Earlier quoted context omitted.
Many ISPs won't offer such thing https://www.zdnet.com/article/uk-isp-group-names-mozilla-int...
Also certain countries (eg. Australia), have a metadata retention law. That means that the ISP dns will 100% be logging all requests made. The risk of Cloudflare doing it is far outweighed by ISPs legally being required to do it, at least in Australia.
Turn off DoH, Firefox
261–270 of 422 posts
Re: Turn off DoH, Firefox
#262This is nonsense.
Re: Turn off DoH, Firefox
#263Earlier quoted context omitted.
> claimed that Mozilla plans to support DNS-over-HTTPS "in such a way as to bypass UK filtering obligations and parental controls, undermining internet safety standards in the UK." > By planning to support DNS-over-HTTPS, Mozilla is throwing a monkey wrench in many ISPs' ability to sniff on customers' traffic and filter traffic for government-mandated "bad sites." But I don't see why they can't offer their DoH, it se…
because most people don't know they can easily bypass the DNS based filters that is used to block "bad sites". DoH by default uses cloudflare's DNS, and so won't (need to) comply with the UK's filter laws.
I'm assuming the DoH servers used by British users are physically in the UK. (I believe they anycast the service from all of their edge locations, and they have several in the UK.)
So the fact that Cloudflare doesn't have to comply with this law is precarious. Is it because only ISPs are required to comply? If so, it seems like a matter of time before Parliament amends the law to require any public DNS operator to implement the filters as well.
Re: Turn off DoH, Firefox
#264Earlier quoted context omitted.
Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.
The other viable doh provider is google. Other’s timeout is simply not worth the request, in my experience. How does one choose from these two?
[1]: https://quad9.net/doh-quad9-dns-servers/ [2]: https://nextdns.io/
Re: Turn off DoH, Firefox
#265Earlier quoted context omitted.
The other viable doh provider is google. Other’s timeout is simply not worth the request, in my experience. How does one choose from these two?
No, the other viable option is not enabling DoH by default.
Re: Turn off DoH, Firefox
#266Earlier quoted context omitted.
So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).
Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.
Re: Turn off DoH, Firefox
#267Earlier quoted context omitted.
I can think of something worse: sending all your DNS queries to an unregulated third party.
ISP and government are that "unregulated third party".
Re: Turn off DoH, Firefox
#268Earlier quoted context omitted.
So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).
Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.
Of course there's arguments for and against these aspects in the case of name resolution, both technical and on a legislative level, but maybe a net win in terms of privacy protection for the majority of users is still worth it. And should Cloudflare or whoever decide to misbehave with the data we send, it'll at least be easy to switch to other providers when DoH is widely adopted.
Re: Turn off DoH, Firefox
#269As somebody who's been working for internet security over 20 years, we strongly believe that applications should not choose the DNS server. The operating system is designed to manage DNS and network settings for all applications. This is nonsense.
Re: Turn off DoH, Firefox
#270This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
> security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany).
The author appears to be from Switzerland, and it's not clear at all why "security services" (who?) in Germany "especially" have few restrictions.