Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

381–390 of 422 posts

Re: Turn off DoH, Firefox

#381
post #354
post #307

Earlier quoted context omitted.

A contract where cloudflare receives no consideration isn't particularly comforting, as such agreements are routinely ignored by courts (or equivalently by capping damages at nothing). > Mozilla's conundrum is how to protect everyone 's privacy And exactly how does this protect user's privacy? Instead of the user's ISP being able to see where the user connects now both cloudflare AND the user's ISP (via seeing the co…

Re: the contract, let's hope you're wrong. Re: privacy: by not having lying DNS or no NXDOMAIN, there is also less tracking (say, fingerprinting in ad web pages). And in the ISP's case, you're assuming they already do DPI, otherwise they now see IPs, which might not mean much in the CDN case. But if they do DPI, it will be resolved once ESNI starts being deployed.

> But if they do DPI, it will be resolved once ESNI starts being deployed.

What if ISPs block requests with eSNI for all users, in order to be able to remain compliant with legal intercept legislation (e.g. warrant for suspected child porn investigation)?

There are conflicting desires with trade-offs, and all Mozilla is doing here is escalating the war, rather than trying to reach agreement with the rest of the industry on how to satisfy two different requirements.

Re: Turn off DoH, Firefox

#382
post #251
post #199

Earlier quoted context omitted.

I hardly see how the OP is FUD. What the article states is true; just because you can opt-out doesn't mean it's wrong. Where you are drawing the line is the opt-out to disable it, as opposed to the convention of opt-in. Think about companies in the 50-200 employee range; As a sysadmin, I have to purposefully go out of my way to put that domain (use-application-dns.net)[1] in my root resolver, and point it to NXDOMAIN…

Indeed, Firefox is prioritizing the interests of users over the interests of sysadmins. Personally, I'm fine with that. > The basic IT mantra has been 'If it aint broke, don't fix it.' An unencrypted protocol that compromises privacy may not be "broke" for sysadmins, but it is for users.

Well, now CF will know per-organization IT structures. All those LAN-only administrative interfaces, and, with link prefetching, internal resource maps could be built in just a few clicks , using account with sufficient privileges. This is such a security-defying move by Mozilla I can't even start. And CF DNS logs will be the obvious first step for every targeted attack.

Re: Turn off DoH, Firefox

#383
post #377

Earlier quoted context omitted.

How is it in the interest of users if they can't access the intranet servers anymore?

They can, it just takes extra steps. Firefox tries DoH via Cloudflare, for an internal domain that returns NXDOMAIN (Cloudflare can't answer for your internal resolver,) then they fall back to local resolvers, which is OS based (DHCP or statically set.) The response time to complete the internal request goes up, because you're sending data to Cloudflare, they can't find it, then the 'normal' response time for interna…

> They can, it just takes extra steps.

For 99% of users, that means they can't.

Luckily for them, they probably aren't allowed to use Firefox anyway, and are stuck using Edge or whatever, and the local MCSE will use this as another reason why Firefox may not be used by anyone.

Re: Turn off DoH, Firefox

#384
post #373
post #322

The Internet was a great distributed system with reasonable separation of concerns. Now we are content that applications do their own name resolution and said resolution is centralised on a very few (non-altruistic) hands (CloudFlare/Google). Add amp to this. Sprinkle it with the views of people who run their own mail server and consider where this leaves us. I am not that naive and think we can keep ourselves in 199…

The internet also was 99% plaintext. Then we realized that governments would pull all kinds of tricks to watch that text. From your own state monitoring all the traffic, to outside states hijacking BGP and slurping up your data. This has, at least in the case of http centralized certificates. Here's the next thing, no one is stopping you from running your own DoH server. No one is stopping you from changing the FF co…

> This could have been handled between operating system developers and DNS infrastructure but they didn't care to.

No, there was a lot of caring over the years as DNS is old and insecure, in particular unencrypted communications with authoritative DNS servers being the biggest issue. And yet completely ignored by DNS-over-HTTPS, because solving it would likely eliminate the need for resolvers in the middle, so surveillance capitalism isn't interested, they only want to "solve" it in a such way that doesn't really solve it, but just gives them DNS data.

Re: Turn off DoH, Firefox

#385
post #354

Earlier quoted context omitted.

Re: the contract, let's hope you're wrong. Re: privacy: by not having lying DNS or no NXDOMAIN, there is also less tracking (say, fingerprinting in ad web pages). And in the ISP's case, you're assuming they already do DPI, otherwise they now see IPs, which might not mean much in the CDN case. But if they do DPI, it will be resolved once ESNI starts being deployed.

> Re: the contract, let's hope you're wrong. Switching from a technical measure of privacy (no data being shared) to hope isn't the right way to go. > But if they do DPI, it will be resolved once ESNI starts being deployed. Once.

> > But if they do DPI, it will be resolved once ESNI starts being deployed.

> Once.

This underestimates DPI vendors. eSNI can't stop them, they will just move to exploit side channel information (traffic patterns) to identify which websites you are visiting. People need to remember, that DPI industry has been fighting with obfuscation for years, it's a war where Cloudflare and Mozilla are compete newbies.

Re: Turn off DoH, Firefox

#386
I was never a conspiracy buff but the hordes of shills here who think it's a good idea to send the whole worlds browsing habits to the US a country with practically no protection of data lets this seem like a long prepared operation.

The Chinese had to hack BGP to get that kind of data for a limited time.

Re: Turn off DoH, Firefox

#387

Earlier quoted context omitted.

Then it would be easier for an ISP to block encrypted DNS (by port number). It is better to masquerade everything as normal HTTPS to make blocking more difficult.

> Then it would be easier for an ISP to block encrypted DNS (by port number). It is better to masquerade everything as normal HTTPS to make blocking more difficult. For most people, if you can't trust your ISP, you have bigger problems. For people who can trust their ISP, why should we all by default be affected by the fact that the Mozilla developers seem to all live in a non-free or non-democratic country. Maybe th…

What if you can trust your ISP most of the times but not during a specific time? For example, when there are civilian protests/acts which the current government doesn't like?

I have a very specific case for this: in the days before and during the referendum for the Catalonia independence (Oct 1s 2017), all the spanish ISPs where blocking access to the websites related with the referendum, using DPI to look for the SNI hostname. One of the main reasons to enable DoH in FF is to enable the encrypted SNI feature https://miketabor.com/enable-dns-over-https-and-encrypted-sn...

Re: Turn off DoH, Firefox

#388

Earlier quoted context omitted.

> Of all the governments to worry about, the ones in the EU (as well as US, CA, AU, NZ), are the ones I'd least be concerned with, relatively speaking. Completely wrong threat assesment in my opinion. You should always be concerned about your own government. It isn't only the axis of evil that imprisons people with leaks about heavy privacy invasions. Russia and China have anything about you and you are a citizen of…

> ... * concerned about your own government.* Who says I'm not? But I have recourse with government. What recourse do I have with a private corporation that's based in a country with such law privacy laws.

I know it was a rhetorical question but here it needs to be spelled out:

None.

Re: Turn off DoH, Firefox

#389

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

DoH is vital to protect users around the world from censorship and worse. Like I've asked before, should Mozilla also start including an obfuscating VPN by default, to bypass the Chinese firewall? This is a political issue, and one that I don't think Mozilla should even get involved in because it could have very ugly consequences --- just focus on making a good browser and leave the politics (and VPN/firewall-busters…

And route all (Firefox) internet traffic of the world through the US.

Re: Turn off DoH, Firefox

#390

Earlier quoted context omitted.

And for regular DNS, their ISP/employer/school will be the service provider for 99.9999% of users. Regular DNS is not exactly easy to find (on Windows, it's under Settings -> Network -> Change Adapter Options -> Adapter Name -> IPv4 -> Properties), which is arguably as hard as going to about:config. And there is no menu of providers listed--nor does it explain who would choose the "automatic" DNS server options (the…

> So the status quo is no better than this You're completely missing the point. Users have many different ISPs, and them knowing DNS queries is not a problem because it's the ISP anyway. Now a browser wants to change that behavior, and send ALL queries to one american company.

Indeed, I think that in this case, on the whole, more privacy is achieved by decentralization rather than by encryption...
Post reply on HN