Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

391–400 of 422 posts

Re: Turn off DoH, Firefox

#391

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…

> As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company

> Sure, encrypting DNS is a good thing. But this is just like trying to make email more secure by using a 3rd party encryption gateway - all it does is moving around who to trust.

Make up your mind are you worried about the number of people that can see your dns or not?

Re: Turn off DoH, Firefox

#392
post #354

Earlier quoted context omitted.

Re: the contract, let's hope you're wrong. Re: privacy: by not having lying DNS or no NXDOMAIN, there is also less tracking (say, fingerprinting in ad web pages). And in the ISP's case, you're assuming they already do DPI, otherwise they now see IPs, which might not mean much in the CDN case. But if they do DPI, it will be resolved once ESNI starts being deployed.

> Re: the contract, let's hope you're wrong. Switching from a technical measure of privacy (no data being shared) to hope isn't the right way to go. > But if they do DPI, it will be resolved once ESNI starts being deployed. Once.

It's true hope isn't the proper answer. But IANAL is.

Re: Turn off DoH, Firefox

#393

Earlier quoted context omitted.

Your ISP is subject to the same FISA warrant threat. If it's one of the large monopoly providers, it's as much a one-stop-shop as Cloudfront is.

Not outside the US. Now unless Mozilla decides to pick a different DoH party for deployment in EU, the problem will come back.

The internet is as much of a monopoly outside of the US for example Tiscali in Europe. We have the same kangaroo courts when it comes to getting warrants to invade people privacy.

At least from a general perspective I don't see a big difference.

Re: Turn off DoH, Firefox

#394
post #359
post #199

Earlier quoted context omitted.

I hardly see how the OP is FUD. What the article states is true; just because you can opt-out doesn't mean it's wrong. Where you are drawing the line is the opt-out to disable it, as opposed to the convention of opt-in. Think about companies in the 50-200 employee range; As a sysadmin, I have to purposefully go out of my way to put that domain (use-application-dns.net)[1] in my root resolver, and point it to NXDOMAIN…

You know that Chrome is also planning a similar switch? https://www.silicon.co.uk/workspace/browser/google-chrome-do...

Yes, however the difference here is that Chrome is looking at the OS resolver itself first; not just disregarding it, or looking for a magic domain. Chrome is being opt-in, Firefox is being opt-out.

Chrome DoH use cases:

For the average home user, fine; they're either using what the ISP DNS is, or the public ones (1.1.1.1, 8.8.8.8 ....) If those are on the 'accepts DoH from us', then it'll use DoH to the appropriate destination.

For the corporate environment, their internal DNS might not support DoH, and as such, Chrome will not even try to use DoH.

The key is that it is respecting the OS DNS settings, not the ability to not resolve a magic domain. If I opt to setup DoH internally, the understanding is that I know what I'm getting into.

Re: Turn off DoH, Firefox

#395

Earlier quoted context omitted.

> Re: the contract, let's hope you're wrong. Switching from a technical measure of privacy (no data being shared) to hope isn't the right way to go. > But if they do DPI, it will be resolved once ESNI starts being deployed. Once.

> > But if they do DPI, it will be resolved once ESNI starts being deployed. > Once. This underestimates DPI vendors. eSNI can't stop them, they will just move to exploit side channel information (traffic patterns) to identify which websites you are visiting. People need to remember, that DPI industry has been fighting with obfuscation for years, it's a war where Cloudflare and Mozilla are compete newbies.

These are just unsubstantiated assertions. Fingerprinting does exist, but what you're saying is that there might be methods we haven't foreseen that will be implemented to improve DPI analysis and tampering. So what ? Do nothing in the meantime ?

Re: Turn off DoH, Firefox

#396
post #334
post #120

Earlier quoted context omitted.

> the only thing [browsers] should do is fetch exactly the page URL that was entered and display it. I strongly disagree. Browsers deal with a hostile environment that poses countless threats to their users, and need to be safe. Arguing that browsers should be minimal and not protect privacy is like arguing that cars should be minimal and not have seat belts. There is an argument that ensuring privacy in DNS could be…

>>browsers should do one thing >browsers should do it all The essential Multics vs Unix mindset clash. One application to rule them all vs. a versatile toolbox of interchangeable modules. Telco heads vs hacker heads. In the end, the hackers always win - but the telcos grow to be fat cats.

I don't think this is at odds with "should do one thing well". Safety is not an application in itself, it is a design principle.

"rm"'s purpose is only to delete, yet it still tries to ensure safety and sanity with its flags: -r, -f, --no-preserve-root, etc. Even simple tools should be safe by default.

Re: Turn off DoH, Firefox

#397

Earlier quoted context omitted.

Not outside the US. Now unless Mozilla decides to pick a different DoH party for deployment in EU, the problem will come back.

The internet is as much of a monopoly outside of the US for example Tiscali in Europe. We have the same kangaroo courts when it comes to getting warrants to invade people privacy. At least from a general perspective I don't see a big difference.

But it's not one or the other; an EU court will make a warrant for the ISP traffic data, and an US court for the DNS requests. You become vulnerable to both.

Re: Turn off DoH, Firefox

#398
post #360

Earlier quoted context omitted.

Before, my ISP could gather the domains I visit by DNS. Now, they can still gather them from the IP addresses and SNI, and Cloudflare can gather them from DNS. I'm really struggling to see how this isn't a reduction in privacy. > Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk…

Which is why SNI encryption is an important next step.

SNI encryption is only useful if the website you're visiting shares the IP with lots of other websites. E.g, they're sitting behind cloudflare.

When you visit any of my websites, which are not on shared IPs, then not only will you continue to inform your ISP that you're doing so (regardless of the existence of ESNI), but you will additionally be informing cloudflare too.

What's your solution? That I centralise all my websites behind Cloudflare? In the name or privacy? Laughable.

Re: Turn off DoH, Firefox

#399
post #370

Earlier quoted context omitted.

> They won't be able to block DNS over HTTPS Of course they will. The DoH server can be blocked just like any other.

Eh, this is a losing battle for them. In theory any HTTPS server can be a DoH server if set up for it. One key for the future is to have so many DoH servers available for people in countries that filter that there is no way the government can block them all.

My uBlock Origin contains over 100k filter rules, and I pay zero for it. I doubt a company can't sell a list of open DoH servers for a reasonable price.

Re: Turn off DoH, Firefox

#400

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

There's nothing that makes Cloudflare the more "privacy friendly" 3rd party. "Privacy friendly" would be a mechanism by which my desire to communicate with "example.com" involved my computer and the computer at example.com with no third party in between. As it stands Mozilla is switching out our local ISP for CloudFlare without asking our consent which means my traffic data is now spread around one more company - tha…

You are not considering that IP addresses are dynamic. Only your provider can associate your IP address with you, and thus associate the DNS requests that you make with your identity. Cloudfare can't, because today you have one IP, tomorrow you can have another. And this without talking about providers that puts you inside a NAT, like it's common with mobile connections, where thousands of different costumers shares the same IP address, and thus only the provider can really log your DNS traffic.

So if Cloudfare maintains a log of your requests who cares, that log is useless since they can't identify you as soon as you change your IP address. While using standard DNS the provider can identify you and can log all you DNS requests, even if you don't the default ISP DNS servers, since they can simply intercept and decode all the traffic on the DNS port. And not only your provider, everyone in the path between your PC and the DNS server, even at LAN level, for example in public WiFi networks like in airports, schools, companies, the administrators can log all your DNS traffic, and put filters on it.

Post reply on HN