Live data from Hacker News

Improving DNS Privacy with Oblivious DoH

blog.cloudflare.com

61–70 of 367 posts

Re: Improving DNS Privacy with Oblivious DoH

#61

Until we get rid of SNI[1] in HTTPS for good there will still be providers (like my ISP) that do deep packet inspection on SNI and kill the connection right away if you happen to visit a forbidden site (and this was western Europe, yesterday, on a site behind CloudFlare) [1] https://en.m.wikipedia.org/wiki/Server_Name_Indication

You can bypass SNI inspection [0] with tools like GreenTunnel [1] and Intra [2]. [0] https://twitter.com/vinifortuna/status/1304189371688660992 [1] https://news.ycombinator.com/item?id=22654737 [2] https://getintra.org/

I can't find any source on intra working to prevent SNI sniffing. The page itself only mentions DNS, and Googling doesn't reveal any other source for that.

E: NVM, found it. It does like it uses split hellos.

Re: Improving DNS Privacy with Oblivious DoH

#62
post #36
post #3

Probably better source, the blog post at Cloudflare: https://blog.cloudflare.com/oblivious-dns/ See also: https://news.ycombinator.com/item?id=25344220

Thanks. The original post redirects to: https://guce.advertising.com/collectIdentifiers?sessionId=3_... Which is blocked at the DNS level on my network.

As it should be.

Re: Improving DNS Privacy with Oblivious DoH

#63

> Sullivan said a few partner organizations are already running proxies, allowing for early adopters to begin using the technology through Cloudflare’s existing 1.1.1.1 DNS resolver. In other words, in order to thwart efforts to make the internet anonymous , US companies are planning to takeover DNS for the vast majority of people.

Oh, please. ODoH is a proposed standard. Use whatever the hell proxy/resolver you feel like, wherever you like. DNS is a shit show of unencrypted data flying around being scooped up by God-knows-who and along comes someone proposing a standard to fix said shit show and this is the response people get.

Decentralized spying > centralized spying

Re: Improving DNS Privacy with Oblivious DoH

#64

Opened this post expecting to be hating on another power grab dressed up as protocol engineering, but this one seems to actively /reduce/ the centralization of user data collection in DoH. Props to Cloudflare, I'm impressed.

I still have doubts, 1.1.1.1 was a clear power grab and effort to control more of the internet. DoH in partnership with Mozilla was an extension of that

So I am still suspect of their motives but maybe the negative PR got to be too much

Re: Improving DNS Privacy with Oblivious DoH

#65
post #55

Whats the point? Governments subpoena the information or just block the protocol outright. ( or in China, get it delivered to their door by Apple ) Commercial parties have a bag full of tricks from fingerprinting to embeds on the page itself to track you. Privacy seeking users are already tunneling their traffic. That leaves script kiddies at Internet cafes. TLS kind of fixed that already so... Good work?

You, the proxy, and the DNS service, can be in 3 different countries. It's not bullet proof but makes it quite hard for a single government. Unless you are a Bond villain I think this is more than you need.

If you need more than that use ToR or similar.

Re: Improving DNS Privacy with Oblivious DoH

#66
post #61

Earlier quoted context omitted.

You can bypass SNI inspection [0] with tools like GreenTunnel [1] and Intra [2]. [0] https://twitter.com/vinifortuna/status/1304189371688660992 [1] https://news.ycombinator.com/item?id=22654737 [2] https://getintra.org/

I can't find any source on intra working to prevent SNI sniffing. The page itself only mentions DNS, and Googling doesn't reveal any other source for that. E: NVM, found it. It does like it uses split hellos.

[deleted]

Re: Improving DNS Privacy with Oblivious DoH

#67

Until we get rid of SNI[1] in HTTPS for good there will still be providers (like my ISP) that do deep packet inspection on SNI and kill the connection right away if you happen to visit a forbidden site (and this was western Europe, yesterday, on a site behind CloudFlare) [1] https://en.m.wikipedia.org/wiki/Server_Name_Indication

Part of the counter-argument that has been so prevalent on HN (most recently: [0]) is that when you prevent middlemen on your network from being able to see what website you're browsing, you're doing exactly that: preventing anyone, even a trusted network administrator, from being able to inspect traffic. I'm all for DoH and ECH since US ISPs have a history of inspecting and logging traffic, but it seems like there should be a way to manage the devices on your network besides being forced to set up MDM on everything.

0: https://news.ycombinator.com/item?id=25314182

Re: Improving DNS Privacy with Oblivious DoH

#68

Opened this post expecting to be hating on another power grab dressed up as protocol engineering, but this one seems to actively /reduce/ the centralization of user data collection in DoH. Props to Cloudflare, I'm impressed.

I would like someone to correct me if I am wrong, but I think we can never have 100% privacy because the destination IPs cannot be encrypted or hidden, so as long as the destination IP can be observed, the server that you are connecting at can be obtained (I know a server can host many web pages, but this requires the port, which cannot be encrypted either).

So I don't know to what extent this protocol can be useful.

Re: Improving DNS Privacy with Oblivious DoH

#69

Opened this post expecting to be hating on another power grab dressed up as protocol engineering, but this one seems to actively /reduce/ the centralization of user data collection in DoH. Props to Cloudflare, I'm impressed.

All I see is a proxy service and a way for cloudflare to get access to the data

Re: Improving DNS Privacy with Oblivious DoH

#70
post #20

Earlier quoted context omitted.

Do you have actual proof of this or are you just going to make misleading claims yourself?

Privacy is a buzzword to boost sales even more. Perhaps the biggest problem with Apple is its nasty monopoly strategies, remember the times you could easily add more RAM, change batteries?

This buzzword is actually useful though. It gave us ESNI, Cambridge Analytica, antimonopoly memes and whatnot.
Post reply on HN