Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

371–380 of 422 posts

Re: Turn off DoH, Firefox

#371

Earlier quoted context omitted.

the next step is eSNI and judging by the DoH rollout that will also be a new level of controversy advocating against it

What are the arguments against eSNI?

> What are the arguments against eSNI?

Institutions providing internet access, but with an obligation or operational requirement to block certain kinds of content (e.g. insufficient network capacity on the free WiFi at a hospital to allow streaming video for all visitors) would not be able to do it at all.

Privacy proponents seem to forget that there are sometimes reasonable reasons to allow traffic to be blocked, and instead of looking for a real solution, are imposing ridiculous "solutions" on all Firefox users.

Re: Turn off DoH, Firefox

#372
post #69
post #34

Earlier quoted context omitted.

> There has to be SOME default chosen It seems trivial to select a half a dozen likely candidates and let the user choose between them on install. Honestly I'd like them to do the same with the search engine. Yes, it's simple enough to change the default, but it'd be nice to choose up-front.

But Cloudflare also happen to be the fastest DNS resolver.

Fastest isn't necessarily best.

My ISPs caching DNS, and any caching DNS running on IP addresses belonging/advertised by my ISP by BGP to various CDNs, are the best possible responses.

I don't care if the p99 DNS response from my ISP is 50% slower than Cloudflare, if the streaming video, or large download, or many small files requests are better served by CDNs in my ISPs network that are not visible to Cloudflare.

All DNS benchmarks I have seen focus only on the DNS response time, never on the DNS response quality.

But that's because they are mostly written by people who don't know how the internet (or competent ISPs) actually work. Some of them even seem to log errors when they get unexpected responses for some well-known URLs (like google.com) because they don't know there are new Google sites than when they last checked ...

Re: Turn off DoH, Firefox

#373
post #322

The Internet was a great distributed system with reasonable separation of concerns. Now we are content that applications do their own name resolution and said resolution is centralised on a very few (non-altruistic) hands (CloudFlare/Google). Add amp to this. Sprinkle it with the views of people who run their own mail server and consider where this leaves us. I am not that naive and think we can keep ourselves in 199…

The internet also was 99% plaintext. Then we realized that governments would pull all kinds of tricks to watch that text. From your own state monitoring all the traffic, to outside states hijacking BGP and slurping up your data. This has, at least in the case of http centralized certificates.

Here's the next thing, no one is stopping you from running your own DoH server. No one is stopping you from changing the FF config to use it. The big issue has been is the end user has been so unaware of security for so long and done so little about it somebody has to. There is no financial incentive for your ISP to care, so they have not. Most operating systems, specifically Windows, but also Apple have done little to nothing for client DNS security. This could have been handled between operating system developers and DNS infrastructure but they didn't care to.

Re: Turn off DoH, Firefox

#374
post #334
post #120

Earlier quoted context omitted.

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…

>>browsers should do one thing >browsers should do it all The essential Multics vs Unix mindset clash. One application to rule them all vs. a versatile toolbox of interchangeable modules. Telco heads vs hacker heads. In the end, the hackers always win - but the telcos grow to be fat cats.

In a way, it's a Multics vs. Multics clash. I already have one application to rule them all. My operating system. I do not appreciate when the browser tries to supersede it. Not (just) because of philosophical reasons, but because browsers completely suck at being operating systems. The web takes a lot of control from the users, and offers near-zero interoperability.

It all feels like a step-by-step attempt at turning general-purpose computers into cable TV.

Re: Turn off DoH, Firefox

#375

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…

>As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent

According to their blog post discussing the matter, they fully intend to inform the user of the change and give them the opportunity to opt out.

>When DoH is enabled, users will be notified and given the opportunity to opt out

https://blog.mozilla.org/futurereleases/2019/09/06/whats-nex...

Re: Turn off DoH, Firefox

#376
post #354
post #307

Earlier quoted context omitted.

A contract where cloudflare receives no consideration isn't particularly comforting, as such agreements are routinely ignored by courts (or equivalently by capping damages at nothing). > Mozilla's conundrum is how to protect everyone 's privacy And exactly how does this protect user's privacy? Instead of the user's ISP being able to see where the user connects now both cloudflare AND the user's ISP (via seeing the co…

Re: the contract, let's hope you're wrong. Re: privacy: by not having lying DNS or no NXDOMAIN, there is also less tracking (say, fingerprinting in ad web pages). And in the ISP's case, you're assuming they already do DPI, otherwise they now see IPs, which might not mean much in the CDN case. But if they do DPI, it will be resolved once ESNI starts being deployed.

> Re: the contract, let's hope you're wrong.

Switching from a technical measure of privacy (no data being shared) to hope isn't the right way to go.

> But if they do DPI, it will be resolved once ESNI starts being deployed.

Once.

Re: Turn off DoH, Firefox

#377
post #251

Earlier quoted context omitted.

Indeed, Firefox is prioritizing the interests of users over the interests of sysadmins. Personally, I'm fine with that. > The basic IT mantra has been 'If it aint broke, don't fix it.' An unencrypted protocol that compromises privacy may not be "broke" for sysadmins, but it is for users.

How is it in the interest of users if they can't access the intranet servers anymore?

They can, it just takes extra steps.

Firefox tries DoH via Cloudflare, for an internal domain that returns NXDOMAIN (Cloudflare can't answer for your internal resolver,) then they fall back to local resolvers, which is OS based (DHCP or statically set.)

The response time to complete the internal request goes up, because you're sending data to Cloudflare, they can't find it, then the 'normal' response time for internal resolvers.

Edit: Made more clear.

Re: Turn off DoH, Firefox

#378

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

Since this moment Firefox should be actively prohibited in any security-conscious workplace - because it will leak some or whole map of internal resources to the third party, which has absolutely no business knowing what resources are deployed in the local network. And deciding what's good for users without making them explicitly and consciously confirm this choice is bad, worse than censorship.

Re: Turn off DoH, Firefox

#379
post #29

Earlier quoted context omitted.

There aren't many intermediaries if you use your ISP's internal resolvers.

And there are intermediaries between Cloudflare/other DoH providers and the respective authoritative nameservers anyway.

My ISP is subject to specific regulations for licensed network providers, which Cloudflare isn't.

Thus, Cloudflare is the problematic intermediary.

Re: Turn off DoH, Firefox

#380
post #367

Earlier quoted context omitted.

ISPs are highly regulated, as opposed to Cloudflare and Google. The only effect here is that Google closes another "loophole" in their view where web visit signals are send to another party (other than Google), and Cloudflare wanting their share of the cake as well. Has Mozilla disclosed what Cloudflare is paying them for being listed as default DoH provider?

ISP's are highly regulated when it comes to DNS? Not here in the US they are not.

Well to buy a domain you need to go to an accredited registrar for the respective TLD. And DNS registrations, renewals, etc. are standardized (and have TLD-specific policies). Also, you're entitled to transfer your domain name to another registratr, etc., also with a public and transparent protocol. The registrar will then arrange for their nameserver being registered as authoritative for your domain on the TLD's root domain server, etc. What's the problem with US ISPs here? That they're selling DNS query records (with your IP) against their nameservers? That's in the same territory as Cloudflare and Google, and will only stop with proper privacy laws; certainly not by giving up on the decentralized nature of DNS and giving all traffic/signals to Cloudflare/Google.
Post reply on HN