If the single DoH 'server' is the issue, wouldn't having a list of several 'servers' around the globe (hopefully in places where there isn't any form of censorship and preferably though non-commercial institutions) that the browser selects randomly solve this?
No. The browser has no business in selecting DNS servers; it is a system-wide setting and it should ask the operating system to resolve names. How the operating system resolves names, is up to it. It could use tcp-over-pigeons, if the sysadmin configured it so, and no application should be working around that. If you want to use DoH with Cloudflare, you are free to configure your system to do so. You will also get co…
Turn off DoH, Firefox
211–220 of 422 posts
Re: Turn off DoH, Firefox
#212This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services Not true. ISPs typically record and store netflow-like data, very rarely DNS-data (I'd say storing DNS data is even unusual). If ISPs are in a position to get more detailed than netflow data on you they resort to things like deep packet inspection (DPI), which doesn't rely on DNS,…
Re: Turn off DoH, Firefox
#213This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
Re: Turn off DoH, Firefox
#214Earlier quoted context omitted.
> I trust my ISP and government more than a US company I have no formal contract with and the US government. And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something b…
If you use your ISP's DNS servers, there is no intermediary between you and them.
Re: Turn off DoH, Firefox
#215Earlier quoted context omitted.
No, the other viable option is not enabling DoH by default.
privacy-wise, plaintext is the worst option possible.
My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work).
I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited.
If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have no rights and both American businesses and the American government can do whatever they please with no real recourse.
Re: Turn off DoH, Firefox
#216Earlier quoted context omitted.
Corporations concerned about that should be blocking DoH anyway
Any device at home an go to http://nas and get on my nas, " http://desktop" , " http://router" , and " http://shed" and get on those. How does that work in this bold new future? I'll have to register a domain name and add a bunch of A records for 192.168.0.1, but then it still won't work -- I'll have to do " http://desktop.mydomain.com" . Worse, while going to "shed" will work in chrome, it will fail in firefox. My g…
Re: Turn off DoH, Firefox
#217This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
Too involved. Cloudflare also single-handedly killed web browsing over Tor with extremely frequent and hard CAPTCHAS, until users install a browser extension that sets a cookie encrypted using NSA's favourite elliptic curve flavour.
Just a coincidence, I'm sure. Much like their ability to offer free MITM CDN services to so many web sites.
Re: Turn off DoH, Firefox
#218That being said I am a little confused by those that are concerned because this change would mean their DNS queries will be sent to a US company and they don't trust US companies. Firefox is developed and distributed by a US corporation and is just a susceptible to being forced to follow US government directives as Cloudflare.
Re: Turn off DoH, Firefox
#219Earlier quoted context omitted.
privacy-wise, plaintext is the worst option possible.
I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…
Re: Turn off DoH, Firefox
#220I think it should be on by default. In my country encrypted DNS makes it more difficult for the government to track what people watch and to block sites.
> And to select or enter the DoH provider instead of defaulting to Cloudflare.
You can enter any DNS server address in Firefox.
While I agree, that it is bad to concentrate all the world's DNS queries in the hands of an entity under US jurisdiction, not encrypting DNS is much worse currently. So Cloudflare and US government are the lesser evil for me.
Also, if there were volunteers running free DoH servers then Mozilla could choose one of them randomly instead of sending all queries to USA.