Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

351–360 of 422 posts

Re: Turn off DoH, Firefox

#351
post #4
post #2

What they should do is offer several alternatives when enabling DoH (Cloudflare isn't the only DoH provider out there), and anto-detect if your ISP or local network supports it at the enterprise level. At least you can change the provider in about:config. I don't remember if you can do it through the settings page.

Many ISPs won't offer such thing https://www.zdnet.com/article/uk-isp-group-names-mozilla-int...

Note that Mozilla has added a way for network operators to disable DoH for their entire network, by NXDOMAINing a specific fake address. UK ISPs will presumably do that, and DoH won't happen in the UK for a while.

Re: Turn off DoH, Firefox

#352

The only thing that annoys me slightly about this, is that I currently have a couple of pi-holes running at home (one for us, and one for the kids) and I have the Mikrotik setup to redirect any request for DNS to the correct pi (So even if they change the DNS on the device it still hits the pi) This is going to make that a pain - especially if they introduce it in the mobile version?

Only firefox does this, and Firefox has uBlock Origin. Why is this an issue?

Re: Turn off DoH, Firefox

#353
post #251
post #199

Earlier quoted context omitted.

I hardly see how the OP is FUD. What the article states is true; just because you can opt-out doesn't mean it's wrong. Where you are drawing the line is the opt-out to disable it, as opposed to the convention of opt-in. Think about companies in the 50-200 employee range; As a sysadmin, I have to purposefully go out of my way to put that domain (use-application-dns.net)[1] in my root resolver, and point it to NXDOMAIN…

Indeed, Firefox is prioritizing the interests of users over the interests of sysadmins. Personally, I'm fine with that. > The basic IT mantra has been 'If it aint broke, don't fix it.' An unencrypted protocol that compromises privacy may not be "broke" for sysadmins, but it is for users.

How is it in the interest of users if they can't access the intranet servers anymore?

Re: Turn off DoH, Firefox

#354
post #307
post #156

This is a gross over-simplification. Cloudflare is required by contract to respect your privacy, which is much stronger than even the privacy laws have here in the EU since it addresses everyone, not just the EU population: https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... The people fighting for the status quo probably know how to run their own resolver, even with DoH or DTLS. But Mozilla's conundrum i…

A contract where cloudflare receives no consideration isn't particularly comforting, as such agreements are routinely ignored by courts (or equivalently by capping damages at nothing). > Mozilla's conundrum is how to protect everyone 's privacy And exactly how does this protect user's privacy? Instead of the user's ISP being able to see where the user connects now both cloudflare AND the user's ISP (via seeing the co…

Re: the contract, let's hope you're wrong.

Re: privacy: by not having lying DNS or no NXDOMAIN, there is also less tracking (say, fingerprinting in ad web pages).

And in the ISP's case, you're assuming they already do DPI, otherwise they now see IPs, which might not mean much in the CDN case. But if they do DPI, it will be resolved once ESNI starts being deployed.

Re: Turn off DoH, Firefox

#355

Earlier quoted context omitted.

Corporations concerned about that should be blocking DoH anyway

Any device at home an go to http://nas and get on my nas, " http://desktop" , " http://router" , and " http://shed" and get on those. How does that work in this bold new future? I'll have to register a domain name and add a bunch of A records for 192.168.0.1, but then it still won't work -- I'll have to do " http://desktop.mydomain.com" . Worse, while going to "shed" will work in chrome, it will fail in firefox. My g…

I don't know why you're downvoted, because that is a very good question.

What you have to do is add an entry in your local nameserver for domain use-application-dns.net and set it to NXDOMAIN. See https://support.mozilla.org/en-US/kb/configuring-networks-di....

Hopefully Google will use the same method for disabling DoH in Chrome. But I won't be surprised if they're going to force DoH even harder, and make it even more difficult to turn off.

Re: Turn off DoH, Firefox

#356
post #348

Earlier quoted context omitted.

Detect it, how? By forwarding the request to a local resolver after DoH fails, and thus leaking information?

Do you... really care if someone outside you network knows the domain you chose for an internal network service? That's not sensitive information. Also, there's basically no way for cloudflare, even if they were being malicious about it, to collect and use that information. What would they do with it?

It's definitely sensitive information --- useful for attackers to find out the structure of the LAN.

Re: Turn off DoH, Firefox

#357
post #239

Earlier quoted context omitted.

I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. I strongly disagree. A browser has one job, and that is to follow and render URLs. Secure connections and such are services provided by other components of the…

What do you do as a browser vendor when the OS fails to provide you meaningful security and privacy? This is pretty much how we got here. Basically every device on the planet is right now configured to blindly accept whatever DNS server is handed to it by DHCP and there is really no movement on changing that. So browsers can throw up their hands and say "we are as secure as the OS" or they can do it themselves. Not i…

What do you do as a browser vendor when the OS fails to provide you meaningful security and privacy?

Nothing. Absolutely nothing. Work within the environment you're given.

Basically every device on the planet is right now configured to blindly accept whatever DNS server is handed to it by DHCP and there is really no movement on changing that.

...and that's just fine, because I trust my LAN more than some third party in another country.

Re: Turn off DoH, Firefox

#358

Earlier quoted context omitted.

Your ISP can gather them with much, much more effort. There is privacy value in making things harder. The only motivation your ISP has for logging this is making money; if getting the information is too tedious and expensive why would they bother? > and Cloudflare can gather them from DNS but is contractually forbidden from saving that information. > What happens if they get a FISA warrant? They have to follow the la…

> Wrong threat model. You are not permitted to hand-wave corrupt government interception or rubberhosing of civilian data as "wrong threat model." These technologies are central to, and must be focused specifically on, protecting all civilian data from all governments. That is the primary purpose of all privacy systems. Not to protect you from coffee-shop denizens trying to snoop which dating sites you use.

Your ISP is subject to the same FISA warrant threat.

If it's one of the large monopoly providers, it's as much a one-stop-shop as Cloudfront is.

Re: Turn off DoH, Firefox

#359
post #199
post #176

Earlier quoted context omitted.

It's actually FUD, because it's missing some important points > For starters, Mozilla said that after it turns on DoH by default for US users, Firefox will contain a mechanism to detect the presence of any local parental control software or enterprise configurations. > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists. > The organization said it…

I hardly see how the OP is FUD. What the article states is true; just because you can opt-out doesn't mean it's wrong. Where you are drawing the line is the opt-out to disable it, as opposed to the convention of opt-in. Think about companies in the 50-200 employee range; As a sysadmin, I have to purposefully go out of my way to put that domain (use-application-dns.net)[1] in my root resolver, and point it to NXDOMAIN…

You know that Chrome is also planning a similar switch?

https://www.silicon.co.uk/workspace/browser/google-chrome-do...

Re: Turn off DoH, Firefox

#360

Earlier quoted context omitted.

> that seems like less privacy. Seems obvious, but is wrong. If there is a really obvious obstacle to anything, which immediately comes to mind, chances are people addressed this already. In the US, Firefox by default directs DoH queries to DNS servers that are operated by CloudFlare, meaning that CloudFlare has the ability to see users' queries. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place t…

Before, my ISP could gather the domains I visit by DNS. Now, they can still gather them from the IP addresses and SNI, and Cloudflare can gather them from DNS. I'm really struggling to see how this isn't a reduction in privacy. > Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk…

Which is why SNI encryption is an important next step.
Post reply on HN