Live data from Hacker News

NextDNS Joins Firefox’s Trusted Recursive Resolver

blog.mozilla.org

41–50 of 146 posts

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#41
post #18

I'm not sure how I feel about Firefox's strategy for DoH. On the one hand, moving DNS out of the hands of ISPs that (at least in the US) have no real incentive to respect user privacy is probably a good thing. On the other hand, circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental co…

Enterprise use cases can easily manage this through Group Policy. Households (keep in mind we are only talking about people who knew enough to change DNS settings in the first place) can just change the setting on each of their five or so computers. And if you are using DNS as parental controls, that's not a great solution as nothing stops someone from getting the IPs out of band (ex. a website that does DNS lookups) and connecting directly to the blocked sites.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#42
post #29

“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…

It's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.

This is the wrong dichotomy and it's a false one perpetuated by Mozilla.

Users can have end to end encrypted DNS and browsers shouldn't be hijacking it.

To put it another way, you don't want the people who only care about eyeballs (Google, Mozilla, etc.) picking your DNS provider.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#43
So im curious to know, what is stopping Mozilla from selling "Trusted Recursive Resolver" positions to private companies just like they sell search engine placement in their browser?

whats to prevent a VC firm from just...quietly acquiring NextDNS (or any of the other DoH providers) and selling your browse history back to anyone who wants it?

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#44
post #36
post #18

I'm not sure how I feel about Firefox's strategy for DoH. On the one hand, moving DNS out of the hands of ISPs that (at least in the US) have no real incentive to respect user privacy is probably a good thing. On the other hand, circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental co…

> circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental controls, etc. This is configurable via group policy.

Sure, if all the machines you care about are windows boxes managed with Active Directory. There are ways to configure it on linux and mac too by putting a json file in the firefox installation folder, but it is one more thing IT needs to worry about. I don't know of any IT professional that would be excited at the prospect of having to configure DNS for individual applications.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#45
post #29

“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…

I think the endgame is to route everything through Tor or a similar anonymizing layer, nothing else will suffice in the face of pervasive tracking.

Incidentally, Mozilla is showing interest in embedding Tor in Firefox [1], but they haven't yet publicly commited to it [2].

[1] https://www.zdnet.com/article/mozilla-offers-research-grant-...

[2] https://www.techradar.com/news/firefox-isnt-getting-a-tor-pr...

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#46
post #29

“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…

It's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.

Probably the ISP, since it already has a working business model unrelated to selling your DNS query data and doing so is probably illegal in several countries.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#48
post #43

So im curious to know, what is stopping Mozilla from selling "Trusted Recursive Resolver" positions to private companies just like they sell search engine placement in their browser? whats to prevent a VC firm from just...quietly acquiring NextDNS (or any of the other DoH providers) and selling your browse history back to anyone who wants it?

Possibly contractual obligations? That's what Mozilla did with Pocket before simply acquiring it themselves.

edit: Yes, it is with contracts. https://wiki.mozilla.org/Security/DOH-resolver-policy#Confor...

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#49
post #42

Earlier quoted context omitted.

It's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.

This is the wrong dichotomy and it's a false one perpetuated by Mozilla. Users can have end to end encrypted DNS and browsers shouldn't be hijacking it. To put it another way, you don't want the people who only care about eyeballs (Google, Mozilla, etc.) picking your DNS provider.

So disable DoH in Firefox, or change the provider? If you know enough to choose a DoH provider, the browser defaults are not very relevant, presumably.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#50
post #21

Earlier quoted context omitted.

It's probably a good thing? US ISPs actively collect data from DNS lookups. They're an actual according-to-Hoyle threat actor in the IETF's supposed threat model.

> It's probably a good thing? US ISPs The world is hella lot bigger than the US. And Firefox runs in the rest of the world too.

> And Firefox runs in the rest of the world too.

But Firefox only enabled DoH by default in the US.

Post reply on HN