Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

201–210 of 422 posts

Re: Turn off DoH, Firefox

#201
I had to turn it off, not because I'm opposed to the idea, far from it, I'd love to use DoH, but because cloudflare's spat with archive.is renders the whole thing useless if you ever need to browse archive.is stored copies of pages.

Re: Turn off DoH, Firefox

#202
post #201

I had to turn it off, not because I'm opposed to the idea, far from it, I'd love to use DoH, but because cloudflare's spat with archive.is renders the whole thing useless if you ever need to browse archive.is stored copies of pages.

Kind of a disservice to call it cloudflare's spat when archive.is added special code to make their dns implementation non spec compliant only when queried by cloudflare.

Re: Turn off DoH, Firefox

#203

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

DoH is vital to protect users around the world from censorship and worse. Like I've asked before, should Mozilla also start including an obfuscating VPN by default, to bypass the Chinese firewall? This is a political issue, and one that I don't think Mozilla should even get involved in because it could have very ugly consequences --- just focus on making a good browser and leave the politics (and VPN/firewall-busters…

In case you missed it, https://blog.mozilla.org/blog/2019/09/10/firefoxs-test-pilot...

Re: Turn off DoH, Firefox

#204
post #166

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

> DNS requests are routinely ... monitored by ISPs DoH doesn't prevent ISP monitoring. Even if they cannot see the DNS request, the browser sends the ISP the returned A/AAAA record in the header of a TCP SYN packet. The ISP necessarily sees the hosts you are connecting to; they don't need to see the DNS traffic. DoH to Cloudflare allows both Cloudflare and the ISP to monitor your pattern-of-life. > DoH is vital to pr…

Well, the A/AAAA record and the host you're contacting aren't necessarily the same information, right? You could connect to 10 wildly different sites all behind a CDN and get the same A record for all of them, but vastly different results. It's the host, not the A/AAAA record, that leaks the most information in such a case. DoH/DoT plugs the host being leaked in the DNS packet, then.

But of course, then the problem is punted to SNI, since your TLS Hello packet will probably send the host name with the setup packet, leaking the host then. So we're back to square one. To be fair, Firefox and Cloudflare are also working on ESNI, in which case, from what I understand, your DoH reply will include the A/AAAA record and the public key to encrypt SNI names with, which plugs that final major hole.

So I think the A/AAAA record being exposed doesn't necessarily tank everything, but it certainly isn't perfect, either. But realistically none of these solutions were 100% perfect and a unique A/AAAA record was always going to expose you to a significant amount of side analysis, I think. In general, it just raises the bar and lets us place more trust in the "last hop" between you and the resolvers, much like many other improvements over the past few years, and originally envisioned by e.g. DNSCrypt. In general I feel the actual host header is more important than the A/AAAA record (it is at least more accurate), but I could be super wrong about that.

(The more general discussion about a few major players being able to shape major internet changes for users like this, and general consolidation of the internet is, I think, extremely relevant. But also beyond just this particular exercise.)

Re: Turn off DoH, Firefox

#205

Earlier quoted context omitted.

Not really, my DNS requests go to my ISP's DNS server. And the ISP sees the requests anyway since they are the one forwarding all the packets. Now, Cloudfare will see them too. (if this would come to my country).

But your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.

[deleted]

Re: Turn off DoH, Firefox

#206
I don't know about you guys but in Turkey if you query wikipedia.org from 8.8.8.8 it doesn't return results.

However if you use DoH you can access Wikipedia.

Thank you whoever contributed to DoH!

Re: Turn off DoH, Firefox

#207
post #102

Earlier quoted context omitted.

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com…

This!

This is very bad for Erdoğan. They won't be able to block DNS over HTTPS. Thus teir classic DNS blocks will be useless. Last time I've checked there was over 300K blocked domains via DNS. Even 8.8.8.8 doesn't work.

Re: Turn off DoH, Firefox

#208
post #82

Earlier quoted context omitted.

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

It's worse, because the local ISP is more trustworthy and additionally you enable cloudflare for large scale profiling. And don't claim they won't do it, it's just a matter of time

Are you kidding? My ISP is blocking wikipedia.org, i.imgur.com, imbd.com, torproject.org, and many other.

Re: Turn off DoH, Firefox

#209
post #17
post #9

Earlier quoted context omitted.

I do trust my ISP and my government more than I trust CloudFlare.

It seems very American to me to trust a private actor such as CouldFlare more than your own government. I feel like at least in Europe, a large majority of people would trust their government and local ISP much more than some company halfway over the world with basically no accountancy in your own country, especially an American one since it means your data is basically at the mercy of the US government.

Cloudflare has a better track record than most ISPs and governments.

Re: Turn off DoH, Firefox

#210
post #201

I had to turn it off, not because I'm opposed to the idea, far from it, I'd love to use DoH, but because cloudflare's spat with archive.is renders the whole thing useless if you ever need to browse archive.is stored copies of pages.

Kind of a disservice to call it cloudflare's spat when archive.is added special code to make their dns implementation non spec compliant only when queried by cloudflare.

I wonder if they will deal with it now that all US Firefox users will be unable to use it by default.
Post reply on HN