Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

291–300 of 422 posts

Re: Turn off DoH, Firefox

#291

Earlier quoted context omitted.

So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).

Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.

> Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.

DNS over TLS has other issues. There's a nice comparison there https://dnscrypt.info/faq/ I have been using local resolver on 53, that forwards all requests from my LAN into DNSCrypt (and sends that over a VPN tunnel). That way I maintain privacy, and decentralization as well as being able to simply use the DNS resolver built into my OS.

I have to wonder though with HTTP/3 https://en.wikipedia.org/wiki/HTTP/3 being QUIC based, will we see DNS over QUIC? https://en.wikipedia.org/wiki/QUIC

Seems like Firefox doesn't even support QUIC at the moment. https://bugzilla.mozilla.org/show_bug.cgi?id=1158011

Re: Turn off DoH, Firefox

#292
post #216

Earlier quoted context omitted.

Any device at home an go to http://nas and get on my nas, " http://desktop" , " http://router" , and " http://shed" and get on those. How does that work in this bold new future? I'll have to register a domain name and add a bunch of A records for 192.168.0.1, but then it still won't work -- I'll have to do " http://desktop.mydomain.com" . Worse, while going to "shed" will work in chrome, it will fail in firefox. My g…

Firefox claims they will detect this situation and disable DoH.

Detect it, how? By forwarding the request to a local resolver after DoH fails, and thus leaking information?

Re: Turn off DoH, Firefox

#293
post #291

Earlier quoted context omitted.

Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.

> Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS. DNS over TLS has other issues. There's a nice comparison there https://dnscrypt.info/faq/ I have been using local resolver on 53, that forwards all requests from my LAN into DNSCrypt (and sends that over a VPN tunnel). That way I maintain privacy, and decentralization as well as being able to simply use the DNS resolver built int…

The IETF QUIC isn't finished. Periodically the Working Group thinks it has stopped fiddling with the low-level bit layout and is ready to focus on polish, then somebody finds a show stopper that means revisiting the low-level bits. Maybe 2020? They missed all their advisory target dates (July 2019) for actually writing documents, and that isn't the end by any means for a protocol like this.

So Firefox could at most support either Google QUIC (internal prototype, now obsolete, who cares?) or a random draft that may end up not resembling the final product. If they haven't decided to do either it doesn't seem like a big deal.

Re: Turn off DoH, Firefox

#294
post #219

Earlier quoted context omitted.

Couldn’t your isp watch traffic to pull out SNI information?

the next step is eSNI and judging by the DoH rollout that will also be a new level of controversy advocating against it

What are the arguments against eSNI?

Re: Turn off DoH, Firefox

#295

Earlier quoted context omitted.

It's in Options/Preferences > Network Settings > Settings, scroll to the bottom and select Custom from the Use Provider dropdown. I added AdGuard's DNS over HTTPS address. https://dns.adguard.com/dns-query

Haha. Okay: Actually didn't see it because that one line landed below the fold on my resolution (960px height, fixed taskbar on Windows). Rookie mistake. But also bad UI design if this is actually something that's important and that users should pay attention to. But. (1) There is no informed consent happening here, highlighting to a user, say in Europe, that this would lead to a U.S.-regulated entity knowing a lot a…

The dropdown in (2) doesn't have any other options because of the thing you're worried about in (1). Mozilla seeks specifically to contract with DoH operators to secure the operator's consent to protect their users and never do most of the things you're worried they might do.

They do NOT want the list to go:

Cloudflare

Sketchy Valley Company with six months runway and no clear plan how to make a profit

The Actual Mob, really

Google

Great Britain's Ministry of Truth

Russian Media Company owned by Vladimir Putin

And then have news sites going "Why are all these obviously untrustworthy folks listed?" when the answer would be "Oh we heard that people didn't like the short list of actually trustworthy providers so we added all the other ones that we don't trust too!"

Re: Turn off DoH, Firefox

#296

Earlier quoted context omitted.

DoH is vital to protect users around the world from censorship and worse. Like I've asked before, should Mozilla also start including an obfuscating VPN by default, to bypass the Chinese firewall? This is a political issue, and one that I don't think Mozilla should even get involved in because it could have very ugly consequences --- just focus on making a good browser and leave the politics (and VPN/firewall-busters…

Mozilla is working to add a tor mode or add on.

I dont think they are in a position to be trustworthy enough to offer that. Not after the fiasco with their expired addon certificate sabotaging Tor. I still dont see how the standard practice in Firefox to just silently disable addons is anything but malice.

Re: Turn off DoH, Firefox

#297
post #291

Earlier quoted context omitted.

> Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS. DNS over TLS has other issues. There's a nice comparison there https://dnscrypt.info/faq/ I have been using local resolver on 53, that forwards all requests from my LAN into DNSCrypt (and sends that over a VPN tunnel). That way I maintain privacy, and decentralization as well as being able to simply use the DNS resolver built int…

The IETF QUIC isn't finished. Periodically the Working Group thinks it has stopped fiddling with the low-level bit layout and is ready to focus on polish, then somebody finds a show stopper that means revisiting the low-level bits. Maybe 2020? They missed all their advisory target dates (July 2019) for actually writing documents, and that isn't the end by any means for a protocol like this. So Firefox could at most s…

> The IETF QUIC isn't finished. Periodically the Working Group thinks it has stopped fiddling with the low-level bit layout and is ready to focus on polish, then somebody finds a show stopper that means revisiting the low-level bits. Maybe 2020?

Ah yes you're right. Also Mozilla (M. Thomson, Ed) is on the author list there so I expect they will support it when it is finalized.

https://datatracker.ietf.org/doc/draft-ietf-quic-transport/

Hopefully then they also support DNS over QUIC, I expect they probably will once QUIC is finalized. I think DoH is just a stop-gap measure to be honest.

https://datatracker.ietf.org/doc/draft-huitema-quic-dnsoquic...

Re: Turn off DoH, Firefox

#298

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Your post is painful to read. Masses of unfounded FUD. > security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany). The author appears to be from Switzerland, and it's not clear at all why "security services" (who?) in Germany "especially" have few restrictions.

Laws restricting what the government and private entities can do with data almost invariably (e.g. the GDPR) just have a blanket exception for security services.

Very long term we might trend away from that, just as eventually countries which had outlawed capital punishment "except in times of war" realised they had no intention of doing it in a war either so many of them began removing that caveat. But today this is the case with every such restriction I've seen, it either says in the law itself that it doesn't apply to security services or there's a superseding law that says the security services needn't obey the data protection rules.

Re: Turn off DoH, Firefox

#299
post #129

Earlier quoted context omitted.

And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?

I'm fairly sure that most, even non-technical users understand fairly well that their ISP can snoop on their internet connection. On the other hand I doubt that my mom expects that when she connects to https://www.impots.gouv.fr/ her browser pings an american-owned server to get access.

Tracetouting that address could reveal a lot more foreign-owned (and built) servers in the path, so I’m not sure what your litmus test is.

Re: Turn off DoH, Firefox

#300
post #215
post #141

Earlier quoted context omitted.

privacy-wise, plaintext is the worst option possible.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

That's a very good point.

I'm not familiar with DoH. Would it allow CloudFlare to match domain names to IP addresses still? If so, then I don't see how it adds any value to the current solution. If anything, it creates a false sense of security which is worse than no security at all.

What's the point of encrypting the DNS lookup step if a middleman can still potentially see everything in plaintext?

Post reply on HN