Live data from Hacker News

Firefox 143 for Android to introduce DoH

blog.mozilla.org

81–90 of 121 posts

Re: Firefox 143 for Android to introduce DoH

#81
post #53

Does anyone know how to force disable DoH on a network? In https://support.mozilla.org/en-US/kb/canary-domain-use-appli... it says that the canary domain does not apply for users who have made the choice to turn on DoH by themselves. I want to avoid running an sslproxy, and it seems an application level proxy on the firewalls is necessary.

It should be possible to have a firewall rule to default deny outgoing connections and a DNS resolver that tells the firewall to allow a connection only after it has resolved it, but I don't know that there's anything off-the-shelf to do this yet. I imagine DoH providers are also either using known SNIs or ESNI, so you could block both of those.

The former approach is where we need to go with security IMO. If you don't have some auditability for why a computer on your network is making an outgoing connection (and ability to inspect/refuse it before it happens), then it should just be blocked. There's no reason for computers you own to reach out to random IPs you don't understand and can't inspect at your gateway. Most computing devices are preloaded with malware these days and need to be treated as untrustworthy by default.

Re: Firefox 143 for Android to introduce DoH

#82
post #33

>DNS query [...] in the clear. [...] (DoH) plugs this privacy leak [...] no one on the network, not your internet service provider [...] can eavesdrop on your browsing Whoever could see DNS traffic can still see the target you're connecting to...

Correct - that would be visible via ClientHello. But Firefox also enabled ECH (when DoH is enabled) a while back - https://support.mozilla.org/en-US/kb/faq-encrypted-client-he... .

also this: https://support.mozilla.org/en-US/kb/firefox-dns-over-https#...

Re: Firefox 143 for Android to introduce DoH

#83

Not sure why it took so long for Mozilla to expose the setting on Android, it's been a 'secret' setting for a long time. In fact, sometimes they let features ride the rails for a little bit too long IMO. For Waterfox for Android I exposed the setting by default and also added an addition DNS over Oblivious HTTP setting (DoOH) which uses Fastly as the relay (they host and control it, for privacy sanitisation) and Clou…

It's been accessible via about:config, yes.

But more importantly, there's a system wide DoH setting in Android (or at least in GrapheneOS). I don't see why it would preferable to only configure DoH in the browser.

Re: Firefox 143 for Android to introduce DoH

#84

Earlier quoted context omitted.

For those wanting a bit of privacy, you can run your own DOH server[0]. Be aware that the upstream requests can still be tracked, but additional safety steps can be taken such as hosting your own dns resolver (bind/powerdns), sending dns/doh queries over a vpn or tor connection, or spanning queries over multiple sources. Each has its own security and privacy implications, which is beyond the scope of this comment :)…

Running your own DOH server comes with it's own set of risks, depending on your adversary. If you're the only person using a DOH server, then any requests that server make must belong to you. I'd argue that it's better to use a public server and hide in between the other users.

My main issue with DOH is failing to honor my internal DNS overrides to provide local addresses for services on my local network (externally the DNS entries point to the external address but internally the LAN address) It is so annoying fighting against DOH for this

Re: Firefox 143 for Android to introduce DoH

#85
DoH is a technical win but a practical regression for anyone who actually runs their own DNS. With classic DNS, you could hand out your resolver via DHCP and transparently control local zones. With DoH, that's gone. You have to configure each client explicitly, because the traffic is wrapped in HTTPS and can't be intercepted.

And the defaults don't help: instead of your ISP seeing your queries, now it's Cloudflare, Google, or whichever big player your browser hardcodes. That's not decentralization, it's centralization under a shinier marketing story.

Encryption is good, censorship resistance is good, but the rollout conveniently shifts power away from users and toward a handful of global DNS silos. For technical folks, it feels less like progress and more like lock-in with extra steps.

Re: Firefox 143 for Android to introduce DoH

#86
post #8

Earlier quoted context omitted.

Mullvad runs a privacy-oriented DoH service, which is free to use regardless of whether you use their VPN service. https://mullvad.net/en/help/dns-over-https-and-dns-over-tls

Mullvad DoH is great, and things like ad-blocking seems to be more effective on Mullvad. But, and its a BIG BUT .... Mullvad don't have the geo-coverage that Quad9 has. They are predominantly Northern Europe with very limited server coverage outside (6x Northern Europe, 2xUSA, 1xSingapore) Which is fine if you spend most of your time in those three places. But if you are a road-warrior or you live elsewhere, then Qua…

> Avoid Cloudflare. They log traffic.

That sounds like a GDPR violation if the logs include PII like IPs and if it's not opt-in. Is that really the case?

Re: Firefox 143 for Android to introduce DoH

#87
post #86

Earlier quoted context omitted.

Mullvad DoH is great, and things like ad-blocking seems to be more effective on Mullvad. But, and its a BIG BUT .... Mullvad don't have the geo-coverage that Quad9 has. They are predominantly Northern Europe with very limited server coverage outside (6x Northern Europe, 2xUSA, 1xSingapore) Which is fine if you spend most of your time in those three places. But if you are a road-warrior or you live elsewhere, then Qua…

> Avoid Cloudflare. They log traffic. That sounds like a GDPR violation if the logs include PII like IPs and if it's not opt-in. Is that really the case?

> That sounds like a GDPR violation if the logs include PII like IPs and if it's not opt-in. Is that really the case?

Cloudflare retain what they call "limited transaction and debug log data" for 25 hours.

Cloudflare state that IPs are truncated and the truncated IPs are deleted after 25 hours BUT for "randomly sampled network packets" they will retain the full IP for "network troubleshooting purposes".

Even so, as we know, a truncated IP can still be used to track and trace people ...

Compare and contrast to Quad9 who explicitly consider IP addresses as GDPR PII ("Quad9 regards Internet Protocol ("IP") addresses associated with its users to be Personally Identifiable Information ("PII")")

Quad9 states IPs are only ever in RAM "for the few microseconds to milliseconds necessary to service the user's query"

They also state "Quad9 does not collect or record IP addresses, nor does it collect or hold any proxy for or representation of IP addresses, nor does it collect or hold any other unique identifier of individuals in lieu of IP addresses."

Which is why I said Quad9 have a much better privacy policy.

Re: Firefox 143 for Android to introduce DoH

#88

Earlier quoted context omitted.

Kind of wish brand new accounts would get auto-banned if they get comments flagged within a certain timeframe of their creation.

And I wish people wouldn't flag a post because they disagree with it, rather than because it violates the rules.

Yes I agree with that, but most flagged comments I catch usually are pretty blatant violations of the comment guidelines.

It does happen often enough that I kind of wish there was negative flagging weight applied to abusers.

Re: Firefox 143 for Android to introduce DoH

#89
post #70

Single-handedly, Firefox (independently from how crappy it can be at times) is what is keeping me on Android. Its full extension support (i.e.: uBlock Origin support) is something that I can't really do without. I do wonder if the crowd here knows of other good alternatives though - specifically, Android and/or iOS browsers with "full" uBlock Origin support (no uBlock origin lite, no other blocker, ...). I would love…

Try lemur browser, it has extension support.
Post reply on HN