Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

231–240 of 422 posts

Re: Turn off DoH, Firefox

#231
post #139
post #123

Earlier quoted context omitted.

The other viable doh provider is google. Other’s timeout is simply not worth the request, in my experience. How does one choose from these two?

No, the other viable option is not enabling DoH by default.

I think you mistook it. I was talking about doh providers, not all options, and responded to a line completely tangential, if not unrelated to what you try to bring here. An answer looking for a question, I guess?

Re: Turn off DoH, Firefox

#232
post #173

> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Not in applications! You're right. But so are Mozilla. Here we are 30 years into the web, and we're still using plain old DNS. DNS over TLS should have caught on, but it didn't. Apple and Microsoft had years to ensure it's implemented as standard, but they didn't. The points this…

Agreed, I'd prefer setting up the DNS-over-HTTPS config at the gateway level (and either push the config over DHCP, or have the gateway act as a local resolver, which forwards the new requests over DoH), but we're not there yet.

> have the gateway act as a local resolver, which forwards the new requests over DoH

This is what I would like to see as a default (and included in routers). In fact, it's what I already do myself.

I think (as others here have said) that the privacy concerns the article raises are mostly FUD. But I do agree with the article when it says handling DNS at the application level is kind of a terrible idea (even though it might seem justified in this case). If the end result is that every application has its own built in network stack, that's going to be terrible for security, usability, and make it much harder to debug third-party apps.

Re: Turn off DoH, Firefox

#233
post #215

Earlier quoted context omitted.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

So it depends on the country. In my country (Russia) all Internet traffic is being recorded by the ISP for the last month and sites are blocked on political reasons. For me having DoH with Cloudflare is better.

Ditto in Australia

The reason why browsers are moving to features like DoH and eSNI as defaults is because it's every type of nation that is now instituting pervasive surveillance against its citizens

You also can't trust laws since ISPs can be hacked or infiltrated from the inside

In terms of personal protection encryption trumps law

Re: Turn off DoH, Firefox

#234
post #176
post #78

Earlier quoted context omitted.

Even worse, corporate intranet addresses get leaked. Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.

It's actually FUD, because it's missing some important points > For starters, Mozilla said that after it turns on DoH by default for US users, Firefox will contain a mechanism to detect the presence of any local parental control software or enterprise configurations. > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists. > The organization said it…

> Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists.

Wait, what? Surely making DNS private and non-censorable is the whole point of DoH?

Re: Turn off DoH, Firefox

#235
post #219
post #215

Earlier quoted context omitted.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

Couldn’t your isp watch traffic to pull out SNI information?

the next step is eSNI and judging by the DoH rollout that will also be a new level of controversy advocating against it

Re: Turn off DoH, Firefox

#237

Earlier quoted context omitted.

No I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).

With TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).

With Tor ISP can't even see the final address, but maybe Tor has its own solutions for DNS?

Re: Turn off DoH, Firefox

#238
post #117
post #87

Earlier quoted context omitted.

you too have ignored "it's trivial to change your DoH provider"

The average internet user probably has no idea what DNS or HTTPS are, let alone DoH (which even I as a technical user had forgotten existed before I read this post). Defaults matter a whole lot. I haven't formed a definitive opinion on DoH but either way saying "you can configure it so it doesn't matter" is not reasonable in my opinion.

It's interesting that when Russia started blocking access to some popular websites a few years ago, the instructions for installation of VPN were found in all places. The case - then, for example, attempts to block Telegram servers lead to unexpected unblocking some forbidden sites, like kasparov.ru - shows how some networking skills can be grown en masse in a short period of time.

So, yes, average Internet user isn't very familiar with DNS. Maybe privacy wars will lead to growing awareness in this area though.

Re: Turn off DoH, Firefox

#239
post #120

Earlier quoted context omitted.

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…

I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. I strongly disagree. A browser has one job, and that is to follow and render URLs. Secure connections and such are services provided by other components of the…

What do you do as a browser vendor when the OS fails to provide you meaningful security and privacy? This is pretty much how we got here. Basically every device on the planet is right now configured to blindly accept whatever DNS server is handed to it by DHCP and there is really no movement on changing that.

So browsers can throw up their hands and say "we are as secure as the OS" or they can do it themselves. Not ideal but the alternative is worse for users.

Re: Turn off DoH, Firefox

#240

Earlier quoted context omitted.

No I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).

With TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).

And down the toilet goes the (distributing and caching) Inter-Net. Long live to the new Cloud-Net. Cloudfare and Google are achieving what Compuserve and AOL could not.

Exaggerating slightly ... but not that much really. And all in the good name of privacy and security.

It is also amazing how people (Americans ?) are not willing to admit I want MY jurisdiction to apply. Not an American one. I want the choice.

Post reply on HN