Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

251–260 of 422 posts

Re: Turn off DoH, Firefox

#251
post #199
post #176

Earlier quoted context omitted.

It's actually FUD, because it's missing some important points > For starters, Mozilla said that after it turns on DoH by default for US users, Firefox will contain a mechanism to detect the presence of any local parental control software or enterprise configurations. > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists. > The organization said it…

I hardly see how the OP is FUD. What the article states is true; just because you can opt-out doesn't mean it's wrong. Where you are drawing the line is the opt-out to disable it, as opposed to the convention of opt-in. Think about companies in the 50-200 employee range; As a sysadmin, I have to purposefully go out of my way to put that domain (use-application-dns.net)[1] in my root resolver, and point it to NXDOMAIN…

Indeed, Firefox is prioritizing the interests of users over the interests of sysadmins. Personally, I'm fine with that.

> The basic IT mantra has been 'If it aint broke, don't fix it.'

An unencrypted protocol that compromises privacy may not be "broke" for sysadmins, but it is for users.

Re: Turn off DoH, Firefox

#252

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.

And for regular DNS, their ISP/employer/school will be the service provider for 99.9999% of users. Regular DNS is not exactly easy to find (on Windows, it's under Settings -> Network -> Change Adapter Options -> Adapter Name -> IPv4 -> Properties), which is arguably as hard as going to about:config. And there is no menu of providers listed--nor does it explain who would choose the "automatic" DNS server options (the one that uses DHCP).

So the status quo is no better than this, and at least this is encrypted and protected by a privacy guarantee.

Now I agree that ideally a user-visible preference should be created for the DoH resolver, but I don't think that's a blocking issue. Just like the accounts features uses a mozilla server, and chrome uses google accounts, and both use google safe browsing lists, browsers have always made the decision to hardcode various external service providers.

Re: Turn off DoH, Firefox

#253
post #23

This misses the forest for the trees. In the UK ISPs are already legally mandated to log your web requests and provide them to the government. Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications. The fact that cloudflare is a US entity and thus not subject to UK law is the whole point.

> The fact that cloudflare is a US entity and thus not subject to UK law is the whole point. As a fellow citizen of a Five Eyes country, I assume that if any of those 5 have info about me that one of the other four wants it won't even be a question of paperwork for it to be shared.

Then it's a good thing that if you use DNS over HTTPS, none of those countries will have the info, since the connection is encrypted to Cloudflare and they will not be logging queries.

Re: Turn off DoH, Firefox

#254

It's worth noting that CloudFlare has already proven itself to not be a neutral party - they have proven willing to take sites offline for both legal and social pressure reasons. This will greatly impact the internet's ability to route around censorship as if it were damage.

Cloudflare has proven willing to refuse to use their own bandwidth to host particular websites. That's very different from censoring DNS requests, and there's no reason to think they would do the latter.

Re: Turn off DoH, Firefox

#255
post #4
post #2

What they should do is offer several alternatives when enabling DoH (Cloudflare isn't the only DoH provider out there), and anto-detect if your ISP or local network supports it at the enterprise level. At least you can change the provider in about:config. I don't remember if you can do it through the settings page.

Many ISPs won't offer such thing https://www.zdnet.com/article/uk-isp-group-names-mozilla-int...

Also certain countries (eg. Australia), have a metadata retention law.

That means that the ISP dns will 100% be logging all requests made.

The risk of Cloudflare doing it is far outweighed by ISPs legally being required to do it, at least in Australia.

Re: Turn off DoH, Firefox

#256

Earlier quoted context omitted.

ISPs have proven themselves untrustworthy repeatedly, CloudFlare yet really hasn't. Not that I like the control they have, but it's honestly the fault of ISP's this has happened.

Cloudflare has taken sites offline before, in response to legal requests (CP) and social pressure (8ch). Whether it’s right to do it or not, Cloudflare has proven that it is not a neutral party.

CloudFlare has stopped hosting particular websites; they haven't censored DNS requests. There's a huge difference between the two.

Re: Turn off DoH, Firefox

#257

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

[deleted]

Re: Turn off DoH, Firefox

#258
post #125

Earlier quoted context omitted.

Corporations concerned about that should be blocking DoH anyway

How can you block it, if the browser itself is doing the communication, over https no-less? DoH was made to stop censorship, which includes blocking; if you could just block it, then whats the point of DoH?

DoH uses regular DNS to get the IP address of the DoH server. So they could just block queries for the most popular DoH servers.

Re: Turn off DoH, Firefox

#259
post #215
post #141

Earlier quoted context omitted.

privacy-wise, plaintext is the worst option possible.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

> I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited.

There's very few countries with such strong privacy protections, even in the Western world.

Re: Turn off DoH, Firefox

#260
post #25
post #8

Firefox, wth. Cloudflare is not the internet.

It's currently proxying 10.2% of all known websites (by the surveyor) on the entire Internet. https://w3techs.com/technologies/details/cn-cloudflare/all/a... Not big, but not insignificant.

[deleted]
Post reply on HN