13 ms·
"Caveats TRR doesn't read or care about /etc/hosts There's no way to exclude or white list specific domains" For me, the primary advantage of HOSTS/DNS is th
by textmode 8y ago
"Caveats
TRR doesn't read or care about /etc/hosts
There's no way to exclude or white list specific domains"
For me, the primary advantage of HOSTS/DNS is the ability to control answers to application queries for addresses and block ads.
This seems to remove all control a user might have through controlling such lookups. Yikes.
I think DOH is useful but in a different way. For example, it is useful for retrieving bulk DNS data using RFC 2616 pipelining, alleviating dependence on piecemeal DNS lookups, thus increasing speed and privacy. Data can be stored locally and refreshed periodically, if necessary (I have been doing this witout problems for 15 years). It's also useful for retrieving data from a variety of caches, allowing answers to be compared.
- niftich 8y agoFirefox's DOH client ignores /etc/hosts, but it shouldn't be too hard to host your own DOH server [1][2] that you could then configure how you see fit. I can see this pattern becoming widespread someday, and with DOH, people can re-use their experience in setting up webservers. [1] https://github.com/st3fan/tinydoh https://github.com/st3fan/tinydoh [2] https://github.com/m13253/dns-over-https https://github.com/m13253/dns-over-https
- toomuchtodo 8y agoI think there’s great value in DOH caching servers running on home routers; all the benefits of DOH but “regular DNS” between clients and your home router.
- peterwwillis 8y agoYou think regular end users having to set up and maintain server software in order to force a name for an IP is going to become a widespread pattern? That's horrifying. I don't want to live in that world.
- greglindahl 8y agoRegular users today don't use that feature, so you're choosing a rather odd hill to die on. To put this another way: it's a significant benefit for my random non-techie friends to be able to use this new feature plus HTTPSEverywhere. And even as a techie, I don't use a hosts file to block anything. So I'm not bothered by how Firefox chose to implement this, like most people.
- da_chicken 8y agoThere's plenty of ad blocking, spyware blocking, ransomware blocking, etc. software that absolutely uses the hosts file to blackhole requests. Much of it is free and intended for home computer use.
- greglindahl 8y agoAnd what market share do they have? None of my non-techie relatives or friends who've asked me to look at their machines run that kind of software.
- mortenlarsen 8y agoOnly the use case with the largest market share matters? That kind of thinking, really irks me.
- greglindahl 8y agoNo, I don't think like that. It does bother me when Firefox introduces a feature which covers up a huge hole in TLS, and they get a large number of complaints on HN.
- vetinari 8y agoOf course it gets large number of complains, when it creates more problems than it solves, and it is papered over "but mainstream users do not need that". Mainstream users do not need most software ever made.
- Immortalin 8y agoIt's easier than ever to host a server transparently for end user software. You don't hear users complaining about node.js running in most Electron apps. A http server for DNS can easily be compiled to binary and ran like any other system daemon.
- fanf2 8y agoThat [1] implements a very old draft so I doubt it is compatible with Firefox.
- chupasaurus 8y agoJust run local dnscrypt-proxy (it supports DoH) on your machine/router and everything would be fine.
- deleted 8y ago[deleted]
- dogecoinbase 8y agoTRR doesn't read or care about /etc/hosts There's no way to exclude or white list specific domains Sigh. This is aggressively breaking normal DNS behavior (and will be an absurd hassle for a very large number of organizations, but in terms of extremely normal split-horizon and orgs with regulatory obligations to catch HTTPS traffic). Applications should not contain their own encapsulated resolvers, let alone resolvers that default to sending all of my DNS traffic to for-profit companies that have previously experienced massive data leaks (and fun CF fact, they invited the then-CTO of Cambridge Analytica to talk at their Internet Summit event in SF last year).
- riquito 8y ago> will be an absurd hassle for a very large number of organizations they can disable it, any organization that modify /etc/hosts can also change Firefox's preferences file
- peterwwillis 8y agoThis isn't an acceptable compromise. In general it's not acceptable to break functionality and then demand people invent workarounds. But it's insane to demand that every organization in the world write new portable system integration software that has to take into account 100 varying things just to disable something nobody has asked for. And it's even more insane when the software in question is the underpinning of all internet access that has existed in the same form for 40 years.
- greglindahl 8y agoI wanted this feature.
- dogecoinbase 8y agoNo, you wanted encryption for DNS transport, and I completely agree with that desire. This is a terrible half-measure that bypasses many existing security precautions people have intentionally taken by default, and moreover exposes private data to a company with a history of handling such poorly.
- acqq 8y agoAlso problematic: "0 - Off (default). use standard native resolving" ... "5 - Explicitly off. Also off, but selected off by choice and not default." It seems that the plan for the "0 - default" is to switch the users to other modes without the user knowing it, and to keep the behavior off the user must specifically change the option to "5."
- anonymfus 8y agoNo, it is not problematic, it's a good engineering. Imagine in the future DNS over HTTPS will be supported by OS and there will be an OS-wide setting for it. Then it will make sense to change default setting in FireFox to use OS-wide setting.
- bagder 8y ago"I better speculate on the reason here because surely Daniel is part of a conspiracy meant destroy the browsing experience of millions" or... It could be prepared for when the user gets asked what they want and then Firefox can remember an explicit "no" as compared to not selection ever made. / Daniel (author of the blog post)
- acqq 8y agoDaniel is not responsible for the decisions made by other Mozilla managers who already used their powers to deliver an unsolicited ad to the millions using the means presented as having apparently other purposes. Daniel’s own decisions aren’t in question here. If he works for Mozilla he is not more powerful than the whole company. Having “off” and “off when selected by user” but not other variants still points to the intention of the default state not remaining off. Which is not problematic. Problematic is however naming the state that will obviously be changed “off.”
- Operyl 8y agoIt’s worth noting that Daniel is the GP here. You’re talking about him in the third person.