Live data from Hacker News

Firefox’s Trusted Recursive Resolver DNS feature is dangerous

blog.ungleich.ch

281–290 of 306 posts

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#281

Earlier quoted context omitted.

> - you can provide your own server How do I RUN my own server? A few minutes of Googling hasn't revealed any DNS-over-HTTPS server that appears production-ready.

You don't need DoH for that. Just use a VPN and configure it to replace your host's resolver as long as it is up. Another advantage of using standard UDP-based DNS over a UDP-based VPN is that it can reorder packets in flight, so it should have lower latency than anything TCP-based.

The counterpoint is that traditional DNS has horrendous loss recovery and basically no congestion control and these things definitely benefit DoH at the tail.

QUIC will let us have it both ways (and as QUIC has an HTTP definition, its basically a free upgrade for DoH).

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#282

Earlier quoted context omitted.

that's great, but are you coming for the ip addresses too (probably the bigger challenge)?

Yes, we are. After ESNI we’re working on DNS IP address randomization.

is that a joke? sorry I don't see how that would help... where could I get more info?

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#285
post #227

Earlier quoted context omitted.

The first sentence of the article is about TRR/DOH being turned on by default in the next patch.

Yes, that's the big issue. Plus, changing to a different resolver is not very simple and most users won't even know.

It would be a big issue, if it was true.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#286
post #22

The article lacks instructions about disabling it or using some other DOH resolvers. about:config -> search for network.trr -> set network.trr.mode = 5 to completely disable it (I do not recommend this) The curl wiki has a list of DOH servers: https://github.com/curl/curl/wiki/DNS-over-HTTPS It should also point to "the other side of the story", the benefits of DOH over classic DNS resolving, for example https://hack…

Considering the default is off, anyone that goes out of their way to turn this on should remember how to turn it back off.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#287
post #34

Earlier quoted context omitted.

That one actually breaks in the new release :-/

Wow. Firefox, out of the box, is going to be perfectly useless to me. At home, I have an internal DNS resolver which is used for internal stuff (e.g., Home Assistant, a friendly name for my NAS, etc). This will be broken. Likewise, I've got Pi-Hole set up for my girlfriend, but that's going to stop working as soon as her Firefox updates itself to this version. At work, we have an internal DNS resolver for obvious rea…

This isn’t enabled by default on any versions of Firefox and Mozilla does not have a timeline for enabling this by default on any future versions of Firefox.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#288
post #250

Earlier quoted context omitted.

But if they violate their promise to Mozilla, won't they be liable? And won't Mozilla have standing to sue? What do you think damages would be if you violate a contract with Mozilla that puts millions of users at risk? (I wouldn't want to test that) And won't they get caught during audits? Or at least risk it.

I don't really care about "promises" and contracts made between faceless corporations. I have no reason to trust Cloudflare or modern Mozilla, neither have I a reason to believe Mozilla would litigate against a breach of contract publicly instead of settling privately and secretly to prevent public outrage.

You trust Mozilla code, why not trust them to negotiate on your behalf?

Do you think you'll be able to negotiate a better solution on your own... If so, just change the defaults.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#289

Earlier quoted context omitted.

VHVya2V5IGhhcyBsZWdhbGlzZWQgY2Vuc29yc2hpcCBvZiBhbGwgcmFkaW8sIFRWIGFuZCBJbnRl cm5ldCBhcyBhbiAiYWRtaW5pc3RyYXRpdmUgbWVhc3VyZSIgaW4gbWlkIDIwMTcgKGxhd2xpa2Ug ZGVjcmVlIDY5MCkuIEFsbCByYWRpbyBhbmQgVFYgdHJhbnNtaXR0ZXJzIChldmVuIG9uZXMgdHJh bnNtaXR0aW5nIHByaXZhdGUgY2hhbm5lbHMpIGFyZSBvd25lZCBieSBhIGdvdmVybm1lbnQtbWFq b3JpdHkgY29tcGFueSBhbmQgYWxsIG5vbi1MQU4gbmV0d29yayB0cmFmZmljIGdvZXMgdGhyb3Vn aCBjZW50cmFsIGdhdGV3YXlzLiBFcmRvxJ9…

If they can MitM you to see your post, base64 will just draw more attention. Consider checking SSL fingerprints from trusted and untrusted locations instead. openssl s_client -servername news.ycombinator.com -connect news.ycombinator.com:443 /dev/null | openssl x509 -fingerprint -noout -in /dev/stdin SHA1 Fingerprint=BB:DD:64:6F:EB:11:0C:D5:EC:CF:57:D1:F7:52:AA:99:50:1B:44:FD I would also suggest browser addons that…

  SHA1 Fingerprint=BB:DD:64:6F:EB:11:0C:D5:EC:CF:57:D1:F7:52:AA:99:50:1B:44:FD
HN is not replaced by MiTM in Turkey.

They cannot read HTTPS unless it is using TÜBİTAK certificate (all .gov.tr and some other .tr domains use this). There are more layers of censorship till central gateway, which is inferior to, but structurally more robust than GFWoC.

Re: Firefox’s Trusted Recursive Resolver DNS feature is dangerous

#290

Earlier quoted context omitted.

Indeed, all us US taxpayers and, more importantly, citizens are complicity with the myriad heinous crimes of our government. They do them in our name, with our money, and in most cases with our vote.

OK, but I hope that you don't propose vilanizing any support helping US taxpayers because of it, as it was the purpose of the analogy to explore that. Are hospitals evil for providing healtcare to US citizens who are enabling NSA?

No, that's absurd.
Post reply on HN