Earlier quoted context omitted.
> There has to be SOME default chosen It seems trivial to select a half a dozen likely candidates and let the user choose between them on install. Honestly I'd like them to do the same with the search engine. Yes, it's simple enough to change the default, but it'd be nice to choose up-front.
Yes, it's trivial. It's also very annoying to the probably 99% of users who don't care about it at all, especially if this becomes just one of many settings that needs to be configured on startup.
Turn off DoH, Firefox
91–100 of 422 posts
Re: Turn off DoH, Firefox
#92Earlier quoted context omitted.
ISPs have proven themselves untrustworthy repeatedly, CloudFlare yet really hasn't. Not that I like the control they have, but it's honestly the fault of ISP's this has happened.
some ISPs. The problem is that Mozilla is taking a very US-centric view of a product that is used worldwide.
Re: Turn off DoH, Firefox
#93My understanding is that the DNS query goes to the closest of the more than 180 Cloudflare servers, not specifically to the US servers. Complete FUD.
The point is that Cloudflare is a US company. From that perspective, where their servers are located is irrelevant.
Re: Turn off DoH, Firefox
#94This misses the forest for the trees. In the UK ISPs are already legally mandated to log your web requests and provide them to the government. Those who live under free regimes should not deny those of us who live under oppressive governments the right to privacy of our communications. The fact that cloudflare is a US entity and thus not subject to UK law is the whole point.
As a fellow citizen of a Five Eyes country, I assume that if any of those 5 have info about me that one of the other four wants it won't even be a question of paperwork for it to be shared.
Re: Turn off DoH, Firefox
#95Earlier quoted context omitted.
> the article deliberately buries that it's trivial to change your DoH provider While true for you or me, the vast majority of people will have this enabled by default - probably not even realising it's on
And? Those same people are likely using their ISP or Google for DNS right now. How is this worse?
That seems pretty shady to me
Re: Turn off DoH, Firefox
#96There are two points: 1. centralization of all dns lookups is worrisome 2. Dns should not be handled by applications. It should be handled by the operating system. I see a lot of people conflating the two in the comments.
I disagree. It has become common for the OS to handle DNS globally. This can provide nice cache efficiency/centralized configuration benefits. But it is also much less flexible and unlike e.g. the OS's Certificate Authority Registry there's no update/revocation benefits.
DNS over HTTPS being configurable in the browser gives us more flexibility. For example you want to AdBlock but not risk breaking OS Updates, you want to split-tunnel a VPN connection then pick which resolver for the browser, or you even want to use a different non-"internet"/non-ICANN network only in a single browser/instance you now can. That's powerful.
DNS by the OS is common in 2019. But saying it "should" without explanation isn't a strong argument except towards the status quo.
PS - If you think of a web browser like an "app ecosystem" this line of thinking makes a heck of a lot of sense. The OS is just a host for a sub-"OS" ecosystem. There's a reason browsers already have their own configuration for e.g. web cams, microphones, sound/mute, language, 3D acceleration, and security that already end-run around what the OS is trying to dictate.
Re: Turn off DoH, Firefox
#97This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
Of all the governments to worry about, the ones in the EU (as well as US, CA, AU, NZ), are the ones I'd least be concerned with, relatively speaking.
They're enabling this in the US, and yet even with all its problems, it's the one country that the average web surfer would have to worry least about when visiting "inappropriate" sites.
* https://en.wikipedia.org/wiki/Room_641A
> DoH is vital to protect users around the world from censorship and worse.
Great. Then enable it in countries where it's actually a problem. As a Canadian I do not feel a need for this, and I worry about Cloudflare getting an NSL more than I worry about CSIS/RCMP tapping glass.
Re: Turn off DoH, Firefox
#98This is painful to read. Masses off unfounded FUD - the article deliberately buries that it's trivial to change your DoH provider if you're silly enough to believe that CF is actively logging DoH requests and selling them (CF is involved with serving vast swathes of the internet anyway - if they wanted to go down this route they have far more lucrative avenues open than selling DNS requests by IP). If instead what yo…
So far I'm using NextDns.io at home, which is DoH and also applies ad-filtering. I haven't heard of any security concerns yet Disclaimer: I do not work or have any financial connection to that service
Re: Turn off DoH, Firefox
#99It's very disturbing to see the overreach that Mozilla has resorted to and the "privacy" argument (it was "security" before that...) being used to justify essentially ignoring system configuration. My ISP has more accountability than a company in another country. The correct way would be to standardise DoH and DoT and add support into it into automatic address configurations and operating systems. Exactly. If Mozilla…
This is beside the point. Mozilla make a browser. They don't make the address resolution code for the underlying operating system. Operating system vendors are of course going to start to support DNS-over-https.
You can disable dns-over-https if you don't want it enabled. Just go to about:config and set network.trr.mode. to 5
Re: Turn off DoH, Firefox
#100Of course, I'd rather trust unecncrypted plaintext DNS queries that go to my ISP and government! If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS
Your ISP has access to more detailed data on you than DNS queries. Also CF servers are typically located in the same jurisdiction as your government and send unencrypted DNS queries from there. Now instead of dealing with every ISP your government has to deal with just one company in one location, no need to even ask that company anything, just come in and setup mirroring point, very convenient for the government, not very good for you.