Earlier quoted context omitted.
No, the other viable option is not enabling DoH by default.
And that should surely be the default. What's Mozilla's intent to send DNS queries to Cloudflare by default , and require regular DNS resolution to be configured manually?
Turn off DoH, Firefox
271–280 of 422 posts
Re: Turn off DoH, Firefox
#272Earlier quoted context omitted.
> The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https. You can disable dns-over-https if you don't want it enabled. Just go…
Thanks. I feel this should just be a setting on the settings screen. I use a PiHole DNS service at home which I want to keep using over this.
Re: Turn off DoH, Firefox
#273As somebody who's been working for internet security over 20 years, we strongly believe that applications should not choose the DNS server. The operating system is designed to manage DNS and network settings for all applications. This is nonsense.
Instead of a reactionary remark please provide arguments and explanations for your viewpoint to actually further the discussion.
Re: Turn off DoH, Firefox
#274The main point I am making is just as we want to be free in choosing whether or not to use DoH over CF, Mozilla is as free to design their own product.
Re: Turn off DoH, Firefox
#275Earlier quoted context omitted.
No I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).
With TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).
Re: Turn off DoH, Firefox
#276People say that it's trivial to change. It's trivial to change for us who are technically minded. It's far from obvious and will not be changed by non-technical users.
This will only increase the massive amount of data that Cloudflare gets about people's online behavior. I am always very skeptical of centralization and of having a company get this much information. Remember google's Don't be evil? I'm extremely uncomfortable with such a massive centralization of data.
People might say that the status co is not great because DNS is sent to the ISP. I'd argue the status co is better because it's far less centralized. And, at least for Europeans, I trust European legislation better than US legislations.
I can understand the argument that some countries have mass surveillance and it's a net positive for users in those countries since it will protect them. But in that case, I feel that the default should be randomized from a list of provider, not only one company. I also would be much less concerned by this if it was an option on first startup with a clear explanation (even though users tend to not read and blindly click accept, it's at least more of an informed consent)
And anyway, that purpose of preventing mass surveillance and blocking in those countries where it would actually be useful seems to be moot because of: > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists.
> The organization said it's been asking ISPs and providers of network-based parental control solutions to add a "canary domain" to their blocklists. When Firefox will detect that this canary domain is blocked, it will disable DoH to prevent the feature to be used as a filter-bypassing solution.
So, if isp in countries with censorship can use a canary website to prevent users from bypassing "legally-set blocklists". What is the point again of enabling this?
Re: Turn off DoH, Firefox
#277This is a gross over-simplification. Cloudflare is required by contract to respect your privacy, which is much stronger than even the privacy laws have here in the EU since it addresses everyone, not just the EU population: https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... The people fighting for the status quo probably know how to run their own resolver, even with DoH or DTLS. But Mozilla's conundrum i…
How often to corporations take other corporations to court over contract disputes? I think it's pretty often.
Re: Turn off DoH, Firefox
#278This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
Don't oversimplify the issue. > it's trivial to change your DoH provider Cloudfare is the default. Cloudfare is the only provider listed. Cloudfare will be On by default, so it will be that for 99.999% of Firefox users. That ain't right no matter how well intended it is.
Re: Turn off DoH, Firefox
#279Re: Turn off DoH, Firefox
#280Earlier quoted context omitted.
> You can disable dns-over-https if you don't want it enabled. It was also possible to disable Ubuntu from sending your desktop searches to online retailers: * https://www.pcworld.com/article/2889895/how-to-stop-ubuntu-f... Just because something can be disabled does not necessarily mean it should be enabled by default in the first place.
That's a really strange comparison. You know that mozilla has an agreement with cloudflare under which cloudflare has agreed not to log dns queries right?