Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

321–330 of 422 posts

Re: Turn off DoH, Firefox

#322
The Internet was a great distributed system with reasonable separation of concerns.

Now we are content that applications do their own name resolution and said resolution is centralised on a very few (non-altruistic) hands (CloudFlare/Google).

Add amp to this. Sprinkle it with the views of people who run their own mail server and consider where this leaves us.

I am not that naive and think we can keep ourselves in 1995. But I do think we give up on too many of the good parts all to freely.

Re: Turn off DoH, Firefox

#323

Earlier quoted context omitted.

So it depends on the country. In my country (Russia) all Internet traffic is being recorded by the ISP for the last month and sites are blocked on political reasons. For me having DoH with Cloudflare is better.

Ditto in Australia The reason why browsers are moving to features like DoH and eSNI as defaults is because it's every type of nation that is now instituting pervasive surveillance against its citizens You also can't trust laws since ISPs can be hacked or infiltrated from the inside In terms of personal protection encryption trumps law

> You also can't trust laws since ISPs can be hacked or infiltrated from the inside

Cloudflare isn't magically free from the same threats.

Re: Turn off DoH, Firefox

#324

Earlier quoted context omitted.

Before, my ISP could gather the domains I visit by DNS. Now, they can still gather them from the IP addresses and SNI, and Cloudflare can gather them from DNS. I'm really struggling to see how this isn't a reduction in privacy. > Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk…

Your ISP can gather them with much, much more effort. There is privacy value in making things harder. The only motivation your ISP has for logging this is making money; if getting the information is too tedious and expensive why would they bother? > and Cloudflare can gather them from DNS but is contractually forbidden from saving that information. > What happens if they get a FISA warrant? They have to follow the la…

> Wrong threat model.

You are not permitted to hand-wave corrupt government interception or rubberhosing of civilian data as "wrong threat model." These technologies are central to, and must be focused specifically on, protecting all civilian data from all governments. That is the primary purpose of all privacy systems. Not to protect you from coffee-shop denizens trying to snoop which dating sites you use.

Re: Turn off DoH, Firefox

#325
It's weird how large companies can make decisions like this (re-routing all DNS requests to the US) on their own, without local/EU government stepping in to prevent it...

Re: Turn off DoH, Firefox

#326
post #148

Living in Russia, I, for one, welcome DoH and ESNI. I know I trust Cloudflare more than my government and ISP (The same ISP that routinely spoofs requests to inject ad pages/reminders to pay for service, nevermind all the blocked sites).

Not like DoH helps much here though.

Re: Turn off DoH, Firefox

#327
post #215

Earlier quoted context omitted.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

> I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. There's very few countries with such strong privacy protections, even in the Western world.

From what I can tell, all countries covered by the GDPR heavily limit what an ISP can do with DNS queries. That covers 515M people, which is more than the populations of three mentioned countries (US, Russia and Australia) put together.

Re: Turn off DoH, Firefox

#328
I don't understand the DoH protocol entirely. I thought the entire point of it was to pass encrypted requests to CloudFlare. Can anyone confirm how this works? I thought this was the entire point of DoH, adding encryption to requests and directing it away from the plaintext DNS requests.

Re: Turn off DoH, Firefox

#329
post #31

Earlier quoted context omitted.

If you use your ISP's DNS servers, there is no intermediary between you and them.

If you use wi-fi without a VPN, you have the coffee shop and the coffee shop's ISP. And anyone listening there. Of course there is cleartext SNI even for SSL connections... but alas.

What coffee shop ? I only connect to wifi at home and at the office.

Re: Turn off DoH, Firefox

#330
post #102

Earlier quoted context omitted.

The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com…

Wrong way around. Said own country might one day decide to restrict access/log visits to controversial site X (e.g. Tibet, government critical news, piratebay etc.), which does not affect your DNS based in foreign country

Said country will just block the Cloudflare DoH server as well, forcing users to switch to a controlled DNS server.
Post reply on HN