Live data from Hacker News

Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

arstechnica.com

61–70 of 211 posts

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#61
post #42

Earlier quoted context omitted.

> malware can use DoH to retrieve data without logging suspicious DNS queries on Firewall DNS logs Malware can already query IPs of its choice to learn about other IPs it should contact. DoH doesn't let it do anything new.

In a corporate network, it's pretty common to block all outgoing DNS traffic (53/TCP and 53/UDP), except from the company's DNS servers. In that case, DoH does let malware do something new -- block the company's existing DNS policies, quert logging, and security monitoring!

DoH is a protocol for using HTTPS to learn what IPs to talk to.

Malware does not need DoH to do this. They can simply run an ordinary HTTPS server with a self-signed cert on an arbitrary IP, with a simple JSON-based or whatever protocol, and have support for that in their client.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#62

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

Comcast has had a pretty poor track record w/r/t their statements of what they do or don't do versus reality, and this goes back well over a decade (see: denials of Sandvine deployment).

I personally was impacted by this behavior after having my internet service deactivated due to going over bandwidth caps (which reportedly didn't yet exist) and it was one of the most Kafka-esque corporate experiences in my life. My internet was being deactivated because I violated a policy which they repeatedly stated didn't exist. Several months later those caps actually became policy.

I ask this with all sincerity: why should we believe Comcast?

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#63

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

> Actually not only does Comcast say they don't do that...

Just like they said they didn't forcibly reset BitTorrent connections (until they did).

Just like they said they didn't silently institute bandwidth caps (until they did).

Just like they said they didn't hijack NXDOMAIN responses (until they did).

Just like they said they didn't intercept plain-text HTTP connections and inject their own traffic into them (until they did).

---

With all due respect, I have personally had contracts with Comcast in the past and have experienced firsthand how well they honor those -- and I am certainly not the only one!

Surely you can understand why, to me and many others, their little agreement with Mozilla doesn't really mean a damn thing?

---

(I know that none of this is your fault and it's obviously nothing personal! I'm sure you're a smart, decent person but I'm also sure that you are well aware of your employer's reputation, their past "misdeeds", and, of course, the generally unfavorable opinion that many, many customers have of them.)

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#64
post #50

> "Adding ISPs in the TRR program paves the way for providing customers with the security of trusted DNS resolution, while also offering the benefits of a resolver provided by their ISP such as parental control services and better optimized, localized results," the announcement said. What? No! Why would DNS have "optimized, localized results"?

> Why would DNS have "optimized, localized results"? Any content that is CDN-based (which is most content) dynamically responds to DNS queries based on network and geographic location - to support CDN localization. In this way, Akamai for example knows the end user is in Boston on a Comcast network and will send the recursive DNS server a dynamic response that points to a directly-connected local-to-Boston content se…

oh, I didn't know that. thanks!!

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#65

Let me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Com…

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

That’s great that they’ve said they don’t publicly and that they’re now going to be contractually obligated not to... but that’s kind of irrelevant if they are actually sniffing, tracking, and/or recording user DNS traffic.

And the fact that Comcast doesn’t allow users to change the DNS settings of xfinity routers leads me to believe they have some monetary incentive to go in and disable that functionality in their equipment.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#66
post #40

I don't know how we can have privacy and Comcast in one sentence. We have a saying where I come from that translates roughly to "Putting the Wolf to Guard the Sheep". If you don't have any other option but to be with comcast my recommendation is to run Pi-Hole + DoH.

I do run PiHole. Any tips on how to do the `DoH` side of the equation?

edit: this looks to do the trick: https://docs.pi-hole.net/guides/dns-over-https/

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#67

Earlier quoted context omitted.

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

If Comcast sells DNS data now, they open themselves up to penalties from the both FTC and Mozilla. FTC because they enforce privacy policies, and Mozilla because of the contract they have. I would say this Mozilla changing the overall ecosystem for the better.

Do we know what the actual penalties are? I have trouble believing that they are of any substance.

Additionally, I think it's safe to say that Comcast has years and years of experience in finding "loopholes" and/or other "workarounds" in its agreements.

> I would say this Mozilla changing the overall ecosystem for the better.

You obviously have much more faith in Comcast than I do. Let's hope you're right.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#68

Earlier quoted context omitted.

> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that ( https://www.xfinity.com/privacy/policy/dns ) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong p…

If Comcast sells DNS data now, they open themselves up to penalties from the both FTC and Mozilla. FTC because they enforce privacy policies, and Mozilla because of the contract they have. I would say this Mozilla changing the overall ecosystem for the better.

The FTC has no teeth and no one at Comcast is losing any sleep over potential FTC penalties. Ajit Pai is more likely encourage meaningful enforcement of this agreement than anyone at the FTC. Which is to say, I don’t have much faith.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#69

How does FF know my DNS is a Comcast-provided one? Is there an IP list kept inside of browsers and updated?

Comcast's ASNs and networks are documented in ARIN's WHOIS database and various route registries. Hell, Comcast probably publishes a list on their own web site. So, yeah, Mozilla can easily determine if a user is on the Comcast network just from their IP address. Also, while Comcast actually has a bunch of DNS servers spread across the country, I believe that nowadays they're mostly "promoting" the use of 75.75.75.75…

> So, yeah, Mozilla can easily determine if a user is on the Comcast network just from their IP address.

I mean, how can the determine it's a Comcast DNS server configured on my network? I might be a Comcast customer w/ a custom DNS server configured. If it's a fixed IP check, I suppose that list is in the browser.

Re: Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox

#70
post #47

Earlier quoted context omitted.

I hit commit on that feature. Sorry. It's not just Comcast. Every ISP that uses Akamai's software to power their ISP has this ability and possibly uses it, just not in obvious ways. And given that almost every ISP in the US, let alone the world, uses this software, well.. that's just how it is. Though, it's http only. You can always switch to https and they can not do anything. There is no key injection or anything g…

How would encrypting DNS help me avoid Comcast MITMing my HTTP traffic to inject bandwidth cap notifications? Doesn't the system just inject a script tag into the appropriate place in the HTTP response?

HTTPS Everywhere + encrypted DNS blocks a huge chunk of what they can see without expending effort on you in particular
Post reply on HN