Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

721–730 of 777 posts

Re: Mozilla’s DNS over HTTPs

#721

Earlier quoted context omitted.

DoH doesn't need to provide extra privacy to make sense (although it is a mandatory stepping stone to good privacy). It also provides a difficult to block security upgrade (as opposed to DoT, which is easy to block). We've seen regular US ISPs hijack unencrypted DNS to insert content or replace sites entirely. We've also seen bad actors do far worse on public WiFi. So acting like DoH is a waste of time unless every p…

Except, not really. If you're worried about DNS tampering, DNSSEC already exists all the way up to the root servers. If you're worried about ISPs snooping on what sites you visit, they'll continue to be able to do this even with widespread DoH/DoT and ESNI adoption. You still need to connect to an IP and TLS certs still have unique serials (most of which appear on public CT logs). Correlated over a large user populat…

> TLS certs still have unique serials

In TLS 1.3 everything sent by the server, including its certificate, is encrypted.

This is possible because of a re-ordering of considerations. It used to be that the conversation starts like this:

Client: "Hi, I want to talk to Server?"

Server: "Here's a certificate for Server, which is me"

Client: [ "Secret is 123456" encrypted using the Public Key from the certificate for Server ]

Server: [ "See, it's me" encrypted using the secret 123456 ]

But in TLS 1.3 it starts like this:

Client: "Hi, I want to talk to Server and I used ECDHE to pick this number 123"

Server: "I used ECDHE and I picked 456..." [ "I am Server, here's a Certificate for Server, and here's a signature proving the conversation we're having right now is with me, Server, which you can verify using the Public Key in that Certificate" encrypted using the secret 987654 ]

ECDHE allows Client and Server to agree the secret key 987654 even though the information they publish to agree on it (123 and 456) is public for anyone to see. Its predecessor Diffie Hellman is easier to understand if you never got past high school mathematics, so research that if you've never seen this trick before.

You'll notice this is also less round trips (so better performance over high latency links) as well as being more secure and more future-proof.

Re: Mozilla’s DNS over HTTPs

#722

Earlier quoted context omitted.

If I sit any family member down in front of this comment, their eyes would glaze over. Not only is what you mention a PITA, it's impossible for most people.

I'm a programmer and I have no idea what OPs comment means. I keep meaning to learn about networking stuff, but there is always so many other things to learn and since I don't work with devops or networking stuff it hasn't really been a priority.

You're not alone. That said, I highly recommend reading and referencing "High Performance Browser Networking" by Ilya Grigorik^1, it's accessible, detailed, accurate, and useful in the extreme.

1 https://hpbn.co/

Re: Mozilla’s DNS over HTTPs

#723
post #417

Earlier quoted context omitted.

> If you use the nextdns DoH provider in Firefox you can actually configure your own adblocking domains even when you're moving around across networks. Uh. Doesn't this prove that Firefox's DOH implementation is sending strong per-user identifying information to the server?

If you configure a personal NextDNS URL as the DoH provider then unsurprisingly NextDNS will know that URL was used, and personalise things accordingly. If you use Firefox's defaults but pick NextDNS from the list, you don't get personalisation as NextDNS has no idea who you are. A nice thing about DoH here: For DNS over TLS NextDNS has to hide the configuration ID in the hostname, which as a result is revealed in SN…

> ...for DoH they can put it in the path and so it is encrypted like everything else.

Wait: You mean to say URLs are encrypted? I thought not. There must be a reason why GET requests aren't used for secret-sharing, for instance, as opposed to POST. What am I missing?

Re: Mozilla’s DNS over HTTPs

#724
post #285

Earlier quoted context omitted.

> ...it is a PITA, especially when roamining and you want to resolve hostnames available only in local networks. Not really. If you're not blackholing traffic at the dns-layer via DoH, set Firefox's trr.mode to 2 . Per documentation, at the cost of additional latency incurred, system-level / network-level resolvers should pick up the slack, provided they've been set as appropriate via DHCP or otherwise. Ref: https://…

Considering the amount of people using library or Starbucks internet that needs you to use the local DNS (at least once you initially connect), maybe #2 should be the default? Or is there some risk in doing so?

If your OS doesn’t already detect the captive portal, Firefox will.

Re: Mozilla’s DNS over HTTPs

#725
post #687

Earlier quoted context omitted.

If the ISP (or Nation) is willing to block google or cloudflare IP-ranges then you will have to be a moving target. Using tor and similar. For normal shitty ISPs thats not an option

Cloudflare and Google's dns resolvers got a lot of adoption bc they provided a way for normal people to get around censorship, but they're inherently censorable bc they're run by centralized companies. There are new initiatives aiming to create a distributed dns layer which are promising like https://handshake.org .

And the distributed DNS layer will get censored soon enough if it gets traction. If you need proof, look at how TOR is doing in china.

Re: Mozilla’s DNS over HTTPs

#726
post #437

Earlier quoted context omitted.

99 % of users won’t touch default values, so it’s not a valid excuse. I really have come to the conclusion that privacy is just a marketing feature for Mozilla. They e.g. also do nothing against data exfiltration by popular extensions although they have known that issue for years. If they’re really serious about privacy they should have waited to implement DoH as an open standard and allow more DNS providers to suppo…

DoH is an open standard. DoH is also better for the 99% of users who don’t care about DNS resolvers and use their standard, shoddy and privacy invasive ISP provided one.

My ISP has to obey the rules of my government, and it is not allowed to sell my data. It's in my country, with my regulatory bodies and close enough that I (or a group of people like me) can sue them, if they start doing bad things.

What the hell am I supposed to do again cloudflare?

Re: Mozilla’s DNS over HTTPs

#727
post #478
post #289

I'm so sad to see Mozilla move forward with this massive attack on user privacy. Firefox DoH is snake oil, plain and simple. It sends all the users DNS queries to Cloudflare, adding a new party which can surveil the user's traffic (and can be legally compelled to do so and not disclose this fact)-- providing a convenient choke point to save spies and hackers the trouble and exposure of extracting the data from tens o…

> It sends all the users DNS queries to Cloudflare, adding a new party it removes many parties (some unknown) who have no legal oversight, and adds a select parties who are legally bound to respect your privacy. > because the user's destination IPs remain unencrypted This makes no sense. your ISP cannot see that you are visiting facebook because the IP shows up us cloudflare urrrghhh! > At the moment you can disable…

My ISP is legally bound to respect my privacy. I have regulatory bodies literally 10 minutes away, that can deal with tham, and a court system where I (and many more like me) can sue the ISP if they do something bad.

What can I, citizen of small EU country, with an en_US firefox, do against cloudflare?

Re: Mozilla’s DNS over HTTPs

#728

Earlier quoted context omitted.

Sure in that case makes sense to use VPN. > I predict there will be plenty of privacy respecting services to choose from. Why, where is the money in there ? Sure there might be some, but many ? Call me cynic but I don't think google(one of the biggest public DNS servers atm) or clodflare(probably second biggest) are providing this service out of goodness of their harts. If you worry about DNS that much, running your…

I don't know why Google and Cloudflare provide this service and I don't really care, because it's irrelevant. DoH is first of all a protocol. If you run your own DNS resolver at home, surely you'll be able to run your own DoH server too. Also your requests will no longer be sent in clear text, which means that a Wifi administrator at your local coffee shop won't be able to see your queries and responses, which with t…

> Personally, coming from communism, I fear the nanny state more than I fear big companies from other countries.

I am from Slovenia and I know exactly what you mean, and agree 100% with that.

I just think that in the end POE is worse, since I think it will result in concentration of something that was widespread (plenty of small ISP's and providers), into few bigger and easier to backdoor providers. So it will be easier to monitor then before. And I don't think think that western democracies and "democracies" will just throw in their towel.

I trust Cloudlfare and Google less than I trust my ISP, if nothing else their budget (and competence, and reach) is much lower(isp's).

I mean gmail and outlook are much more competently run than most ISP's and businesses ran their mail servers. I am afraid something similar can happen here.

> DoH is first of all a protocol. If you run your own DNS resolver at home, surely you'll be able to run your own DoH server too.

Packets never leave local network. The advantage of DoH is that it's over https, so if you don't control your firewall you can still use it. But if you control your own network, DoH is not that useful, since you still have to support old DNS for all the applications and devices that don't support DOH. If someone can listen on your LAN you have bigger problems than someone being able to intercept your DNS queries. Not saying there are no advantages, it just isn't a priority.

Re: Mozilla’s DNS over HTTPs

#729

Earlier quoted context omitted.

I think China has demonstrated that countries are willing to do that.

China is a special case though. They're large enough to populate their own internet with things. Most countries aren't that large.

China was a special case. There are smaller countries seeking to do the exact same thing now. Russia, for example.

Re: Mozilla’s DNS over HTTPs

#730

Earlier quoted context omitted.

Maybe you're new to the tech/security space, but the majority of companies operate at a loss as they grow and pivot their business. If you follow Cloudflare they've only recently begun to start to sell into the enterprise space with new products as in the SASE space and beyond their traditional DDoS/WAF/encryption plays. Even with those "legacy" products - Cloudflare never heavily sold into large enterprise compared…

No, it clearly says that if they haven't figured out a business model yet, the business model they will end up figuring out might just as well be selling your data, so it's maybe not wise to make the internet depend on them not doing so.

Let's be clear here...

The Internet is not dependent on Cloudflare now, or in the future. While FireFox has made a choice (a polarized one), the end user still has the freedom to completely disable DoH and CloudFlare - or choose whatever other service they'd like to use.

Mozilla has an agreement with Cloudflare. Again, it is in Cloudflare's best interest to not break that agreement. If they do, then we can all have that conversation. But just because they could break the agreement does not mean we should jump to any conclusion that they are currently.

It's odd to me that there are a lot of defenders of the status quo that is DNS. Something that is easy to manipulate, easy to profile and scrape passively on the wire (no need to even ask if nobody knows you're doing it), and is generally (with regard to security models) less secure than DoH.

Could Cloudflare nefariously start NXDOMAINing everything? Sure. So could your current ISP (it's likely they already are or already have). Cloudflare hasn't done that. While I have some reservations on the 3 letter agency involvement, that is my only unfounded reservation at this point. Until someone exposes, factually, that Cloudflare has considered selling users data, is selling users data, is planning on monetizing data collected around DNS, etc. I, personally, feel that Cloudflare is offering up a good service. They do allow APNIC to see DNS query data, but not source IP info (go read their privacy policy I linked in this thread).

The Internet has inherent underpinnings of trust. You have to trust your ISP to not MitM your traffic. You have to trust someone to resolve your DNS without manipulation. You have to trust websites to not sell your data back to Facebook, Google, Microsoft, etc. It seems as though DNS data hand waving with regard to Cloudflare is only a fraction of what we should really be concerned about. Do you really want your DNS traffic to continue to be unencrypted? DNS has always been centrally controlled. We have the ease with which we can distribute our DNS queries across multiple providers to not give insight to everything we do all the time. But at the end of the day we have to ask someone where Google is. DNS is the problem, not DoH - at least in my opinion.

You have to trust someone. Cloudflare has done a good job of being a good steward as I see it so far. I'm not saying anyone should trust them blindly or forever by default. But - who do you trust? Who is so free from monetary gain that they should be the single source of truth for all of your DNS queries? Who? I don't see anyone on the playing field that isn't selling something. They're either selling you access to the Internet, or they're selling ads, or they're building up a social graph of you by giving you access to free services.

The Internet is built on trust and that give and take.

Post reply on HN