DNS. Some of them might not wven do it right

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#23
post #19

There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…

Well, DoH effectively bypass DNS-filters set up by countries. While some are questionable, I believe it won't take long until Mozilla ends up with some bad press, and being an underdog it doesn't need that.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#24
post #3

At first, I was sceptical of DNS over HTTPS and thought that it gave Cloudflare, who already control too much access over the internet, even more control. However, other DNS providers are available. For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. [1] https://developers.google.com/speed/public-dns/docs/doh/ [2] https://www.quad9.net/doh-quad9-dns-servers/

> For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. Using Google is giving your browsing history to an Ad company, why? At least Quad9 is non-profit. It also provides DNS over TLS, DoT service, which I'm using.

Because with Google you only have to trust one organization that flat out says in the FAQ that they do not "correlate or combine information from temporary or permanent logs with any personal information that [you] have provided Google for other services".

Quad9 is a conglomorate of "Threat Intelligence Partners" and three founding organizations: IBM, Packet Clearing House and Global Cyber Alliance https://www.quad9.net/about/ . What's that third one? I don't know, but it's founded by The City of London Police, NY District Attorney and the Center for Internet Security https://www.globalcyberalliance.org/who-we-are/ that third one is like a hundred "Partners", with such privacy champions as The US Secret Service. Over 100 organizations. What are their incentives? What role do all these organization play and how much access do they have? Who knows.

Compare their privacy policies. They're strikingly similar because Quad9 largely lifted theirs from Google's (I'm assuming, since theirs came later)

https://developers.google.com/speed/public-dns/privacy

https://www.quad9.net/policy/

Google's policy states they collect private information for 24-48 hours, keep "anonymized" information for 2 weeks and then randomly samples that data for permanent storage:

> Google Public DNS stores two sets of logs: temporary and permanent. The temporary logs store the full IP address of the machine you're using. We have to do this so that we can spot potentially bad things like DDoS attacks and so we can fix problems, such as particular domains not showing up for specific users.

> We delete these temporary logs within 24 to 48 hours.

> In the permanent logs, we don't keep personally identifiable information or IP information. We do keep some location information (at the city/metro level) so that we can conduct debugging, analyze abuse phenomena. After keeping this data for two weeks, we randomly sample a small subset for permanent storage.

Quad9 collects effectively the same information (except AS) as Google's 2 week logs and says

> All the above data may be kept in full or partial form in permanent archives.

If you want a game theoretic, capitalist analysis, Google has an incentive to keep the web running and keeping it an awesome platform, to make sure humanity's information is created and shared in an open format that they know how to index and that they can freely index, instead of apps or some alternative web or some other walled garden.

But we're bombarded daily with "goog bad" by politicians and journalists, so Google must obviously be just brazenly lying and you should give your DNS history to an organization founded by The City of London Police instead that "share anonymized data on specific domains queried [...] with its threat intelligence partners".

Please double check my work, I didn't read the privacy policies too carefully (I think notably Google stores the AS number and Quad9 doesn't) because I don't actually care, I (along with roughly 100% of internet users) just give all my DNS history in plain text to my ISP.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#25

The article is not clear about one issue: are all applications expected to disregard the OS DNS? Is there an option to tell all applications that they should not bypass it? I will be pretty pissed if I wake up one day and find that Firefox decided to stop using my DNS server and instead started sending my requests to a third-party.

The article explicitly mentions the way to tell applications including Firefox not to disregard the OS DNS: blocking a canary domain. It even links to detailed instructions. Frankly, given how much trouble I've had with systemd's DNS meddling, I look forward to applications taking DNS under their own control.

> blocking a canary domain

And how long will it take for most ISPs to block this domain when they realize that their DNS servers are not being used anymore? Some of them sell this data so they see it as a source of revenue.

At this point this canary domain will have the same fate as Do Not Track.

> I look forward to applications taking DNS under their own control.

I am sure I can find a hundred applications/programs resolving domains on my machine. It is unrealistic to configure all of them separately. At this point we are back to the OS providing the configuration for all of them.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#26

What is the latency for DoH compared to traditional UDP DNS?

Here's a whitepaper that did some benchmarks and a detailed analysis on it. Was posted on hn a few days ago. https://arxiv.org/abs/1907.08089

They test various network conditions with some results showing DoH and DoT loading webpages faster than udp dns (due to tcp timing out faster than udp on lossy connections )

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#27
post #20

Unfortunately, Mozilla are planning to leave DoH off by default for Firefox users in the UK. Almost certainly to avoid criticism from politicians and children’s charities about how DoH would interfere with the UK’s network level website blocking of ‘adult’ websites.

Hrhr. But talk about how it intends to prevent censorship...

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#28
post #24

Earlier quoted context omitted.

> For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. Using Google is giving your browsing history to an Ad company, why? At least Quad9 is non-profit. It also provides DNS over TLS, DoT service, which I'm using.

Because with Google you only have to trust one organization that flat out says in the FAQ that they do not "correlate or combine information from temporary or permanent logs with any personal information that [you] have provided Google for other services". Quad9 is a conglomorate of "Threat Intelligence Partners" and three founding organizations: IBM, Packet Clearing House and Global Cyber Alliance https://www.quad9.…

My history goes mostly to my carefully chosen, overseas VPN provider. Yes, there are no good choices, best you can do is to split your data between several parties, so its hard to correlate. Google has data on most people on the planet, unlike London Police, so giving Google your data is way more dangerous than other parties combined. And user data is Google primary business model.

And I wouldn't spend much time analysing policies, they are all "we pinky swear". Its is there a business incentive in using my data or not.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#29
post #3

At first, I was sceptical of DNS over HTTPS and thought that it gave Cloudflare, who already control too much access over the internet, even more control. However, other DNS providers are available. For instance Google[1] and Quad 9 [2] both provide free DNS over HTTPS services. [1] https://developers.google.com/speed/public-dns/docs/doh/ [2] https://www.quad9.net/doh-quad9-dns-servers/

The difference is, DNS-over-HTTPS seems to support cookies and identification. DNS only identified the IP of a person.

So it’s clearly an upgrade for Google.

Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default

#30
post #24

Earlier quoted context omitted.

Because with Google you only have to trust one organization that flat out says in the FAQ that they do not "correlate or combine information from temporary or permanent logs with any personal information that [you] have provided Google for other services". Quad9 is a conglomorate of "Threat Intelligence Partners" and three founding organizations: IBM, Packet Clearing House and Global Cyber Alliance https://www.quad9.…

My history goes mostly to my carefully chosen, overseas VPN provider. Yes, there are no good choices, best you can do is to split your data between several parties, so its hard to correlate. Google has data on most people on the planet, unlike London Police, so giving Google your data is way more dangerous than other parties combined. And user data is Google primary business model. And I wouldn't spend much time anal…

If you want privacy, use Tor. Like Richard Stallman https://stallman.org/stallman-computing.html

Anything else like a "VPN" (which is really just a proxy under a cooler name) is somewhere between a half measure, a snake oil hobby or self-sabotage (if you picked the wrong VPN).

You don't trust a large multi national that works on encryption and tries to deny frivolous law enforcement requests when it outright says it samples a small amount of "anonymized" data and doesn't correlate it with anything else it has on you or sell it

>> Is any of the information collected stored with my Google account?

> No.

>> Does Google share the information it collects from the Google Public DNS service with anyone outside Google?

> No, except in the limited circumstances described in Google's privacy policy, such as legal processes and enforceable governmental requests. (See also Google's Transparency Report on user data requests.)

>> Does Google correlate or combine information from temporary or permanent logs with any personal information that I have provided Google for other services?

> No.

https://developers.google.com/speed/public-dns/faq

yet trust some small, anonymous group of people that set up a proxy that's netting them like $5/month of revenue per user in a highly competitive market?

> [policies] are all "we pinky swear"

Are they not legally binding? But yea, like I said, obviously they're just brazenly lying because of course they are. "goog bad" has been established. I'm not sure how or where... but everyone knows that.

Better be safe and give your data to an organization that lists the US Secret Service as a "Partner".

Post reply on HN