This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.
Turn off DoH, Firefox
221–230 of 422 posts
Re: Turn off DoH, Firefox
#222> It is clear what Mozilla needs to do: Mozilla can and should revert the change and allow users to easily opt-in. I think it should be on by default. In my country encrypted DNS makes it more difficult for the government to track what people watch and to block sites. > And to select or enter the DoH provider instead of defaulting to Cloudflare. You can enter any DNS server address in Firefox. While I agree, that it…
Re: Turn off DoH, Firefox
#223Earlier quoted context omitted.
privacy-wise, plaintext is the worst option possible.
I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…
Re: Turn off DoH, Firefox
#224Re: Turn off DoH, Firefox
#225Earlier quoted context omitted.
But your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.
No I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).
Re: Turn off DoH, Firefox
#226Earlier quoted context omitted.
Yes, it's trivial. It's also very annoying to the probably 99% of users who don't care about it at all, especially if this becomes just one of many settings that needs to be configured on startup.
Make it random then.
Re: Turn off DoH, Firefox
#227> It is clear what Mozilla needs to do: Mozilla can and should revert the change and allow users to easily opt-in. I think it should be on by default. In my country encrypted DNS makes it more difficult for the government to track what people watch and to block sites. > And to select or enter the DoH provider instead of defaulting to Cloudflare. You can enter any DNS server address in Firefox. While I agree, that it…
Why not install DoH system wide, then (the kind of change which is easy if tools like Firefox use the system APIs for this and very difficult if individual applications all reimplement DNS) instead of only doing it for Firefox?
Also, even if a company like Microsoft adds it to Windows, they will add it only to they latest version and leave people on Windows XP, 7 and 8 without protection. Same with Google - they will add it only to the latest Android. Because commercial companies want you to buy new products, not to use the old one for a long time.
Re: Turn off DoH, Firefox
#228This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
> DNS requests are routinely intercepted and monitored by ISPs in many countries, with the information available to the security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany). Germany: Storing data for a limited period of time so that data pertaining to individuals can be requested on a case-by-ca…
https://www.reuters.com/article/us-germany-spying-merkel/mer...
Re: Turn off DoH, Firefox
#229Earlier quoted context omitted.
> The fact that cloudflare is a US entity and thus not subject to UK law is the whole point. As a fellow citizen of a Five Eyes country, I assume that if any of those 5 have info about me that one of the other four wants it won't even be a question of paperwork for it to be shared.
The previous UK law, RIPA, was abused for investigating minor crimes such as fraudulently obtaining disabled parking badges. It's not just about national governments but local municipal authorities too. Yes I would prefer another jurisdiction but it's way better than the status quo whereby the browsing history is just handed over.
I understand that you're trying to illustrate a larger problem, but that example is likely to get you zero sympathy from anybody, anywhere.
I know that US ISPs have an established pattern of "just handing over" browsing history, but I have no idea what CF's track record is like.
Re: Turn off DoH, Firefox
#230It's very disturbing to see the overreach that Mozilla has resorted to and the "privacy" argument (it was "security" before that...) being used to justify essentially ignoring system configuration. My ISP has more accountability than a company in another country. The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Exactly. If Mozilla…
> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…
I strongly disagree. A browser has one job, and that is to follow and render URLs. Secure connections and such are services provided by other components of the OS, and the browser should absolutely use those services but not attempt to overreach its main purpose. It's really the principle of "do one thing and do it well".
To spin your analogy, you're arguing that cars should have seatbelts that also check your age and blood alcohol level because "that's also a safety thing".
There is an argument that ensuring privacy in DNS could be done outside the browser
Yes, the same way that VPN clients are; and I'm perfectly happy for Mozilla to be working in that area, but most certainly do not put that in the browser and do not make it default.