Live data from Hacker News

Improving DNS Privacy with Oblivious DoH

blog.cloudflare.com

91–100 of 367 posts

Re: Improving DNS Privacy with Oblivious DoH

#91
post #89

I understand why Cloudflare wants this (marketing, as well as being able to serve their customer’s content through restrictions, thus making them more valuable to those customers), but why does Apple want this? My knee-jerk is that they want to further hide/make unstoppable things like the Gatekeeper network checks, but there has to be more right?

Why would Apple care about hiding Gatekeeper traffic from internet providers?

I’m guessing they want to hide it more from users. The recent bypassing of local firewalls shows this, for example.

Re: Improving DNS Privacy with Oblivious DoH

#92

I understand why Cloudflare wants this (marketing, as well as being able to serve their customer’s content through restrictions, thus making them more valuable to those customers), but why does Apple want this? My knee-jerk is that they want to further hide/make unstoppable things like the Gatekeeper network checks, but there has to be more right?

2 reasons I can think of.

Firstly, Apple loves to act like they are always taking your privacy very seriously (of course that's not always true), so for the cost of a few engineers, they get a massive marketing point. "We take your privacy so seriously that we developed a new protocol to do so"

Secondly, Apple has an awful case of NIH syndrome. If they didn't develop it themselves, they would rather develop it from scratch themselves

Re: Improving DNS Privacy with Oblivious DoH

#94
post #65
post #55

Whats the point? Governments subpoena the information or just block the protocol outright. ( or in China, get it delivered to their door by Apple ) Commercial parties have a bag full of tricks from fingerprinting to embeds on the page itself to track you. Privacy seeking users are already tunneling their traffic. That leaves script kiddies at Internet cafes. TLS kind of fixed that already so... Good work?

You, the proxy, and the DNS service, can be in 3 different countries. It's not bullet proof but makes it quite hard for a single government. Unless you are a Bond villain I think this is more than you need. If you need more than that use ToR or similar.

While I agree that it's a step forward you should proxy your whole traffic anyways if you want to enjoy the benefits of encrypted DNS. Otherwise intermediaries routing your packets can still see what you connect to by looking at the IP header (or SNI, if not encrypted).

DoH/DoT is still useful because it allows you to proxy your DNS over Tor (for example) without having to worry about tampering (or surveillance if you also use separate circuits per domain).

Re: Improving DNS Privacy with Oblivious DoH

#95

This is a neat design, but, does this not just shift the issue of trust as to whether the proxy and the target are colluding: > However, each of these guarantees relies on one fundamental property — that the proxy and the target servers do not collude. So long as there is no collusion, an attacker succeeds only if both the proxy and target are compromised. I'm not sure how an end user would be expected to assess this…

Add a few more proxy hops and you’ve effectively reinvented Tor

[deleted]

Re: Improving DNS Privacy with Oblivious DoH

#96
post #89

Earlier quoted context omitted.

Why would Apple care about hiding Gatekeeper traffic from internet providers?

I’m guessing they want to hide it more from users. The recent bypassing of local firewalls shows this, for example.

Wouldn't it still show up in netstat?

Re: Improving DNS Privacy with Oblivious DoH

#97

Earlier quoted context omitted.

Oh, please. ODoH is a proposed standard. Use whatever the hell proxy/resolver you feel like, wherever you like. DNS is a shit show of unencrypted data flying around being scooped up by God-knows-who and along comes someone proposing a standard to fix said shit show and this is the response people get.

Decentralized spying > centralized spying

Choosing to have google or quad9 spy on you doesn't mean AT&T no longer gets your DNS data when you use plain port 53.

Re: Improving DNS Privacy with Oblivious DoH

#99
post #81
post #78

I suspect that practical matters will interfere with widespread adoption of encrypted DNS. In my state, Comcast is going to start charging heavy bandwidth users extra. After a few people get surprise bills, I suspect that lawmakers will require that internet providers break down a bill by application.

I’d just get Starlink. Even if the deal was worse in terms of cost it would be a way to say fuck you to the ISP. Without some way to do that ISPs will not be able to get away with such customer hostile behavior.

> Without some way to do that ISPs will not be able to get away with such customer hostile behavior.

I guess it won't take long until the first community or HOA decides to ban Starlink dish installations for faked "optical nuisance" issues.

Re: Improving DNS Privacy with Oblivious DoH

#100
Interesting that apple is increasing its stake in privacy. On all their billboards and advertisements of course they like to present it as a boon to the customer. More importantly, I think it’s a negative for personal data hungry competitors while being relatively unrelated to Apples business
Post reply on HN