Earlier quoted context omitted.
There is virtually no DNSSEC deployed on any major sites on the Internet and, because DNSSEC is a terrible protocol, it's unlikely there ever will be. I'm a broken record on this; you can just search "author:tptacek DNSSEC" in the bar below to get lots of different reasons why. The most important thing for this thread though is that DNSSEC provides zero privacy and, in ordinary deployments (where you talk to a namese…
I don't think DNSSEC itself is likely to ever win. But it does have an additional dimension that makes it a better foundation for privacy than DoH. DoH is strictly transport layer security, meaning it still relies on a trusted third party (Mozilla or Google or whomever) to not vacuum your requests. Whereas if records are signed, they can be sent laterally between mutually untrusting peers, including bulk broadcasts,…
Big ISPs aren’t happy about Google’s plans for encrypted DNS
211–220 of 456 posts
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#212Earlier quoted context omitted.
I don't think DNSSEC itself is likely to ever win. But it does have an additional dimension that makes it a better foundation for privacy than DoH. DoH is strictly transport layer security, meaning it still relies on a trusted third party (Mozilla or Google or whomever) to not vacuum your requests. Whereas if records are signed, they can be sent laterally between mutually untrusting peers, including bulk broadcasts,…
A better foundation for privacy? No. DNSSEC provides literally no privacy. It doesn't encrypt, it only signs. DNSSEC is passively observable by design.
For example, you'd never want to set your DoH resolver to an arbitrary TOR hidden service. But there would be no problem querying DNSSEC through TOR (assuming the setup wrapped the server-server protocol in something that allowed such forwarding).
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#213Earlier quoted context omitted.
So if VPN over Tor (or Tor over VPN) increases anonymity then why is it the popular advice on the Net is not to do it?
Usually because it is very slow to do so. And anything that likes a persisted connection is likely to get a lot of connection resets. Like websockets (slack) or irc
VPNs through Tor also aren't substantially slower than Tor alone. And indeed, one can use MPTCP to aggregate multiple VPN-via-Tor connections. But only between suitably configured devices, of course.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#214Earlier quoted context omitted.
Death to PiHole and every other DNS-based ad block and security system. At least, by Mozilla's plan.
PiHole supports DoH [0], via the cloudflared daemon. This won't change anything. [0] https://docs.pi-hole.net/guides/dns-over-https/
Browser -[regular DNS]-> pihole -[regular DNS]-> cloudflared -[DoH]-> 1.1.1.1
So of the 3 hops, only 1 uses DoH. And specifically, the browser itself doesn't talk DoH.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#215Earlier quoted context omitted.
And yet, most of Google's plans do not warrant skepticism.
Everything warrants skepticism until proven otherwise. Especially things that are being given out for free. Google might be operating on the up and up, but Google is just a large collection of people and some of them will be ethically lacking. And Google's employees have a large incentive to not see any issues with collecting all the personal information that exists.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#216Earlier quoted context omitted.
Here's a twitter thread worth reading, from the former VP of the Firefox group: https://twitter.com/johnath/status/1116871238922776576 It's easy to make proposals that incrementally increase user security while simultaneously increasing one's own ability to consolidate and exploit user data. Technical appeal needs to be evaluated with a simultaneous critical eye to social impact (QUIC is a perfect example -- it outco…
Forget about developing nations, there are plenty of parts of the US where mobile Internet is unreliable or altogether unavailable (I live in Utah, ask me how I know). Google doesn't even care if you're a paying customer -- they sell phones without expandable storage with the explanation that customers should just use the cloud (i.e., Google Drive) instead. Laughable.
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#217Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#218Earlier quoted context omitted.
A better foundation for privacy? No. DNSSEC provides literally no privacy. It doesn't encrypt, it only signs. DNSSEC is passively observable by design.
For privacy, getting records signed is ultimately more long-term important than getting queries encrypted immediately. As DoH shows, bolting on transport layer security is trivial. For example, you'd never want to set your DoH resolver to an arbitrary TOR hidden service. But there would be no problem querying DNSSEC through TOR (assuming the setup wrapped the server-server protocol in something that allowed such forw…
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#219Earlier quoted context omitted.
Here's a twitter thread worth reading, from the former VP of the Firefox group: https://twitter.com/johnath/status/1116871238922776576 It's easy to make proposals that incrementally increase user security while simultaneously increasing one's own ability to consolidate and exploit user data. Technical appeal needs to be evaluated with a simultaneous critical eye to social impact (QUIC is a perfect example -- it outco…
> developing nations -- but of course, Google doesn't care about those audiences Do you have a citation for your claims? There is plenty of evidence to the contrary: https://www.blog.google/technology/next-billion-users/ .
Also, wow, your comment history is just jam-packed with defending Google. Just a fan? Or do you still work at Youtube (https://news.ycombinator.com/item?id=13261130) ?
Re: Big ISPs aren’t happy about Google’s plans for encrypted DNS
#220Earlier quoted context omitted.
Forget about developing nations, there are plenty of parts of the US where mobile Internet is unreliable or altogether unavailable (I live in Utah, ask me how I know). Google doesn't even care if you're a paying customer -- they sell phones without expandable storage with the explanation that customers should just use the cloud (i.e., Google Drive) instead. Laughable.
Then buy a phone with expandable storage, that does run Google's operating system. That's the beauty of Google -- don't like their hardware? Buy one of the hundred other models.
It was just an example in support of the point made in the parent: as far as Google is concerned, the only people that matter are ones with unlimited, fast and reliable Internet access at all times without exception.
If you thought I was facing some kind of dilemma regarding whether or not to buy a phone that is useless half the time I leave my house, then thank you, but that's not the case.