Live data from Hacker News

NextDNS Joins Firefox’s Trusted Recursive Resolver

blog.mozilla.org

21–30 of 146 posts

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#21
post #18

I'm not sure how I feel about Firefox's strategy for DoH. On the one hand, moving DNS out of the hands of ISPs that (at least in the US) have no real incentive to respect user privacy is probably a good thing. On the other hand, circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental co…

It's probably a good thing? US ISPs actively collect data from DNS lookups. They're an actual according-to-Hoyle threat actor in the IETF's supposed threat model.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#22
post #21
post #18

I'm not sure how I feel about Firefox's strategy for DoH. On the one hand, moving DNS out of the hands of ISPs that (at least in the US) have no real incentive to respect user privacy is probably a good thing. On the other hand, circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental co…

It's probably a good thing? US ISPs actively collect data from DNS lookups. They're an actual according-to-Hoyle threat actor in the IETF's supposed threat model.

> It's probably a good thing? US ISPs

The world is hella lot bigger than the US.

And Firefox runs in the rest of the world too.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#23
post #21

Earlier quoted context omitted.

It's probably a good thing? US ISPs actively collect data from DNS lookups. They're an actual according-to-Hoyle threat actor in the IETF's supposed threat model.

> It's probably a good thing? US ISPs The world is hella lot bigger than the US. And Firefox runs in the rest of the world too.

It's also a lot bigger than the EU.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#24
post #10

I never heard of NextDNS. I am appalled. From their site: https://nextdns.io > See what's happening on your devices with in-depth Analytics and real-time Logs. > Protect your kids and control what they can access online. Their pricing page is also extremely troubling. > We may adjust this later on based on actual costs at scale, but it will follow this logic. What the hell is this Mozilla... This is not a company you…

Wow, you're pretty easily upset. Was Mozilla alive for you before this?

Their privacy policy is pretty straightforward: https://nextdns.io/privacy

Not saying this is going to be good, but at least I'm going to withhold judgement until I've got more data.

> They also aren't at scale, and have to learn lessons the hard way with outages.

Is that a reason you're upset about? Is that a certainty? I don't get it.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#25
How do these DoH partnerships work with DNS split views? If folks are running an internal copy of "something.company.com" and it's expected to resolve to RFC3330 space "on the company network" ... that depends on folks computers and devices using the corporate DNS. If Firefox is going to a public DoH endpoint, they'll get the public IPs instead and connect to the wrong copy of the service, or it might not even resolve if it's an internal-only record.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#26
Congratulations NextDNS! You've been relentlessly executing on every front [0] with super-novel solutions [1] that a few, if any, incumbents have matched [2].

That said, I'm surprised Mozilla doesn't look at the uptime metrics before partnering with TRRs. I've been using NextDNS ever since it was announced here [3] and have been subject to a fair share of "outages" including once when everyone at home thought the internet was down...but couldn't remedy it [4].

Cloudflare's data-plane availability with 1.1.1.1 is a tall-order to match for anyone that's not Google or AWS [5]. The NextDNS founders built DailyMotion, so I'm guessing they know a thing or two about high availability and hopefully fix whatever they need to before they GA with Firefox TRR.

I must point out that Adguard DNS [6] is a viable non-configurable free alternative, which is what I now recommend to folks not savvy/bothered enough to configure NextDNS. It would be wonderful to see them added to TRR.

[0] https://news.ycombinator.com/item?id=21543038

[1] https://news.ycombinator.com/item?id=21604825

[2] https://news.ycombinator.com/item?id=20851626

[3] https://news.ycombinator.com/item?id=20012687

[4] https://news.ycombinator.com/item?id=20785712

[5] https://aws.amazon.com/blogs/architecture/category/networkin...

[6] https://news.ycombinator.com/item?id=18788410

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#27
I'm a fan of DoH, but I'm also a Chromecast owner, so I get to experience the downsides of application-level DNS resolvers. Chromecasts will ignore the DNS servers set by DHCP, and will cease to function if they cannot communicate with Google's DNS servers[1].

That means my network-enforced DNS preferences that block ad and malware sources are ignored, and I see more ads than I want to. It also means that when Google drops support for my Chromecast model like they did with the older Chromecast models, I'll be slightly less secure than I would be if I could enforce my own DNS preferences.

[1] https://news.ycombinator.com/item?id=19170671

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#28

I'm a fan of DoH, but I'm also a Chromecast owner, so I get to experience the downsides of application-level DNS resolvers. Chromecasts will ignore the DNS servers set by DHCP, and will cease to function if they cannot communicate with Google's DNS servers[1]. That means my network-enforced DNS preferences that block ad and malware sources are ignored, and I see more ads than I want to. It also means that when Google…

Oh wow I did not know that.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#29
“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of their data and privacy online.”

It sounds more like the work is to put Mozilla and their partners in control of users' data and privacy online.

Let's be honest. This is really a transfer of control from one third party, e.g., a company providing internet service (ISP), to another third party, e.g., a company/organization providing a browser (Mozilla, Google, etc.), not to mention their "TRR" partners.

Surely it is only a fortuitous coincidence, but DOH in the browser makes it easier to track users by device, which appears to be the Holy Grail of the internet ad industry.

Putting Mozilla (and their partners) in charge of user privacy is different from putting users in charge of their own privacy.

Also, the "back in control" language is interesting. It implies the author believes users were "in control" in the past.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#30

Earlier quoted context omitted.

"Protecting your kids" is often "we log everything and have complete visibility over how people are using our service, and we're willing to share a bit of that with parents to spy on their children". It's a valid concern to have unless there's evidence to the contrary.

Further, any mention of homosexuality is often considered to be inherently and unmistakably morally obscene, such as by the One Million Moms group, or as described by various state GOP platforms. This would include the narratives on whether lesbian or gay parents exist.

One of the positives of DNS-level blocking is that it's relatively rough-grained. You can block pornhub.com, but you can't block out every mention of homosexuality at the DNS level without blocking any site that may potentially mention it, which would include any news site, discussion forum, social media, etc.

We should be skeptical of aggresively-enforced DoH. In most cases, the vendor's interest in stopping ad blockers is stronger than their interest in protecting user privacy. Mozilla is slightly more removed, but as they're dependent on The Big G for revenue, we're basically just waiting for that shoe to drop.

Post reply on HN