Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

311–320 of 422 posts

Re: Turn off DoH, Firefox

#311
post #9
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

I do trust my ISP and my government more than I trust CloudFlare.

I trust Mozilla and the contract they have with CloudFlare (not just CloudFlare by itself) more than my ISP.

> https://support.mozilla.org/en-US/kb/firefox-dns-over-https

Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk, our partners are contractually bound to adhere to this policy.

These are much stronger guarantees than my ISP's.

Re: Turn off DoH, Firefox

#312
post #276

As someone who has donated to Mozilla over the years and used Firefox as much as possible, this makes me very unlikely to donate in the future. People say that it's trivial to change. It's trivial to change for us who are technically minded. It's far from obvious and will not be changed by non-technical users. This will only increase the massive amount of data that Cloudflare gets about people's online behavior. I am…

> This will only increase the massive amount of data that Cloudflare gets about people's online behavior No, it explicitly won't. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk, our partners are contractually bound to adhere to this policy. https://support.mozilla.org/en-US/k…

[deleted]

Re: Turn off DoH, Firefox

#313

Earlier quoted context omitted.

There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…

> that seems like less privacy. Seems obvious, but is wrong. If there is a really obvious obstacle to anything, which immediately comes to mind, chances are people addressed this already. In the US, Firefox by default directs DoH queries to DNS servers that are operated by CloudFlare, meaning that CloudFlare has the ability to see users' queries. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place t…

Before, my ISP could gather the domains I visit by DNS. Now, they can still gather them from the IP addresses and SNI, and Cloudflare can gather them from DNS. I'm really struggling to see how this isn't a reduction in privacy.

> Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk, our partners are contractually bound to adhere to this policy.

What happens if they get a FISA warrant? How does your contract protect users that before didn't have their DNS queries sent to US companies?

Re: Turn off DoH, Firefox

#314

Does anyone knows why does mozilla think this is a good idea? Between each user sharing dns queries with their isps and everyone sharing dns queries with cloudflare it appears that it's obviously more secure the first approach even if none of them is really that great.

https://support.mozilla.org/en-US/kb/firefox-dns-over-https

> Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk, our partners are contractually bound to adhere to this policy.

So, the "obvious" view seems to be wrong.

Re: Turn off DoH, Firefox

#315
post #120

Earlier quoted context omitted.

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…

I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. I strongly disagree. A browser has one job, and that is to follow and render URLs. Secure connections and such are services provided by other components of the…

> I strongly disagree. A browser has one job, and that is to follow and render URLs.

wow. not only has history rejected your premise, but the many technologies that exist today in a web browser prove you wrong.

Re: Turn off DoH, Firefox

#316
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

> I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! I trust my ISP and government more than a US company I have no formal contract with and the US government. Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Fi…

> I trust my ISP and government more than a US company I have no formal contract with and the US government.

I do not! I'd rather have that anon US co. than any government.

Re: Turn off DoH, Firefox

#317

Earlier quoted context omitted.

Your post is painful to read. Masses of unfounded FUD. > security services, who have very few restrictions on what they are allowed to do with this data. This is especially true in the country the author appears to be based (Germany). The author appears to be from Switzerland, and it's not clear at all why "security services" (who?) in Germany "especially" have few restrictions.

The usual list of security services, BND etc., not sure why adding lists of acronyms is important to you, when "security services" captures the meaning quite well. > "especially" That refers to news and new laws in recent years, which extended their surveillance capabilities. Also, it is relevant because Germany both has relative strong data protection against non-state actors, but also quite capable intelligence age…

> I think arguing about state actors is the wrong threat model for this discussion

My post was just a rebuttal to GP's framing the discussion around vague accusations towards state actors.

> security services captures the meaning quite well

It really doesn't. The various secret services (internal, external, military) are reporting to parliament (not the whole of it, just a close circle/committee nevertheless having received trust by being elected), and their heads are nominated by the government. It's of course entirely within your right to criticize their existence or operations, but yielding power to private monopolies based in another country without any public control whatsover and potential ties to foreign secret services (we don't really know) can't possibly solve whatever problem you're on to, and shouldn't be justified on such vague arguments.

Re: Turn off DoH, Firefox

#319
post #102

Earlier quoted context omitted.

The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com…

This! This is very bad for Erdoğan. They won't be able to block DNS over HTTPS. Thus teir classic DNS blocks will be useless. Last time I've checked there was over 300K blocked domains via DNS. Even 8.8.8.8 doesn't work.

Why can't they block 1.1.1.1?

Re: Turn off DoH, Firefox

#320

Earlier quoted context omitted.

> that seems like less privacy. Seems obvious, but is wrong. If there is a really obvious obstacle to anything, which immediately comes to mind, chances are people addressed this already. In the US, Firefox by default directs DoH queries to DNS servers that are operated by CloudFlare, meaning that CloudFlare has the ability to see users' queries. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place t…

Before, my ISP could gather the domains I visit by DNS. Now, they can still gather them from the IP addresses and SNI, and Cloudflare can gather them from DNS. I'm really struggling to see how this isn't a reduction in privacy. > Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk…

Your ISP can gather them with much, much more effort. There is privacy value in making things harder. The only motivation your ISP has for logging this is making money; if getting the information is too tedious and expensive why would they bother?

> and Cloudflare can gather them from DNS

but is contractually forbidden from saving that information.

> What happens if they get a FISA warrant?

They have to follow the law? Wrong threat model.

Post reply on HN