Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

281–290 of 422 posts

Re: Turn off DoH, Firefox

#281
post #255

Earlier quoted context omitted.

Also certain countries (eg. Australia), have a metadata retention law. That means that the ISP dns will 100% be logging all requests made. The risk of Cloudflare doing it is far outweighed by ISPs legally being required to do it, at least in Australia.

What if the user just doesn't make any DNS queries, because all their host lookups are going over DoH? They can log all the user's DNS queries, but all of them will just be for the DoH server whenever the user starts Firefox.

I assume DoH will not be logged at all. Or just many connections logged to "one.one.one.one".

Difference being if I connected to ISP ABC's DoH server - communication between will be encrypted, but the actual requests will be logged after they receive the request.

Re: Turn off DoH, Firefox

#282
post #158
post #98

Earlier quoted context omitted.

It will actually not be used anymore, because firefox avoids your local DoH setup.

> For starters, Mozilla said that after it turns on DoH by default for US users, Firefox will contain a mechanism to detect the presence of any local parental control software or enterprise configurations. > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists. > The organization said it's been asking ISPs and providers of network-based parental co…

Doesn't this completely defeat the whole thing?

Anyone upstream that wants to start censoring or logging can just add this canary domain and continue business as usual.

Re: Turn off DoH, Firefox

#283
post #82

Earlier quoted context omitted.

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

It's worse, because the local ISP is more trustworthy and additionally you enable cloudflare for large scale profiling. And don't claim they won't do it, it's just a matter of time

I live in Sweden and I would never trust any ISP. There are too many cases of data shared with "business partners" that led to things like tries to extort torrent users or porn surfers (even reputable ISPs).

This should be, if not illegal at least highly problematic in the eyes of the law. At best the ISPs got a "better behave, because next time ...".

All ISPs have data sharing with "selected partners to ensure service quality" which, at least until GDPR, meant basically that they could sell data.

Whereas cloudflare states that the 1.1.1.1 data will only ever be shared with APNIC in anonymised form (which they define). Cloudflare defines what data they share for 1.1.1.1 users, which my ISP does not. I trust cloudflare, at least right now. If they were to change their retention policies and agreement I would maybe reconsider.

Re: Turn off DoH, Firefox

#284

I don't know about you guys but in Turkey if you query wikipedia.org from 8.8.8.8 it doesn't return results. However if you use DoH you can access Wikipedia. Thank you whoever contributed to DoH!

Whatever convinced Google – Google – to censor Turkey, you don’t think they will be able to convince Cloudflare to do the same?

This is a problem of centralization.

Re: Turn off DoH, Firefox

#285
In places like India, blocking is often done at the DNS level. Cloudflare and Firefox are big reasons I can get around stupid overbroad government blocking of whatever they think is anti-national or porn.

Re: Turn off DoH, Firefox

#286
post #82

Earlier quoted context omitted.

It's worse, because the local ISP is more trustworthy and additionally you enable cloudflare for large scale profiling. And don't claim they won't do it, it's just a matter of time

I scoff at the idea that Comcast is more trustworthy than Cloudflare.

Telia in Sweden has shared data with "selected partners" in a way that led to customers being extorted because of, among other things, porn surfing history and torrent downloading.

Trusting your ISP, even in a country with data protection laws like Sweden, is naive. I'd much rather trust a company that tells me "this is the data we store. This is the data we share with APNIC and no-one else".

Re: Turn off DoH, Firefox

#288
The result will be simple: FF market share in corporate environments will drop. If sysadmins have to jump through hoops simply to get the thing to respect corporate DNS settings, then it won't be used.

Re: Turn off DoH, Firefox

#289

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

DoH is vital to protect users around the world from censorship and worse. Like I've asked before, should Mozilla also start including an obfuscating VPN by default, to bypass the Chinese firewall? This is a political issue, and one that I don't think Mozilla should even get involved in because it could have very ugly consequences --- just focus on making a good browser and leave the politics (and VPN/firewall-busters…

Mozilla is working to add a tor mode or add on.
Post reply on HN