Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

261–270 of 422 posts

Re: Turn off DoH, Firefox

#261
post #255
post #4

Earlier quoted context omitted.

Many ISPs won't offer such thing https://www.zdnet.com/article/uk-isp-group-names-mozilla-int...

Also certain countries (eg. Australia), have a metadata retention law. That means that the ISP dns will 100% be logging all requests made. The risk of Cloudflare doing it is far outweighed by ISPs legally being required to do it, at least in Australia.

What if the user just doesn't make any DNS queries, because all their host lookups are going over DoH? They can log all the user's DNS queries, but all of them will just be for the DoH server whenever the user starts Firefox.

Re: Turn off DoH, Firefox

#262
As somebody who's been working for internet security over 20 years, we strongly believe that applications should not choose the DNS server. The operating system is designed to manage DNS and network settings for all applications.

This is nonsense.

Re: Turn off DoH, Firefox

#263
post #64

Earlier quoted context omitted.

> claimed that Mozilla plans to support DNS-over-HTTPS "in such a way as to bypass UK filtering obligations and parental controls, undermining internet safety standards in the UK." > By planning to support DNS-over-HTTPS, Mozilla is throwing a monkey wrench in many ISPs' ability to sniff on customers' traffic and filter traffic for government-mandated "bad sites." But I don't see why they can't offer their DoH, it se…

because most people don't know they can easily bypass the DNS based filters that is used to block "bad sites". DoH by default uses cloudflare's DNS, and so won't (need to) comply with the UK's filter laws.

> DoH by default uses cloudflare's DNS, and so won't (need to) comply with the UK's filter laws.

I'm assuming the DoH servers used by British users are physically in the UK. (I believe they anycast the service from all of their edge locations, and they have several in the UK.)

So the fact that Cloudflare doesn't have to comply with this law is precarious. Is it because only ISPs are required to comply? If so, it seems like a matter of time before Parliament amends the law to require any public DNS operator to implement the filters as well.

Re: Turn off DoH, Firefox

#264
post #123

Earlier quoted context omitted.

Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.

The other viable doh provider is google. Other’s timeout is simply not worth the request, in my experience. How does one choose from these two?

Even Quad9[1] or NextDNS[2]? Quad9 works well for me.

[1]: https://quad9.net/doh-quad9-dns-servers/ [2]: https://nextdns.io/

Re: Turn off DoH, Firefox

#265
post #139
post #123

Earlier quoted context omitted.

The other viable doh provider is google. Other’s timeout is simply not worth the request, in my experience. How does one choose from these two?

No, the other viable option is not enabling DoH by default.

And that should surely be the default. What's Mozilla's intent to send DNS queries to Cloudflare by default, and require regular DNS resolution to be configured manually?

Re: Turn off DoH, Firefox

#266

Earlier quoted context omitted.

So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).

Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.

That would break the internet for many innocent souls behind firewalls.

Re: Turn off DoH, Firefox

#267
post #144

Earlier quoted context omitted.

I can think of something worse: sending all your DNS queries to an unregulated third party.

ISP and government are that "unregulated third party".

ISPs are highly regulated, as opposed to Cloudflare and Google. The only effect here is that Google closes another "loophole" in their view where web visit signals are send to another party (other than Google), and Cloudflare wanting their share of the cake as well. Has Mozilla disclosed what Cloudflare is paying them for being listed as default DoH provider?

Re: Turn off DoH, Firefox

#268

Earlier quoted context omitted.

So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).

Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.

While that's an unpopular opinion I tend to agree, I'm still on the fence if that's really bad or if I'm just grumpy about change though. It really feels like instead of fixing the underlying problems we're duct taping the internet by moving HTTPS to OSI layer 4 and making TCP and the concept of ports obsolete for a majority of use cases - which in many cases implies a loss of control. I'm honestly not sure why our sector pushes HTTPS solutions over plain TLS, is it just because it blends in with web traffic and it's easier to grasp because more people are familiar with the basic concepts?

Of course there's arguments for and against these aspects in the case of name resolution, both technical and on a legislative level, but maybe a net win in terms of privacy protection for the majority of users is still worth it. And should Cloudflare or whoever decide to misbehave with the data we send, it'll at least be easy to switch to other providers when DoH is widely adopted.

Re: Turn off DoH, Firefox

#269

As somebody who's been working for internet security over 20 years, we strongly believe that applications should not choose the DNS server. The operating system is designed to manage DNS and network settings for all applications. This is nonsense.

Instead of a reactionary remark please provide arguments and explanations for your viewpoint to actually further the discussion.

Re: Turn off DoH, Firefox

#270

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Your post is painful to read. Masses of unfounded FUD.

> security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany).

The author appears to be from Switzerland, and it's not clear at all why "security services" (who?) in Germany "especially" have few restrictions.

Post reply on HN