Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

411–420 of 422 posts

Re: Turn off DoH, Firefox

#411
post #368

Earlier quoted context omitted.

> Of all the governments to worry about, the ones in the EU (as well as US, CA, AU, NZ), are the ones I'd least be concerned with, relatively speaking. Completely wrong threat assesment in my opinion. You should always be concerned about your own government. It isn't only the axis of evil that imprisons people with leaks about heavy privacy invasions. Russia and China have anything about you and you are a citizen of…

Least concerned with? Have you already forgotten about Snowden? Do you know about Five Eyes (or even Fourteen Eyes)? In Canada they outsource surveillance of Canadians to overseas Five Eyes partner agencies so they evade their own privacy laws. It's reasonable to assume that other Five Eyes countries do the same.

I'm with an ISP that has a direct link to TorIX, which has a who's who of the major Internet properties and CDNs:

* https://www.torix.ca/peers/

My e-mail is hosted on Canadian soil with a direct-connect to TorIX (and I personally know the people who run the servers).

I know when I hit a foreign corporation (AMZN, GOOG, etc.) that my data is probably up for grabs, but I also know when when my traffic is not leaving Canadian (digital) soil.

So yes, I know all about ECHELON et al, but I know how the packets I send out are generally routed as well.

Re: Turn off DoH, Firefox

#412
post #396
post #334

Earlier quoted context omitted.

>>browsers should do one thing >browsers should do it all The essential Multics vs Unix mindset clash. One application to rule them all vs. a versatile toolbox of interchangeable modules. Telco heads vs hacker heads. In the end, the hackers always win - but the telcos grow to be fat cats.

I don't think this is at odds with "should do one thing well". Safety is not an application in itself, it is a design principle. "rm"'s purpose is only to delete, yet it still tries to ensure safety and sanity with its flags: -r, -f, --no-preserve-root, etc. Even simple tools should be safe by default.

We already have applications that can take all your traffic and send it over an encrypted tunnel somewhere else, if you don't want to exit to the Internet from a place you don't trust. They're called VPN clients. DoH is like a partial VPN client. It doesn't belong in the browser.

Re: Turn off DoH, Firefox

#413

Earlier quoted context omitted.

The internet is as much of a monopoly outside of the US for example Tiscali in Europe. We have the same kangaroo courts when it comes to getting warrants to invade people privacy. At least from a general perspective I don't see a big difference.

But it's not one or the other; an EU court will make a warrant for the ISP traffic data, and an US court for the DNS requests. You become vulnerable to both.

1.1.1.1 operates on edges of CloudFlare CDN - EU users will be handled by EU DNS server. And there’s no logging.

Re: Turn off DoH, Firefox

#414
post #215
post #141

Earlier quoted context omitted.

privacy-wise, plaintext is the worst option possible.

I disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have n…

Your request will hit CloudFlare edge node in your country and be served from there. Under your jurisdiction.

Re: Turn off DoH, Firefox

#415

Earlier quoted context omitted.

From what I can tell, all countries covered by the GDPR heavily limit what an ISP can do with DNS queries. That covers 515M people, which is more than the populations of three mentioned countries (US, Russia and Australia) put together.

A lot of these countries currently have laws to record years of DNS logs for future analysis by the police. Due to the abuse these countries have done in the past about it, I do not want any record personally.

That’s a very good point. In fact all of them do, because the same EU that mandates GDPR also mandates data retention, which only differs in details in member states.

Re: Turn off DoH, Firefox

#417
post #368

Earlier quoted context omitted.

> Of all the governments to worry about, the ones in the EU (as well as US, CA, AU, NZ), are the ones I'd least be concerned with, relatively speaking. Completely wrong threat assesment in my opinion. You should always be concerned about your own government. It isn't only the axis of evil that imprisons people with leaks about heavy privacy invasions. Russia and China have anything about you and you are a citizen of…

Least concerned with? Have you already forgotten about Snowden? Do you know about Five Eyes (or even Fourteen Eyes)? In Canada they outsource surveillance of Canadians to overseas Five Eyes partner agencies so they evade their own privacy laws. It's reasonable to assume that other Five Eyes countries do the same.

Alright, in case your government leverages allied ones to evade domestic legislation, foreign governments are a threat. But the initiative for surveillance still lies with your own government. That would only confirm the need to hold your own government accountable.

Re: Turn off DoH, Firefox

#418

Earlier quoted context omitted.

Haha. Okay: Actually didn't see it because that one line landed below the fold on my resolution (960px height, fixed taskbar on Windows). Rookie mistake. But also bad UI design if this is actually something that's important and that users should pay attention to. But. (1) There is no informed consent happening here, highlighting to a user, say in Europe, that this would lead to a U.S.-regulated entity knowing a lot a…

The dropdown in (2) doesn't have any other options because of the thing you're worried about in (1). Mozilla seeks specifically to contract with DoH operators to secure the operator's consent to protect their users and never do most of the things you're worried they might do. They do NOT want the list to go: Cloudflare Sketchy Valley Company with six months runway and no clear plan how to make a profit The Actual Mob…

In a very long-winded and theatrical way you are making the point that you believe that there are no credible alternatives out there. I believe there are. I believe that, as soon as any company puts their HQ and their servers in Europe they have a credibility-advantage over cloudflare right there on the legal front and on regulatory oversight.

I also don't believe that Mozilla has the ability to greatly influence the way Cloudflare would run their service, given that they're probably not paying a lot (or anything at all; don't know the particulars), and are unlikely to be a major component of Cloudflare's revenue. Cloudflare has much more to lose by picking a fight with the U.S. government (think government surveillance) or by pissing off major advertising networks and media corporations (think surveillance capitalism) who make up the lion's share of their revenue on Cloudflare's core webcaching business.

Re: Turn off DoH, Firefox

#419
post #396

Earlier quoted context omitted.

I don't think this is at odds with "should do one thing well". Safety is not an application in itself, it is a design principle. "rm"'s purpose is only to delete, yet it still tries to ensure safety and sanity with its flags: -r, -f, --no-preserve-root, etc. Even simple tools should be safe by default.

We already have applications that can take all your traffic and send it over an encrypted tunnel somewhere else, if you don't want to exit to the Internet from a place you don't trust. They're called VPN clients. DoH is like a partial VPN client. It doesn't belong in the browser.

DoH servers are not open proxies, they're just DNS resolvers with support for a security layer; they are comparable to HTTPS, SMTPS, SSH, etc. servers, not to a VPN.

VPNs are not a substitute for, nor a better solution than DoH in the same way as they are not for HTTPS or SSH.

Re: Turn off DoH, Firefox

#420
I simply don't like DoH because I use a DNS provider that I have chosen - OpenDNS - specifically because they log my DNS queries and let me see that log. I don't mind DNS lookups from my network being logged, as long as the provider does accurate, uncensored DNS lookups. It's helped me find domains to block such as tracking domains used by IoT devices that I can't configure myself.

I have my router directing all DNS traffic to OpenDNS so these devices can't pick their own servers, any outbound requests on port 53 will be redirected. If they start using DoH/DoT, I can't do that so easily. I'd have to start monitoring outbound traffic and do hostname resolution on the IPs.

I think the privacy argument for DoH in the browser is fairly weak, since doing a DNS lookup is not really an indication of, well, anything really. No matter what domain it was, there's no indication that the user intended to visit a website or use a service on that domain, it could be as simple as a lookup to load an embedded image in a spam email. The only good usage of it is to prevent censorship via DNS.

Post reply on HN