Earlier quoted context omitted.
> I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. There's very few countries with such strong privacy protections, even in the Western world.
From what I can tell, all countries covered by the GDPR heavily limit what an ISP can do with DNS queries. That covers 515M people, which is more than the populations of three mentioned countries (US, Russia and Australia) put together.
Turn off DoH, Firefox
361–370 of 422 posts
Re: Turn off DoH, Firefox
#362Earlier quoted context omitted.
There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…
> that seems like less privacy. Seems obvious, but is wrong. If there is a really obvious obstacle to anything, which immediately comes to mind, chances are people addressed this already. In the US, Firefox by default directs DoH queries to DNS servers that are operated by CloudFlare, meaning that CloudFlare has the ability to see users' queries. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place t…
It's as simple as this. Now I do prefer a society of trust over excessive technological means, but let's not pretend like sending data to an additional third party is somehow more or even just as private as not sending it in the first place.
Re: Turn off DoH, Firefox
#363Earlier quoted context omitted.
There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…
> that seems like less privacy. Seems obvious, but is wrong. If there is a really obvious obstacle to anything, which immediately comes to mind, chances are people addressed this already. In the US, Firefox by default directs DoH queries to DNS servers that are operated by CloudFlare, meaning that CloudFlare has the ability to see users' queries. Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place t…
You seem to think that: 1)No company in the history of the world, has ever violated a contract?
2)No government has ever forced a company to give up information that it is contractually obliged not to give up
3)No hacker has ever hacked into a company's systems and exfiltrated data the company was contractually obliged not to share
You seem to think that if a contract has been concluded, it is impossible for it to be violated.
Then there are also the problems of making all Firefox browsers depend on the availability of CloudFlare.
Re: Turn off DoH, Firefox
#364Earlier quoted context omitted.
> Wrong threat model. You are not permitted to hand-wave corrupt government interception or rubberhosing of civilian data as "wrong threat model." These technologies are central to, and must be focused specifically on, protecting all civilian data from all governments. That is the primary purpose of all privacy systems. Not to protect you from coffee-shop denizens trying to snoop which dating sites you use.
Your ISP is subject to the same FISA warrant threat. If it's one of the large monopoly providers, it's as much a one-stop-shop as Cloudfront is.
Re: Turn off DoH, Firefox
#365Earlier quoted context omitted.
Your ISP is subject to the same FISA warrant threat. If it's one of the large monopoly providers, it's as much a one-stop-shop as Cloudfront is.
Not outside the US. Now unless Mozilla decides to pick a different DoH party for deployment in EU, the problem will come back.
Though outside the US, the NSA doesn't require a FISA warrant to intercept data, nor does it face any US legal restrictions on doing so.
Re: Turn off DoH, Firefox
#366Earlier quoted context omitted.
Before, my ISP could gather the domains I visit by DNS. Now, they can still gather them from the IP addresses and SNI, and Cloudflare can gather them from DNS. I'm really struggling to see how this isn't a reduction in privacy. > Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk…
Your ISP can gather them with much, much more effort. There is privacy value in making things harder. The only motivation your ISP has for logging this is making money; if getting the information is too tedious and expensive why would they bother? > and Cloudflare can gather them from DNS but is contractually forbidden from saving that information. > What happens if they get a FISA warrant? They have to follow the la…
I used to work at an ISP.
We configured (wrote policy language for) our DPI platforms to do header inspection of all HTTPS traffic to measure customer experience to different websites, to improve the customer experience.
The raw data was (theoretically) accessible to ~4 people and deleted as soon as ETL had succeeded, and the anonymised results (aggregated only by region, product etc.) were available to the operations team (another ~8) and product management (~4).
This complies with our countries personal information regulations.
Mozilla proponents seem to be quite anti-ISP.
Why is that?
>> What happens if they get a FISA warrant?
> They have to follow the law? Wrong threat model.
If this happens for non-US citizens, this is violation of privacy laws of the affected user.
If this is rolled out, I will either ensure my distro switches this off by default, or have to consider changing browsers (away from Firefox).
Re: Turn off DoH, Firefox
#367Earlier quoted context omitted.
ISP and government are that "unregulated third party".
ISPs are highly regulated, as opposed to Cloudflare and Google. The only effect here is that Google closes another "loophole" in their view where web visit signals are send to another party (other than Google), and Cloudflare wanting their share of the cake as well. Has Mozilla disclosed what Cloudflare is paying them for being listed as default DoH provider?
Re: Turn off DoH, Firefox
#368Earlier quoted context omitted.
> This is especially true in the country the author appears to be based (Germany). Of all the governments to worry about, the ones in the EU (as well as US, CA, AU, NZ), are the ones I'd least be concerned with, relatively speaking. They're enabling this in the US, and yet even with all its problems, it's the one country that the average web surfer would have to worry least about when visiting "inappropriate" sites.…
> Of all the governments to worry about, the ones in the EU (as well as US, CA, AU, NZ), are the ones I'd least be concerned with, relatively speaking. Completely wrong threat assesment in my opinion. You should always be concerned about your own government. It isn't only the axis of evil that imprisons people with leaks about heavy privacy invasions. Russia and China have anything about you and you are a citizen of…
Re: Turn off DoH, Firefox
#369Earlier quoted context omitted.
Or -- much better -- use DoT instead of DoH so port 443 isn't getting misused for DNS.
Then it would be easier for an ISP to block encrypted DNS (by port number). It is better to masquerade everything as normal HTTPS to make blocking more difficult.
For most people, if you can't trust your ISP, you have bigger problems.
For people who can trust their ISP, why should we all by default be affected by the fact that the Mozilla developers seem to all live in a non-free or non-democratic country.
Maybe they should instead focus on fixing the US political system that results in their current situation, rather than trying to use technical means to solve political problems.
Re: Turn off DoH, Firefox
#370Earlier quoted context omitted.
This! This is very bad for Erdoğan. They won't be able to block DNS over HTTPS. Thus teir classic DNS blocks will be useless. Last time I've checked there was over 300K blocked domains via DNS. Even 8.8.8.8 doesn't work.
> They won't be able to block DNS over HTTPS Of course they will. The DoH server can be blocked just like any other.