Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

271–280 of 422 posts

Re: Turn off DoH, Firefox

#271
post #139

Earlier quoted context omitted.

No, the other viable option is not enabling DoH by default.

And that should surely be the default. What's Mozilla's intent to send DNS queries to Cloudflare by default , and require regular DNS resolution to be configured manually?

Yes, that's exactly their plan at the moment. Hence the whole brouhaha.

Re: Turn off DoH, Firefox

#272
post #142

Earlier quoted context omitted.

> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https. You can disable dns-over-https if you don't want it enabled. Just go…

Thanks. I feel this should just be a setting on the settings screen. I use a PiHole DNS service at home which I want to keep using over this.

It should be a setting in a standard dot file. I don't understand why Mozilla can't create a simple configuration file like most applications.

Re: Turn off DoH, Firefox

#273
post #269

As somebody who's been working for internet security over 20 years, we strongly believe that applications should not choose the DNS server. The operating system is designed to manage DNS and network settings for all applications. This is nonsense.

Instead of a reactionary remark please provide arguments and explanations for your viewpoint to actually further the discussion.

I think tptacek's comment is just fine as it is.

Re: Turn off DoH, Firefox

#274
Idk folks, the entire debate seems to be out of proportion. 1) If you do not agree with Mozilla’s actions - do not user their browser. I mean Mozilla isn’t forcing anyone to use Firefox. As a company they are free to design their product as they see fit. As an individual you are free to either use their product or not. 2) If you disagree and still chose to use Firefox - just because you are reading this means you have the knowledge to disable DoH. 3) If Mozilla remove the option to disable DoH over CF and you don’t like it - use another browser. 4) If you are concerned for other people’s data going to CF (specifically people who are not as well informed, people who don’t know what DoH or even DNS is) - very noble indeed, but unfortunately options are limited here. Encourage people to do some research and to decide for themselves whether or not they are as passionate about it.

The main point I am making is just as we want to be free in choosing whether or not to use DoH over CF, Mozilla is as free to design their own product.

Re: Turn off DoH, Firefox

#275

Earlier quoted context omitted.

No I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).

With TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).

Hence your request goes to yet another party: your ISP (by necessity via IP destination in your IP headers), the site you want to go to, and to Cloudflare/Google as DNS provider and as fourth party. Whereas with regular DNS, your ISP's nameserver gets DNS queries, hence only three parties are involved. Eg what ndidi, apexalpha said.

Re: Turn off DoH, Firefox

#276
As someone who has donated to Mozilla over the years and used Firefox as much as possible, this makes me very unlikely to donate in the future.

People say that it's trivial to change. It's trivial to change for us who are technically minded. It's far from obvious and will not be changed by non-technical users.

This will only increase the massive amount of data that Cloudflare gets about people's online behavior. I am always very skeptical of centralization and of having a company get this much information. Remember google's Don't be evil? I'm extremely uncomfortable with such a massive centralization of data.

People might say that the status co is not great because DNS is sent to the ISP. I'd argue the status co is better because it's far less centralized. And, at least for Europeans, I trust European legislation better than US legislations.

I can understand the argument that some countries have mass surveillance and it's a net positive for users in those countries since it will protect them. But in that case, I feel that the default should be randomized from a list of provider, not only one company. I also would be much less concerned by this if it was an option on first startup with a clear explanation (even though users tend to not read and blindly click accept, it's at least more of an informed consent)

And anyway, that purpose of preventing mass surveillance and blocking in those countries where it would actually be useful seems to be moot because of: > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists.

> The organization said it's been asking ISPs and providers of network-based parental control solutions to add a "canary domain" to their blocklists. When Firefox will detect that this canary domain is blocked, it will disable DoH to prevent the feature to be used as a filter-bypassing solution.

So, if isp in countries with censorship can use a canary website to prevent users from bypassing "legally-set blocklists". What is the point again of enabling this?

Re: Turn off DoH, Firefox

#277
post #156

This is a gross over-simplification. Cloudflare is required by contract to respect your privacy, which is much stronger than even the privacy laws have here in the EU since it addresses everyone, not just the EU population: https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... The people fighting for the status quo probably know how to run their own resolver, even with DoH or DTLS. But Mozilla's conundrum i…

> "This is a gross over-simplification. Cloudflare is required by contract to respect your privacy"

How often to corporations take other corporations to court over contract disputes? I think it's pretty often.

Re: Turn off DoH, Firefox

#278

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.

I'm on Firefox 69, it's disabled, I never touched it.

Re: Turn off DoH, Firefox

#280

Earlier quoted context omitted.

> You can disable dns-over-https if you don't want it enabled. It was also possible to disable Ubuntu from sending your desktop searches to online retailers: * https://www.pcworld.com/article/2889895/how-to-stop-ubuntu-f... Just because something can be disabled does not necessarily mean it should be enabled by default in the first place.

That's a really strange comparison. You know that mozilla has an agreement with cloudflare under which cloudflare has agreed not to log dns queries right?

Maybe Mozilla has such an agreement, but I don't. I have a contract with my ISP, and thr GDPR applies to that contract. CF? Not so much.
Post reply on HN