Live data from Hacker News

DNS-over-HTTPS Policy Requirements for Resolvers

blog.mozilla.org

251–260 of 301 posts

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#251
post #151

Earlier quoted context omitted.

It's not a nefarious plan to stop me from doing what I want in a FOSS browser on a PC where I can compile and run what I want. It will be used that way, however, on locked-down devices users pay for but don't actually own.

Then don't buy such a device which clearly doesn't meet your needs. Why should every personal computing device on the planet be tailored to your requirements, at the cost of safety for the majority of other users? Most people don't use PiHole, they use Adblock or uBlock which are not affected by this. It's not as though they are taking away your ability to use adblocking technology.

Then Mozilla should make a crippled "safe" version of their browser that has a hard coded list of trusted servers then.

Because by making this the default, they are helping centralize the internet and greatly benefiting the entrenched powers while putting barriers to entry for the rest of us.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#252

Earlier quoted context omitted.

Macro-level view: The Mozilla Foundation may think that DNS-over-HTTPS is about "safety", but they're unwittingly furthering the agenda of those who would profit from the Internet not being decentralized. A decentralized Internet filled with devices that end users can control, should they choose, is a good thing for society, I'd argue. DNS-over-HTTPS is another piece of technology that can be used to eliminate that.…

This is what Mozilla has been doing for a while. They enable advertisers and bad actors to profile you without any sane safeguards to prevent websites from running JavaScript code that is used in a nefarious way. If they were actually focused on protecting users, they would be working with IPFS and building other tools to help hide user identities through a permission-based system. Chrome is just as guilty, but it's…

Don't know why you are getting downvoted when you are completely correct.

There's so much that Mozilla could do structurally, but they are terrified of rocking the boat or disrupting their corporate underwriters.

Just like earlier today, with their anti malicious javascript features[1]; they could look into empowering the users and changing the structure of how js is run in the browser. But that might threaten advertisers, so instead they opted for a clumsly blacklisting solution instead.

If you want an accurate heuristic for predicting Mozilla's behavior, just ask "What would Google want?". It may not be Google in particular that these decisions benefit, but they absolutely benefit those entities that are locking down and siloing the internet.

[1]: https://news.ycombinator.com/item?id=19614808

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#253

I replied sub-thread, but adding here to give some more visibility to some of the issues DoH is causing and will cause: I work at a k12 school and I am involved on many k12 IT communities. Some schools already removed Firefox from the students computers because it was being used as a "VPN" by some elementary students to access porn - at school. Guess what this VPN was? Just DNS over HTTPS. There is a fine line betwee…

So, it is bad that Firefox was removed? Are you saying that you think that Firefox needs to be crippled enough that school districts feel comfortable using it?

The fact that it is enabling students (or anyone) to bypass restrictions is a good thing.

Why don't you try looking at this from another point of view. Firefox is a powerful important tool, and I want it to continue to be so, even if it is not ideal for everyone.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#254

I replied sub-thread, but adding here to give some more visibility to some of the issues DoH is causing and will cause: I work at a k12 school and I am involved on many k12 IT communities. Some schools already removed Firefox from the students computers because it was being used as a "VPN" by some elementary students to access porn - at school. Guess what this VPN was? Just DNS over HTTPS. There is a fine line betwee…

Curious, how does your school solve this with students' phones? Have y'all considered requiring mandatory monitoring apps? Or cell phone data jammers and requiring them use y'all's wifi and require a CA cert install?

If it becomes a problem, they'll just ban them again. Students got by just fine twenty years ago, when phones were confiscated on sight.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#255
post #14

Earlier quoted context omitted.

(full disclosure: I'm affiliated to Cloudflare, but opinions here are my own of course) Thanks for posting this. I knew Paul is against DoH, but never understood his specific arguments. He has great comment about DoT (dns over TLS) couple of minutes before the linked youtube (I agree with him on that). Personally I'm not an "owner" of the networks I'm connecting to. My home router is managed by my ISP, I don't run pi…

> Personally I'm not an "owner" of the networks I'm connecting to. But I am the owner of my own network, and DoH reduces my ability to protect it. That is the main (but not only) reason why I strongly object to DoH. > I think this train has passed. I suspect the battle has just begun. For example, my response to DoH has been to implement a MITM packet inspection system on my network to regain control over this. This…

What exactly are the threats that you expect blocking DoH to protect you from?

If you are MitMing all encrypted traffic anyway, why not block whatever you want to block when someone actually tries to connect to it, rather than trying to prevent them from learning where it is?

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#256
post #153

Earlier quoted context omitted.

So whose device is it anyway? I don't want to use my ISP's lying DNS resolver.

On your router, you can configure whatever you want to use for the DNS. You were able to do that for years. But I want all the devices and apps to use whatever the local network tells them. I don't want to reconfigure the browser every time I connect at home/work/customer place/etc. P.S. My ISP's DNS doesn't lie. Maybe you should vote with your money and choose better.

> On your router, you can configure whatever you want to use for the DNS. You were able to do that for years.

Sure, if you have a router and know how to configure it. The second requirement excludes the vast majority of non-tech-savvy users, even though they are also harmed by lying or data-collecting DNS resolvers and likely would not consent to them if asked. (The first requirement additionally excludes phones and other devices directly connected to a mobile network; of course, you can generally configure the devices themselves to use a different DNS server, but it may be annoying if you have a lot of them. More convenient if devices already default to the option that protects your privacy, i.e. DoH.)

> P.S. My ISP's DNS doesn't lie. Maybe you should vote with your money and choose better.

Even if it doesn’t lie, does it log requests and sell that data? Are you sure?

Anyway, in many locations including most of the US, there’s no meaningful choice available among wireline ISPs.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#258

This has negative implications for security. For instance, one reason why DNS resolvers might block or modify requests is to blacklist domains used for malware operation (botnet C&C domains). Other things like DNS sinkholing and poisoning are also frequently used as tools to disrupt malware communication. In addition, collection and analysis of below-the-recursive DNS traffic is one of the primary ways in which secur…

> This has negative implications for security.

Yeah, Erdoğan won't be able to block oppositions' web sites. That is a very big threat! /s

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#259

What is the justification for an app to resolve domain names differently than the services the operating system provides? I am really curious why this is a thing.

Windows doesn't provide privacy when it comes to DNS queries. It still uses old fashion, plain text DNS. Firefox is trying to protect its users from prying eyes.

Re: DNS-over-HTTPS Policy Requirements for Resolvers

#260
post #10

Earlier quoted context omitted.

DoH has already more adoption than all previous approaches combined. (Note: I don't think DNS-over-QUIC is really any different from DoH. QUIC is just another way of transmitting HTTPS, so you can just do DoH over QUIC.)

> DoH has already more adoption than all previous approaches combined Are you sure? My experience so far has shown that only dnscrypt is widely supported. Nevertheless, surely they must had some kind of issue with the existing solutions when they started working on it. As for DNS over QUIC, I was under the impression that said solution did not make use of HTTP.

Android 9 has build in DoH support.

https://android-developers.googleblog.com/2018/04/dns-over-t...

Post reply on HN