Live data from Hacker News

Turn off DoH, Firefox

ungleich.ch

61–70 of 422 posts

Re: Turn off DoH, Firefox

#61
post #49
post #36

Earlier quoted context omitted.

> if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). I don't think anyone believes CF will start selling data, that's not what the article argues. Regardless, it's opt-out not opt-in. Which is agains…

> I don't think anyone believes CF will start selling data, that's not what the article argues. > Regardless, it's opt-out not opt-in. Which is against newer consumer protection laws such as GDPR. I understand the argument in theory.. but the reality is CF is a more trustworthy DNS provider than basically any consumer ISP in the EU.

This is where me and the author disagree with you. In most places in Europe there is a complete distrust of US companies and hosting anything on US soil.

Historically we've seen many cases of US companies handing over data to US authorities (willingly or not).

Re: Turn off DoH, Firefox

#62
post #17
post #9

Earlier quoted context omitted.

I do trust my ISP and my government more than I trust CloudFlare.

It seems very American to me to trust a private actor such as CouldFlare more than your own government. I feel like at least in Europe, a large majority of people would trust their government and local ISP much more than some company halfway over the world with basically no accountancy in your own country, especially an American one since it means your data is basically at the mercy of the US government.

Aren't there a bunch of European ISPs applying government enforced DNS blocking?

Seems like this is a very good move for them.

Re: Turn off DoH, Firefox

#63
post #9
post #3

Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS

I do trust my ISP and my government more than I trust CloudFlare.

Couldn't agree more.

And I very much hope they aren't contemplating rolling this out in Europe.

Having worked for a major European telco, I get the impression that the amount of regulation they face around data protection and privacy is tremendous and my experience has been that this stuff is by no means taken lightly either.

It would never in a million years occur to me to route my traffic in such a way as to circumvent the legal protections it enjoys as long as it stays within a European ISP's network and instead encrypt it and send it off to a nearly unregulated entity in a foreign country.

Re: Turn off DoH, Firefox

#64
post #4

Earlier quoted context omitted.

Many ISPs won't offer such thing https://www.zdnet.com/article/uk-isp-group-names-mozilla-int...

> claimed that Mozilla plans to support DNS-over-HTTPS "in such a way as to bypass UK filtering obligations and parental controls, undermining internet safety standards in the UK." > By planning to support DNS-over-HTTPS, Mozilla is throwing a monkey wrench in many ISPs' ability to sniff on customers' traffic and filter traffic for government-mandated "bad sites." But I don't see why they can't offer their DoH, it se…

because most people don't know they can easily bypass the DNS based filters that is used to block "bad sites". DoH by default uses cloudflare's DNS, and so won't (need to) comply with the UK's filter laws.

Re: Turn off DoH, Firefox

#65
post #36

Earlier quoted context omitted.

> if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). I don't think anyone believes CF will start selling data, that's not what the article argues. Regardless, it's opt-out not opt-in. Which is agains…

> I don't think anyone believes CF will start selling data, that's not what the article argues. CF is not a private company funded by a foundation with a time until the funding runs out measured in 30-40 years. It is a public company with a small number of customers that provide majority of its revenue. It simply isn't prudent to say that it won't explore other revenue streams in future and that monetization of data…

Good point. I meant there is no reason to dispute the article because it talks about CF monetizing that data. Because it doesn't.

Re: Turn off DoH, Firefox

#66
post #29

Earlier quoted context omitted.

> I trust my ISP and government more than a US company I have no formal contract with and the US government. And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something b…

There aren't many intermediaries if you use your ISP's internal resolvers.

And there are intermediaries between Cloudflare/other DoH providers and the respective authoritative nameservers anyway.

Re: Turn off DoH, Firefox

#67
post #60

My understanding is that the DNS query goes to the closest of the more than 180 Cloudflare servers, not specifically to the US servers. Complete FUD.

The point is that Cloudflare is a US company. From that perspective, where their servers are located is irrelevant.

Re: Turn off DoH, Firefox

#68
post #23

This misses the forest for the trees. In the UK ISPs are already legally mandated to log your web requests and provide them to the government. Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications. The fact that cloudflare is a US entity and thus not subject to UK law is the whole point.

> Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications

And those who live under oppresive governments should not be an excuse to force those who don't to have their traffic routed through a property of an oppressive government.

Yes, I know it's not about to be a default for non-US users yet. But "The UK people are getting screwed" is not a very good argument for "everyone should be getting screwed by the US".

Re: Turn off DoH, Firefox

#69
post #34

This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…

> There has to be SOME default chosen It seems trivial to select a half a dozen likely candidates and let the user choose between them on install. Honestly I'd like them to do the same with the search engine. Yes, it's simple enough to change the default, but it'd be nice to choose up-front.

But Cloudflare also happen to be the fastest DNS resolver.

Re: Turn off DoH, Firefox

#70
post #58

There are two points: 1. centralization of all dns lookups is worrisome 2. Dns should not be handled by applications. It should be handled by the operating system. I see a lot of people conflating the two in the comments.

> 2. Dns should not be handled by applications. It should be handled by the operating system. I agree with #1 but why it should be managed by the OS?

No one wants a proliferation of different applications which all have different settings to access the network, especially when the OS provides centralised functionality to do so.
Post reply on HN