Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

331–340 of 422 posts

Re: Turn off DoH, Firefox

#331
post #102

Earlier quoted context omitted.

The default (which the majority of people will be using) is not Google, it's their ISP. And in the vast majority of cases, their ISP is under the jurisdiction of their country, while Google and Cloudflare have to obey the laws of a foreign country. Said foreign country might one day decide that for instance Google and Cloudflare now have to log the IP address of everyone who does a DNS lookup for news.ycombinator.com…

This! This is very bad for Erdoğan. They won't be able to block DNS over HTTPS. Thus teir classic DNS blocks will be useless. Last time I've checked there was over 300K blocked domains via DNS. Even 8.8.8.8 doesn't work.

> They won't be able to block DNS over HTTPS

Of course they will. The DoH server can be blocked just like any other.

Re: Turn off DoH, Firefox

#332
The government already has your DNS queries. So the whole point of the argument is moot.

The ISPs, and anyone they share the data with, also already have the DNS queries, so the argument is wrong.

But also, if you do want just one government to have the data, do you prefer that data to go to your local country, which may be speech-oppressing regimes like Syria, Saudi Arabia, UK, Ukraine, or Iran?

I fail to see how this is in any way a step backwards.

Re: Turn off DoH, Firefox

#333

Earlier quoted context omitted.

There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…

> that seems like less privacy. Seems obvious, but is wrong. If there is a really obvious obstacle to anything, which immediately comes to mind, chances are people addressed this already. In the US, Firefox by default directs DoH queries to DNS servers that are operated by CloudFlare, meaning that CloudFlare has the ability to see users' queries. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place t…

Even if this infrastructure was run by Mozilla itself, and they really really promised me that they would not do anything with the data - that's all I would have - a promise ( which is also how cloudflare words it btw [0]). Which in the asymetric situation that puts me in, is not worth all too much to me, because I will never be able to verify it.

The data would still end up at yet one more company, compared to the status quo.

Trust works if I know the people involved - but I don't know a single individual at Mozilla (or Cloudflare for that matter). That Mozilla trusts Cloudflare is besides the point if I don't really know who they are.

The entity I am actually trying to trust is example.com - all this shuffling around trust in increasing layers of complexity is missing the point of the actual problem: Bootstrapping a connection to example.com without revealing to a 3rd part that that is what one is trying to do.

[0] https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...

Re: Turn off DoH, Firefox

#334
post #120

It's very disturbing to see the overreach that Mozilla has resorted to and the "privacy" argument (it was "security" before that...) being used to justify essentially ignoring system configuration. My ISP has more accountability than a company in another country. The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Exactly. If Mozilla…

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…

>>browsers should do one thing >browsers should do it all

The essential Multics vs Unix mindset clash. One application to rule them all vs. a versatile toolbox of interchangeable modules. Telco heads vs hacker heads.

In the end, the hackers always win - but the telcos grow to be fat cats.

Re: Turn off DoH, Firefox

#335

Earlier quoted context omitted.

That's a really strange comparison. You know that mozilla has an agreement with cloudflare under which cloudflare has agreed not to log dns queries right?

Maybe Mozilla has such an agreement, but I don't. I have a contract with my ISP, and thr GDPR applies to that contract. CF? Not so much.

1)Since the agreement is about processing of this data it really doesn't matter whether you have a contract with CF 2)You don't need any contractual relationship to have GDPR apply to processing your data. If you're a European data subject then GDPR applies to any processing of your personally-identifiable data whoever is processing it and wherever they're doing it. If you're not a European data subject then GDPR would only apply if the company was a European company or if the processing was happening in Europe.

Re: Turn off DoH, Firefox

#336
post #142

Earlier quoted context omitted.

Thanks. I feel this should just be a setting on the settings screen. I use a PiHole DNS service at home which I want to keep using over this.

It should be a setting in a standard dot file. I don't understand why Mozilla can't create a simple configuration file like most applications.

All these settings are stored in ~/.mozilla/firefox/

So for me the trr mode is stored in /home/sean/.mozilla/firefox/k3dmofx7.default/prefs.js

Re: Turn off DoH, Firefox

#337

Earlier quoted context omitted.

Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.

While that's an unpopular opinion I tend to agree, I'm still on the fence if that's really bad or if I'm just grumpy about change though. It really feels like instead of fixing the underlying problems we're duct taping the internet by moving HTTPS to OSI layer 4 and making TCP and the concept of ports obsolete for a majority of use cases - which in many cases implies a loss of control. I'm honestly not sure why our s…

You're right of course, but HTTP(S) only 'won' because of the web.

Re: Turn off DoH, Firefox

#338
post #240

Earlier quoted context omitted.

And down the toilet goes the (distributing and caching) Inter-Net. Long live to the new Cloud-Net. Cloudfare and Google are achieving what Compuserve and AOL could not. Exaggerating slightly ... but not that much really. And all in the good name of privacy and security. It is also amazing how people (Americans ?) are not willing to admit I want MY jurisdiction to apply. Not an American one. I want the choice.

Caching died with insecure HTTP, and that's okay. > I want the choice. Then turn it off. But the default protects more people than it harms.

Well, it's not really a choice if for security I must give up on jurisdiction ?

I don't doubt the intentions of Mozilla. But, I expect Mozilla to set the bar much higher.

> But the default protects more people than it harms. Sorry, not good enough for me. They should not be promoting a private company centralized solution. They really should be pushing for a decentralized and distributed solution that is yet secure for everyone involve and promote that.

Re: Turn off DoH, Firefox

#339
post #241

Earlier quoted context omitted.

So the solution could be to make it so that there are many DoH providers and a browser would choose one of them randomly (or by user's choice).

Tor has some nice papers about what happens if you try that: the NSA and KGB each run a server and content themselves with getting a sample of the population.

> the NSA and KGB each run a server and content themselves with getting a sample

Which is already a lot better than getting 100% from simply spying on CloudFlare or serving them with "National Security Letters".

Re: Turn off DoH, Firefox

#340

Earlier quoted context omitted.

> I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. There's very few countries with such strong privacy protections, even in the Western world.

From what I can tell, all countries covered by the GDPR heavily limit what an ISP can do with DNS queries. That covers 515M people, which is more than the populations of three mentioned countries (US, Russia and Australia) put together.

> which is more than the populations of three mentioned countries (US, Russia and Australia) put together.

Not sure it matters, but only by a small margin is that true. 500M vs 515M.

Post reply on HN