Turn off DoH, Firefox
201–210 of 422 posts
Re: Turn off DoH, Firefox
#202I had to turn it off, not because I'm opposed to the idea, far from it, I'd love to use DoH, but because cloudflare's spat with archive.is renders the whole thing useless if you ever need to browse archive.is stored copies of pages.
Re: Turn off DoH, Firefox
#203This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
DoH is vital to protect users around the world from censorship and worse. Like I've asked before, should Mozilla also start including an obfuscating VPN by default, to bypass the Chinese firewall? This is a political issue, and one that I don't think Mozilla should even get involved in because it could have very ugly consequences --- just focus on making a good browser and leave the politics (and VPN/firewall-busters…
Re: Turn off DoH, Firefox
#204This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
> DNS requests are routinely ... monitored by ISPs DoH doesn't prevent ISP monitoring. Even if they cannot see the DNS request, the browser sends the ISP the returned A/AAAA record in the header of a TCP SYN packet. The ISP necessarily sees the hosts you are connecting to; they don't need to see the DNS traffic. DoH to Cloudflare allows both Cloudflare and the ISP to monitor your pattern-of-life. > DoH is vital to pr…
But of course, then the problem is punted to SNI, since your TLS Hello packet will probably send the host name with the setup packet, leaking the host then. So we're back to square one. To be fair, Firefox and Cloudflare are also working on ESNI, in which case, from what I understand, your DoH reply will include the A/AAAA record and the public key to encrypt SNI names with, which plugs that final major hole.
So I think the A/AAAA record being exposed doesn't necessarily tank everything, but it certainly isn't perfect, either. But realistically none of these solutions were 100% perfect and a unique A/AAAA record was always going to expose you to a significant amount of side analysis, I think. In general, it just raises the bar and lets us place more trust in the "last hop" between you and the resolvers, much like many other improvements over the past few years, and originally envisioned by e.g. DNSCrypt. In general I feel the actual host header is more important than the A/AAAA record (it is at least more accurate), but I could be super wrong about that.
(The more general discussion about a few major players being able to shape major internet changes for users like this, and general consolidation of the internet is, I think, extremely relevant. But also beyond just this particular exercise.)
Re: Turn off DoH, Firefox
#205Earlier quoted context omitted.
Not really, my DNS requests go to my ISP's DNS server. And the ISP sees the requests anyway since they are the one forwarding all the packets. Now, Cloudfare will see them too. (if this would come to my country).
But your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.
Re: Turn off DoH, Firefox
#206However if you use DoH you can access Wikipedia.
Thank you whoever contributed to DoH!
Re: Turn off DoH, Firefox
#207Earlier quoted context omitted.
And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?
The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com…
This is very bad for Erdoğan. They won't be able to block DNS over HTTPS. Thus teir classic DNS blocks will be useless. Last time I've checked there was over 300K blocked domains via DNS. Even 8.8.8.8 doesn't work.
Re: Turn off DoH, Firefox
#208Earlier quoted context omitted.
And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?
It's worse, because the local ISP is more trustworthy and additionally you enable cloudflare for large scale profiling. And don't claim they won't do it, it's just a matter of time
Re: Turn off DoH, Firefox
#209Earlier quoted context omitted.
I do trust my ISP and my government more than I trust CloudFlare.
It seems very American to me to trust a private actor such as CouldFlare more than your own government. I feel like at least in Europe, a large majority of people would trust their government and local ISP much more than some company halfway over the world with basically no accountancy in your own country, especially an American one since it means your data is basically at the mercy of the US government.
Re: Turn off DoH, Firefox
#210I had to turn it off, not because I'm opposed to the idea, far from it, I'd love to use DoH, but because cloudflare's spat with archive.is renders the whole thing useless if you ever need to browse archive.is stored copies of pages.
Kind of a disservice to call it cloudflare's spat when archive.is added special code to make their dns implementation non spec compliant only when queried by cloudflare.