How do these DoH partnerships work with DNS split views? If folks are running an internal copy of "something.company.com" and it's expected to resolve to RFC3330 space "on the company network" ... that depends on folks computers and devices using the corporate DNS. If Firefox is going to a public DoH endpoint, they'll get the public IPs instead and connect to the wrong copy of the service, or it might not even resolv…
NextDNS Joins Firefox’s Trusted Recursive Resolver
31–40 of 146 posts
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#32I never heard of NextDNS. I am appalled. From their site: https://nextdns.io > See what's happening on your devices with in-depth Analytics and real-time Logs. > Protect your kids and control what they can access online. Their pricing page is also extremely troubling. > We may adjust this later on based on actual costs at scale, but it will follow this logic. What the hell is this Mozilla... This is not a company you…
the monitoring and blocking features are not enabled by default. The pricing model is certainly troubling though.
> We may adjust this later on based on actual costs at scale, but it will follow this logic.
>We will accept credit, debit and prepaid cards, PayPal, cryptocurrencies and other popular payment platforms.
In what sense is it troubling? I have never looked at a DNS pricing page before today, but this looks reasonable...
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#33I'm a fan of DoH, but I'm also a Chromecast owner, so I get to experience the downsides of application-level DNS resolvers. Chromecasts will ignore the DNS servers set by DHCP, and will cease to function if they cannot communicate with Google's DNS servers[1]. That means my network-enforced DNS preferences that block ad and malware sources are ignored, and I see more ads than I want to. It also means that when Google…
I have a Chromecast. I also redirect all port 53 traffic (DNS) back through my own DNS server at the firewall level (does not go to Google DNS). It works perfectly fine wihtout directly using Google DNS.
Yes, they do ignore the DNS set by DHCP, but that can be worked around.
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#34Earlier quoted context omitted.
Further, any mention of homosexuality is often considered to be inherently and unmistakably morally obscene, such as by the One Million Moms group, or as described by various state GOP platforms. This would include the narratives on whether lesbian or gay parents exist.
One of the positives of DNS-level blocking is that it's relatively rough-grained. You can block pornhub.com, but you can't block out every mention of homosexuality at the DNS level without blocking any site that may potentially mention it, which would include any news site, discussion forum, social media, etc. We should be skeptical of aggresively-enforced DoH. In most cases, the vendor's interest in stopping ad bloc…
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#35“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…
Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#36I'm not sure how I feel about Firefox's strategy for DoH. On the one hand, moving DNS out of the hands of ISPs that (at least in the US) have no real incentive to respect user privacy is probably a good thing. On the other hand, circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental co…
This is configurable via group policy.
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#37I'm a fan of DoH, but I'm also a Chromecast owner, so I get to experience the downsides of application-level DNS resolvers. Chromecasts will ignore the DNS servers set by DHCP, and will cease to function if they cannot communicate with Google's DNS servers[1]. That means my network-enforced DNS preferences that block ad and malware sources are ignored, and I see more ads than I want to. It also means that when Google…
I believe you are referencing possibly old data. I have a Chromecast. I also redirect all port 53 traffic (DNS) back through my own DNS server at the firewall level (does not go to Google DNS). It works perfectly fine wihtout directly using Google DNS. Yes, they do ignore the DNS set by DHCP, but that can be worked around.
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#38I'm a fan of DoH, but I'm also a Chromecast owner, so I get to experience the downsides of application-level DNS resolvers. Chromecasts will ignore the DNS servers set by DHCP, and will cease to function if they cannot communicate with Google's DNS servers[1]. That means my network-enforced DNS preferences that block ad and malware sources are ignored, and I see more ads than I want to. It also means that when Google…
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#39Earlier quoted context omitted.
I believe you are referencing possibly old data. I have a Chromecast. I also redirect all port 53 traffic (DNS) back through my own DNS server at the firewall level (does not go to Google DNS). It works perfectly fine wihtout directly using Google DNS. Yes, they do ignore the DNS set by DHCP, but that can be worked around.
AFAIKT, you can block Google DNS and all your Google Cast devices should fallback to DHCP assigned DNS.
Re: NextDNS Joins Firefox’s Trusted Recursive Resolver
#40Earlier quoted context omitted.
"Protecting your kids" is often "we log everything and have complete visibility over how people are using our service, and we're willing to share a bit of that with parents to spy on their children". It's a valid concern to have unless there's evidence to the contrary.
I assume every single DNS provider is logging and, if possible, selling my data. Why wouldn't I? This is actually why I use my own DNS server and resolve against the root, like anyone else who cares about privacy ought to be doing. Still, if your goal is to block your kids' access to things, DNS is a good place to do it. Works across all your devices and doesn't require any install.