Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

221–230 of 422 posts

Re: Turn off DoH, Firefox

#221

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.

So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).

Re: Turn off DoH, Firefox

#222

> It is clear what Mozilla needs to do: Mozilla can and should revert the change and allow users to easily opt-in. I think it should be on by default. In my country encrypted DNS makes it more difficult for the government to track what people watch and to block sites. > And to select or enter the DoH provider instead of defaulting to Cloudflare. You can enter any DNS server address in Firefox. While I agree, that it…

Why not install DoH system wide, then (the kind of change which is easy if tools like Firefox use the system APIs for this and very difficult if individual applications all reimplement DNS) instead of only doing it for Firefox?

Re: Turn off DoH, Firefox

#223
post #215
post #141

Earlier quoted context omitted.

privacy-wise, plaintext is the worst option possible.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

So it depends on the country. In my country (Russia) all Internet traffic is being recorded by the ISP for the last month and sites are blocked on political reasons. For me having DoH with Cloudflare is better.

Re: Turn off DoH, Firefox

#225

Earlier quoted context omitted.

But your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.

No I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).

With TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).

Re: Turn off DoH, Firefox

#226

Earlier quoted context omitted.

Yes, it's trivial. It's also very annoying to the probably 99% of users who don't care about it at all, especially if this becomes just one of many settings that needs to be configured on startup.

Make it random then.

Random security settings that differ with each installation? No thanks, I’d rather not play dice with security.

Re: Turn off DoH, Firefox

#227
post #222

> It is clear what Mozilla needs to do: Mozilla can and should revert the change and allow users to easily opt-in. I think it should be on by default. In my country encrypted DNS makes it more difficult for the government to track what people watch and to block sites. > And to select or enter the DoH provider instead of defaulting to Cloudflare. You can enter any DNS server address in Firefox. While I agree, that it…

Why not install DoH system wide, then (the kind of change which is easy if tools like Firefox use the system APIs for this and very difficult if individual applications all reimplement DNS) instead of only doing it for Firefox?

Because it is easier to embed it into a browser rather than persuade vendors of all major OSes (Windows, Mac, Android and thousand of Linux distributions) to add it.

Also, even if a company like Microsoft adds it to Windows, they will add it only to they latest version and leave people on Windows XP, 7 and 8 without protection. Same with Google - they will add it only to the latest Android. Because commercial companies want you to buy new products, not to use the old one for a long time.

Re: Turn off DoH, Firefox

#228

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany). Germany: Storing data for a limited period of time so that data pertaining to individuals can be requested on a case-by-ca…

European privacy laws are great, but I’m not so sure it’s as simple as you make it out to be. German intelligence also cooperates with the US on NSA surveillance.

https://www.reuters.com/article/us-germany-spying-merkel/mer...

Re: Turn off DoH, Firefox

#229
post #138

Earlier quoted context omitted.

> The fact that cloudflare is a US entity and thus not subject to UK law is the whole point. As a fellow citizen of a Five Eyes country, I assume that if any of those 5 have info about me that one of the other four wants it won't even be a question of paperwork for it to be shared.

The previous UK law, RIPA, was abused for investigating minor crimes such as fraudulently obtaining disabled parking badges. It's not just about national governments but local municipal authorities too. Yes I would prefer another jurisdiction but it's way better than the status quo whereby the browsing history is just handed over.

> The previous UK law, RIPA, was abused for investigating minor crimes such as fraudulently obtaining disabled parking badges.

I understand that you're trying to illustrate a larger problem, but that example is likely to get you zero sympathy from anybody, anywhere.

I know that US ISPs have an established pattern of "just handing over" browsing history, but I have no idea what CF's track record is like.

Re: Turn off DoH, Firefox

#230
post #120

It's very disturbing to see the overreach that Mozilla has resorted to and the "privacy" argument (it was "security" before that...) being used to justify essentially ignoring system configuration. My ISP has more accountability than a company in another country. The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Exactly. If Mozilla…

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…

I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts.

I strongly disagree. A browser has one job, and that is to follow and render URLs. Secure connections and such are services provided by other components of the OS, and the browser should absolutely use those services but not attempt to overreach its main purpose. It's really the principle of "do one thing and do it well".

To spin your analogy, you're arguing that cars should have seatbelts that also check your age and blood alcohol level because "that's also a safety thing".

There is an argument that ensuring privacy in DNS could be done outside the browser

Yes, the same way that VPN clients are; and I'm perfectly happy for Mozilla to be working in that area, but most certainly do not put that in the browser and do not make it default.

Post reply on HN