I'm looking at what my Windows DNS servers return when I put in an empty zone for "use-application-dns.net" and I'd like to see exactly what Firefox is testing for. Windows 2012 R2, at least, returns the SOA and no NXDOMAIN for an "A" query to "use-application-dns.net" with an empty zone. If they're explicitly looking for NXDOMAIN then blocking DOH behavior with Windows DNS servers probably isn't going to work. >sigh<
What’s Next in Making Encrypted DNS-over-HTTPS the Default
51–60 of 191 posts
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#52There's a lot of negativity here. But this is a win overall for privacy. DNS is used by ISPs to sell user's data and is one way that oppressive regimes track what their users do. If you're technical enough to understand DNS then you are smart enough to change what the default is. If you're a system administrator for a company. You should be able to push a profile down to the user's computer to configure DNS how you w…
Not if one trusts more his/her ISP more than Cloudflare. At least, an ISP is a contractual partner and under the same jurisdiction, in Europe including GDPR.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#53I guess a more long term solution is to have a local proxy dns-to-doh, but we are falling back in the solution that only a technical user can setup :
https://developers.cloudflare.com/1.1.1.1/dns-over-https/clo...
https://facebookexperimental.github.io/doh-proxy/
And it means setting up firewall routing and filters, as some softwares don't have settings to add DNS proxy, or even bypass them (Google Chrome for example)
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#54It's scary that Moz sides with monopolies like Google and Cloudflare on this one.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#55Earlier quoted context omitted.
Not if one trusts more his/her ISP more than Cloudflare. At least, an ISP is a contractual partner and under the same jurisdiction, in Europe including GDPR.
Or if you run your own resolver and don't want a completely unrelated third party like Cloudflare siphoning your traffic.
This will just allow all applications and appliances to bypass my privacy measures.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#56Earlier quoted context omitted.
That's exactly what their plan is -- and if you have experiments enabled, they may have already started sending your DNS queries to Cloudflare.
I guess thats Mozillas new monetizing strategy, sell user data to cloudflare, and market it as privacy. If you want privacy you better firewall everything your computer want to send to Cloudflare, Akamai, et.al.
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#57In systemd there is currently only DNS over TLS and there is a security issue open about that. Also not sure if there forced setting has made it into stable.
What I want to do it just a easy setting to set up up on my Linux (And windows gaming partition) and never think about it again.
And for those concerned about selling data to Google or CF, just use some of the privacy organizations servers for it!
Re: What’s Next in Making Encrypted DNS-over-HTTPS the Default
#58Is there anything in DoH mitigating this? Or maybe is this attack vector negligible in practice because most servers typically host multiple websites? At least this adds plausible deniability in a wide range of situations I guess. But is it really true? And for example, would it really help in a country where a website like Facebook is censored? (Since their IP addresses are dedicated).