Live data from Hacker News

NextDNS Joins Firefox’s Trusted Recursive Resolver

blog.mozilla.org

51–60 of 146 posts

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#51

Earlier quoted context omitted.

"Protecting your kids" is often "we log everything and have complete visibility over how people are using our service, and we're willing to share a bit of that with parents to spy on their children". It's a valid concern to have unless there's evidence to the contrary.

I assume every single DNS provider is logging and, if possible, selling my data. Why wouldn't I? This is actually why I use my own DNS server and resolve against the root, like anyone else who cares about privacy ought to be doing. Still, if your goal is to block your kids' access to things, DNS is a good place to do it. Works across all your devices and doesn't require any install.

> This is actually why I use my own DNS server and resolve against the root, like anyone else who cares about privacy ought to be doing.

How do you prevent the ISP from logging those requests to the root?

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#52
post #46

Earlier quoted context omitted.

It's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.

Probably the ISP, since it already has a working business model unrelated to selling your DNS query data and doing so is probably illegal in several countries.

If you're in the US, read your ISP's privacy policy sometime: part of their business model involves selling the data about the sites you visit.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#53
post #44
post #36

Earlier quoted context omitted.

> circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental controls, etc. This is configurable via group policy.

Sure, if all the machines you care about are windows boxes managed with Active Directory. There are ways to configure it on linux and mac too by putting a json file in the firefox installation folder, but it is one more thing IT needs to worry about. I don't know of any IT professional that would be excited at the prospect of having to configure DNS for individual applications.

They can just configure their internal DNS server to return NXDOMAIN for use-application-dns.net, which is a canary domain that Firefox checks before using DoH: https://support.mozilla.org/en-US/kb/canary-domain-use-appli...

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#54
post #29

“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…

Also, the "back in control" language is interesting. It implies the author believes users were "in control" in the past.

The "putting users in control" phrasing is classic Mozilla doublespeak marketing; Mozilla wants you to think Firefox is the only web browser under your complete control, when a look at their bug tracker and their reaction to all the changes that users have vehemently opposed shows the complete opposite --- a small number of Mozilla employees are the ones making all the decisions. Maybe their interests align better with yours, but they are just as authoritarian-control-freaks as all the other big browser vendors (or indeed, it seems all software companies in general these days.)

DoH behaves like only tunneling DNS over a VPN, and I wouldn't mind Mozilla working on VPN software, but IMHO something like that should really be a separate product (and one that not only their browser can use --- like most other VPN clients in general.)

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#55
post #46

Earlier quoted context omitted.

It's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.

Probably the ISP, since it already has a working business model unrelated to selling your DNS query data and doing so is probably illegal in several countries.

The terms of the Trusted Recursive Resolver program explicitly disallow selling your DNS query data.

> Your DNS data can reveal a lot of sensitive information about you, and currently DNS providers aren’t subject to any limits on what they can do with that data; we want to change that. Our policy requires that your data will only be used for the purpose of operating the service, must not be retained for longer than 24 hours, and cannot be sold, shared, or licensed to other parties.

https://blog.mozilla.org/netpolicy/2019/12/09/trusted-recurs...

https://wiki.mozilla.org/Security/DOH-resolver-policy

(Disclosure: I work for Mozilla, but not on this)

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#56
post #42

Earlier quoted context omitted.

This is the wrong dichotomy and it's a false one perpetuated by Mozilla. Users can have end to end encrypted DNS and browsers shouldn't be hijacking it. To put it another way, you don't want the people who only care about eyeballs (Google, Mozilla, etc.) picking your DNS provider.

So disable DoH in Firefox, or change the provider? If you know enough to choose a DoH provider, the browser defaults are not very relevant, presumably.

That's great for the handful of people that read Hacker News and understand DNS, it's a trash solution for the rest of the world. Defaults matter because they are rarely changed.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#57
post #46

Earlier quoted context omitted.

It's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.

Probably the ISP, since it already has a working business model unrelated to selling your DNS query data and doing so is probably illegal in several countries.

Having a steady revenue stream has not stopped many companies from also selling user data. See: ads in Windows, smart TVs, cell carriers selling location data, etc. The list goes on... Why would ISPs be any different?

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#58
post #37
post #33

Earlier quoted context omitted.

I believe you are referencing possibly old data. I have a Chromecast. I also redirect all port 53 traffic (DNS) back through my own DNS server at the firewall level (does not go to Google DNS). It works perfectly fine wihtout directly using Google DNS. Yes, they do ignore the DNS set by DHCP, but that can be worked around.

AFAIKT, you can block Google DNS and all your Google Cast devices should fallback to DHCP assigned DNS.

This is accurate. I drop all of my google gadgets access to google DNS services and they use my local DNS.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#59
post #29

“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…

I could never think of why Mozilla and friends are so aggressively pushing DoH, but I think you nailed it when you pointed out they can tie a specific device's DNS requests to its other data.

I run Unbound and Pi-Hole to do my own recursive resolving. Like a normal wireless router doing all the DNS lookups for its DHCP clients, Mozilla has no idea which particular device on my network is accessing duckduckgo.com. Once each browser happily sends requests to Mozilla, then on to NextDNS, there's a whole lot more data suddenly available to commingle in a data lake... The efficacy of browser fingerprinting means they won't even need cookies to distinguish between devices in those HTTP headers.

As far as I know, good ol' Insight Communications (then Time Warner, now Spectrum) made money from selling me access to its high-speed internet service, and running ads on failed-to-find-your-website DNS hijacks. Heck, most of its money probably came from upselling people to buy bundled VoIP landlines and premium cable packages--whatever tiny slice of revenue came from those lookups surely pales in comparison to tens of thousands of unused phone subscriptions.

For all the commenters here who think that Google and the other major tech companies are somehow more trustworthy than your ISP? Yeah, I just can't agree with those opinions.

Edit: Less trustworthy should have been more trustworthy.

Re: NextDNS Joins Firefox’s Trusted Recursive Resolver

#60
post #29

“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of…

Also, the "back in control" language is interesting. It implies the author believes users were "in control" in the past. The "putting users in control" phrasing is classic Mozilla doublespeak marketing; Mozilla wants you to think Firefox is the only web browser under your complete control, when a look at their bug tracker and their reaction to all the changes that users have vehemently opposed shows the complete oppo…

I didn't fully understand the cognitive dissonance and Orwellian doublespeak going on in Mozilla until I began researching the jabs n-gate's author embeds into everything he writes concerning the company. Beacons, Google's Safe Browsing lists, etc.: None of those defaults line up the company's actions with its branding.

With Firefox 69, they broke 25% of the internet on Linux with a change to block what they call a MITM attack: Corporations and anti-virus software that add certificates to your computer to decrypt SSL traffic before passing it on to you. That's privacy-focused, I suppose?, but is a confusing change in comparison to more obvious victories such as blocking trackers and fingerprinters by default. Which they will certainly never do... until Google invents a technology that provides the same functionality with a different, less ominous name than "browser fingerprinting."

Post reply on HN