14 ms·
Firefox’s Trusted Recursive Resolver DNS feature is dangerous
- telmich 8y agoThe Internet is not made for centralisation!
- Nokinside 8y agoThe internet has decentralized architecture underneath but the model is being abandoned because traffic volumes are too high for the naive decentralized architecture. Today 60% of the global internet traffic goes trough CDN's. In 2021 it will be over 70% in 2021 (over 90% in North America). There is whole "internet cache" industry standing between clients and servers. When you connect to some site in the internet, most of the data comes from some of these: Google CDN,,MaxCDN, Akamai, MS/Azure CDN, Limelight, EdgeCast, Amazon CDN, Coudfare,Rackspace, Incapsula, ... The issue here is not decentralization vs centralization, it's about browser selecting something for a user as a default.
- rini17 8y agoYou cannot compare CDN with DNS which does not require high traffic volumes nor expensive servers. The issue is pervasive laying of trust into "benevolent" third parties, CA's apparently are not enough and we now must have Trusted Recursive Resolvers, too. And it's more and more difficult to set up alternative infrastructure which does not rely on them.
- Nokinside 8y ago>You cannot compare CDN with DNS I didn't compare them.
- mhkool 8y agoI rather use a DNS cloud that promises to wipe logs every 24 hours than a DNS server of an ISP who is guaranteed to spy on me.
- kelnage 8y agoGreat! And you can already choose to do so. But it seems pretty likely that Firefox will be making that decision on behalf of all its users (except those with the wherewithal to know how to opt out), without effectively communicating the risks of that decision to them (based upon their communication about this feature so far).
- Xylakant 8y agoIt’s currently an expert feature that’s off by default. There is documentation in the wiki and a blog post on the nightly news blog for those that are interested in turning it on. It’s quite the opposite of opt-out. It’s opt-in for the technical inclined. What would your expected level of communication be?
- a012 8y agoThere are many public DNS providers those promise to not logs DNS queries. I don't know precisely but if Mozilla forces user to use Cloudflare DNS is the deal breaker.
- telmich 8y agoIt is especially surprising, because so far Mozilla could always be trusted.
- Xylakant 8y agoThey don’t. It’s the default if you choose to enable the feature, but there are other compatible DNS providers, pick any that suits you (or just don’t enable the feature and keep doing what you’re doing now)
- eikenberry 8y agoFalse dichotomy. I.E. those are not the only 2 options.
- xorcist 8y agoapt-get install unbound
- petters 8y ago> And your ISP knows where you connect to anyways. So the data or information generated by their DNS server provides no additional information to them. This is not correct. Your ISP only knows what IP you are connecting to and that is not enough in general. E.g. Cloudflare.
- currysausage 8y agoThat might be true in the future if and when SNI encryption is widely implemented.
- claudius 8y agoand the internet becomes sufficiently centralised that you only access a few IP addresses behind which most services are hosted. In other words, we can either a) trust our ISP with DNS queries and IP addresses which fairly uniquely identify services or b) trust Cloudflare with DNS queries and our ISP with IP addresses which fairly uniquely identify services or c) move everything "behind Cloudflare" and solely trust Cloudflare Given that I can cancel my ISP’s contract, I can hold them accountable if they spew my data into the internet and I have no idea who Cloudflare is or what their aims are, I’d much prefer a) over c). b) is just worse than a) or c).
- sofaofthedamned 8y agoWith SNI they also know the domain you're connecting to.
- pas 8y agoThere are people working on encrypted SNI: https://huitema.wordpress.com/2017/09/12/cracking-the-sni-encryption-nut/ https://huitema.wordpress.com/2017/09/12/cracking-the-sni-en... it'll take some time, but we'll get there hopefull soon.
- sofaofthedamned 8y agoGood point, but it's not here now. It is however better than the old days where you needed your own IP address to do TLS/HTTPS.
- TimMeade 8y agoWhat about if you have private DNS servers that has sites that cloudflare does not have? For example internal intranets etc? So mozilla will not work at all in that case?
- xg15 8y agoI think as far as browsers are concerned, there are no private DNS names anymore for a good while already - either everyone on the internet knows your DNS or it doesn't exist. See the similar problem with TLS certificates... (edit) Ok, that was indeed put more dramatically than necessary. My point is that private DNS names seem to be heavily discouraged by browsers default configurations. You can change both the DNS resolver as well as install custom CAs - however, this has to be done again for each client. If you want to have your sites visited by clients that you don't administrate, you're out of luck. (warning - rant follows) The direction browser vendors would like the ecosystem to move also seems quite clear to me - there is a strong push to get everyone on HTTPS, at the same time CAs are themselves increasingly regulated by browser vendors and cannot hand out certificates for IPs and private DNS names anymore. Now the next step seems to be DNS. If that is not a platformisation of the web, I don't know what is.
- StavrosK 8y agoWhy do you think that? My home router will happily resolve sites that only exist on my home server.
- xg15 8y agoYour home router will. However, as the article made clear, you won't be able to open that site in Firefox. Even if you were, you won't be able to get a public TLS certificate for that site, making you unable to serve the site as HTTPS and locking you out of many current and all(!) futue JS and CSS features. Yes, you can solve both problems by installing overrides. However, this has to be done separately for every client that you want to use and (potentially) for every app that you want to connect to. If you want to make an intranet-only web page that "just works" with off-the-shelf clients, you'll have to stick to public domain names.
- crtasm 8y agoI suppose a small upside to this is it will prompt some people to look into how trustworthy their ISP's DNS is.
- chunsj 8y agoAs a man in a country where constant censoring is performed by the government this movement at least make it harder for the gov censor/monitor people.
- theclaw 8y agoUntil the TRR endpoint is blocked.
- telmich 8y agoWhich country is that?
- anticensor 8y agoVHVya2V5IGhhcyBsZWdhbGlzZWQgY2Vuc29yc2hpcCBvZiBhbGwgcmFkaW8sIFRWIGFuZCBJbnRl cm5ldCBhcyBhbiAiYWRtaW5pc3RyYXRpdmUgbWVhc3VyZSIgaW4gbWlkIDIwMTcgKGxhd2xpa2Ug ZGVjcmVlIDY5MCkuIEFsbCByYWRpbyBhbmQgVFYgdHJhbnNtaXR0ZXJzIChldmVuIG9uZXMgdHJh bnNtaXR0aW5nIHByaXZhdGUgY2hhbm5lbHMpIGFyZSBvd25lZCBieSBhIGdvdmVybm1lbnQtbWFq b3JpdHkgY29tcGFueSBhbmQgYWxsIG5vbi1MQU4gbmV0d29yayB0cmFmZmljIGdvZXMgdGhyb3Vn aCBjZW50cmFsIGdhdGV3YXlzLiBFcmRvxJ9hbiBjYW4gZWFzaWx5IHJlcGxhY2Ugb3IgY2Vuc29y IGNvbW11bmljYXRpb24uCg==
- LinuxBender 8y agoIf they can MitM you to see your post, base64 will just draw more attention. Consider checking SSL fingerprints from trusted and untrusted locations instead. openssl s_client -servername news.ycombinator.com -connect news.ycombinator.com:443 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin SHA1 Fingerprint=BB:DD:64:6F:EB:11:0C:D5:EC:CF:57:D1:F7:52:AA:99:50:1B:44:FD I would also suggest browser addons that will alert you when SSL fingerprints change, but they don't work in FF any more, so you will have to do it manually understanding that they can swap out certs based on tcp packet size. You can also pin the cert, understanding you will have to update it if HN changes out their certs or they expire.
- anticensor 8y ago
- eps 8y agoIt really comes down to if it's going to be a silent default or a verbose opt-in. Anyone got a link to this announcement?
- StavrosK 8y agoI use Cloudflare's resolver, but I actually agree with this. I don't want every device in my local network ignoring my Pi hole or my custom DNS entries, I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. If I recall correctly, this also breaks geographical-based DNS resolution?
- telmich 8y agoThat depends. Cloudflare probably (did not check) uses anycast and thus their DNS servers are actually in the specfic region. This however does not change the problem of the legal authority still being in the US, as you pointed out.
- geertj 8y ago> I don't want the device of everyone in my country being subject to surveillance requests from the NSA (and Cloudflare is legally (if you call warrantless wiretaps legal) required to comply), and I don't like the centralization this brings. Agreed that this introduces additional centralization. Maybe Mozilla could work to with other third parties in different jurisdictions to see if there's interest to spin up additional DOH servers. That said, if your threat model includes the NSA then this would probably be far from sufficient.
- StavrosK 8y agoAs always, it's not "the NSA is targeting me specifically", it's "they're doing dragnet surveillance for potentially 'interesting' data and who knows how they'll choose to harass me". There is literally no single country in the world I would like my data sent to than the US. Even China is preferable.
- Xylakant 8y agoThere are other DoH providers.
- qiqitori 8y agoMore information: https://blog.nightly.mozilla.org/2018/06/01/improving-dns-privacy-in-firefox/ https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr... According to this page: - you can already test this right now - you can provide your own server And some more: https://en.wikipedia.org/wiki/DNS_over_HTTPS https://en.wikipedia.org/wiki/DNS_over_HTTPS
- foepys 8y ago> - you can provide your own server Nobody will do this except for maybe 5 individuals and a few dozen cooperations simply because there are no other public DoH servers around.
- Xylakant 8y agoNo other public resolver? https://developers.google.com/speed/public-dns/docs/dns-over-https https://developers.google.com/speed/public-dns/docs/dns-over... https://ripe76.ripe.net/on-site/technical-information/dns-over-tls-resolvers/ https://ripe76.ripe.net/on-site/technical-information/dns-ov... The DNScrypt project has a longer list here: https://download.dnscrypt.info/resolvers-list/v2/public-resolvers.md https://download.dnscrypt.info/resolvers-list/v2/public-reso... Keep in mind that this is currently all pretty much experimental.
- Mister_Snuggles 8y agoMany corporations will choose to run their own resolvers for internal services. Home/small business router vendors already include DNS resolvers on the boxes they sell which work to automatically provide hostnames for addresses that they've served up with DHCP.
- vetinari 8y agoMany already run their own resolvers, so providing DNS-over-HTTPS proxy is not a problem. What is THE problem, is configuring the browser. No one is going to reconfigure their browser after each connection to a different network. There's a reason why we moved from static configuration towards DHCP, which can configure network-specific settings. DNS is a network-specific setting, and Mozilla is breaking it.
- xg15 8y agoSo yet another step to centralize security with browsers and override any descisions of local admins. Great...
- rendx 8y agoThe article lacks instructions about disabling it or using some other DOH resolvers. about:config -> search for network.trr -> set network.trr.mode = 5 to completely disable it (I do not recommend this) The curl wiki has a list of DOH servers: https://github.com/curl/curl/wiki/DNS-over-HTTPS https://github.com/curl/curl/wiki/DNS-over-HTTPS It should also point to "the other side of the story", the benefits of DOH over classic DNS resolving, for example https://hacks.mozilla.org/2018/05/a-cartoon-intro-to-dns-over-https/ https://hacks.mozilla.org/2018/05/a-cartoon-intro-to-dns-ove...
- telmich 8y agoThanks for the hint! We added that to our blog entry - please let us know if it sounds right to you.
- opencl 8y agoThe default is already off[1] though... Mozilla has stated plans to eventually turn it on by default[2] but I have yet to see any timeline or details of what the default config will actually be. Your article seems to assert that it will be on by default in FF62, where did Mozilla ever say this? Everything I have read seems to indicate that FF62 is just adding support, which is off by default, and requires a change to about:config to enable in the first place. [1] https://gist.github.com/bagder/5e29101079e9ac78920ba2fc718aceec https://gist.github.com/bagder/5e29101079e9ac78920ba2fc718ac... [2] https://blog.nightly.mozilla.org/2018/06/01/improving-dns-privacy-in-firefox/ https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr...
- dblohm7 8y agoYou're operating under the assumption that if this is turned on by default in the future, everything will go to CloudFlare. While CloudFlare is being used for the opt-in study, you have no evidence that they will be used in any on-by-default scenario. Nor do you have any evidence that only a single DoH provider will be used globally. Perhaps you should monitor Mozilla mailing lists.
- vetinari 8y agoManually setting static resolvers is not adequate in many scenarios. For example, when the user roams among several networks, and each of them has split-horizon DNS, the user is not going to re-set their setting after connecting to each specific network. Throw in VPN connections and their DNS settings, and you have quite a problem at hand. There's a reason why DNS settings are traditionally set system-wide via DHCP, not statically. This is a step backwards.
- kijin 8y agoI don't like the way Cloudflare is centralizing everything, but I would use Cloudflare any day over my ISP. Seriously, fuck my ISP. I would support this feature on the condition that users are able to choose which DNS service to use by default, especially as more public DNS services begin to adopt DoH. Developers like us will also need the ability to use /etc/hosts or route queries to a local instance of dnsmasq. Obviously there's a switch somewhere in about:config, because Firefox is also involved with the Tor project which requires the ability to route DNS queries through Tor. This switch should be accessible to the user, just like the choice of default search provider.
- simias 8y agoI think it's a nice feature to have but it has to be opt-in, you can't set the precedent that it's fine for a web browser to hijack your web traffic, even if it's for a good reason.
- znpy 8y agoSigh. Mozilla had just made Firefox usable again... And now good reasons for leaving it again are coming up.
- telmich 8y agoFully agree. I was also about to take the final move chromium -> firefox. Maybe it's time to fork firefox?
- ripdog 8y agoFirefox is still great. You can turn this off trivially or provide your own server. This is, however, an excellent step towards securing the web.
- chrisper 8y agoSo what is the alternative? Chrome, edge, and Vivaldi?
- jopsen 8y agoYou can disable it... But for the majority of users, it's probably good to have Mozilla negotiate favorable terms with a DNS provider that can be subject to audits, etc. Who audits your ISP? Does Mozilla do that?
- anonymfus 8y agoWhere exactly Firefox/Mozilla people say that they plan to enable it by default?
- chrismorgan 8y ago> My local ISP seems more trustworthy to me than a big US-based corporate which acts under the guise of a selfless privacy rights defender. I have never trusted any local ISP. They’re commonly expressly allowed by law to share roughly whatever they like about you†, and they are known to do so. Cloudflare has at least promised not to be evil, and is to be audited annually concerning it. If they desire to be evil I have no doubt they could wangle it, but I still trust them way more than I trust any ISP, because they’re already known to be evil under these definitions. ---- † (This is a gross simplification, but it’s broadly true enough in most countries.)
- telmich 8y agoI wonder what kind of ISPs you use? Here in .ch, ISPs can be rather small and you even know the operators personally. So trust ISP >> cloudflare.
- chrismorgan 8y agoI live in Australia; ISPs are basically all big entities, altogether unworthy of trust. The US is broadly similar. In both countries, you do get some obscure tiny ISPs, but they’re fairly rare overall. I’ve also spent time in India with a small ISP, and I hated their DNS: they actively intercepted all DNS and replaced it with their own OpenDNS arrangement, involving the horrible NXDOMAIN replacement that was still a thing at the time, and in such a way that you couldn’t opt out of it! I don’t know how trustworthy they might or might not have been (I didn’t personally know them), but I do know that I loathed their technical decisions and would fain have bypassed them.
- rschoultz 8y agoThis feature will break dns-based geo-lookup, so as a user I might get directed to services that are 130ms away from me instead of 1-5ms. For any client application, this will likely have strong negative effects on user experience.
- nebulous1 8y agoI somewhat doubt cloudflare have overlooked that
- telmich 8y agoanycast is the solution here
- rschoultz 8y agoIt seems like you are right. On the company's pages I find "... Instead of doing this, Cloudflare will make the request from one of their own IP addresses near the user. This provides geolocation without tying it to a particular user. ". Still, my concern is that this is no longer a function of the technology, but by a service that is maintained by one company, limited to the coverage that they provide in different parts of the world.
- jpalomaki 8y agoNothing against Cloudflare, but I don’t think it is good in general for the Internet that they are getting so critical. For them this sounds like a good deal (is money involved here?). Having more control of DNS should mean they can provide better service for their customers.
- telmich 8y agoAgree - cloudflare probably does a good job here, but again: centralisation is making the Internet weaker. Also hands even more control into one entity's hands
- foepys 8y ago> For them this sounds like a good deal (is money involved here?). There is a lot of money involved. When you resolve DNS only over Cloudflare, all Cloudflare sites will have a much lower DNS resolution time than any domain that is not hosted by CF's DNS service. CF can also do geo DNS more efficiently, potentially saving millions in edge nodes.
- wild_preference 8y agoCloudflare shows how broken the internet is. For example, imagine a world where you would clearly see that your computer or toaster were used in a botnet because it showed up in your billing. DDoS wouldn’t be $5 anymore. Saying Cloudflare ruins the decentralized internet got the events out of order.
- xg15 8y agoFor reference, the privacy agreement between Cloudflare and Mozilla: https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/firefox/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
- claudius 8y agoGreat, all your data is stored for 24 hours and then collected in "anonymised" form for further processing and "internal research"! Also no mention of penalties, either for Cloudflare as a company or the responsible employees (starting with the CEO) in case of a violation. And no notice period of any time should Cloudflare decide to change those terms and have thousands of browsers still pointed at its resolvers. Why would this make Cloudflare appear remotely trustworthy?
- 477353468463695 8y agoIt's a legally binding contract between Cloudflare and Mozilla. If Cloudflare were to violate it, Mozilla could sue and a judge would determine the penalties for Cloudflare. There should be some rough guidelines written into law as well. And we're definitely not talking about small amounts. Cloudflare violating it would result in Mozilla violating the privacy of millions, which can be interpreted as significant damages to the citizens. They're also both situated in California, so privacy will be valued by a judge. Given Mozilla's public image as a privacy-friendly organization, they could also push charges for damaging that image. That penalty + the damage to Cloudflare's own reputation, I cannot imagine they would survive.
- a_imho 8y agoData from temporary logs will be moved (anonymized) to permanent logs. For me this reads as: once it is there, it is not your data anymore, not from Cloudflare Resolver for Firefox and not PII, so we can do ~whatever we wish. IANAL but it looks like extreme weasel wording (and not even remotely GDPR compliant), there is nothing to violate.
- xg15 8y ago
- tootahe45 8y agoI think he forgot to write the part about how it is dangerous or not 'more secure in general' after explaining why it is for the average user who is likely to connect to any open wifi network without setting static DNS.
- Ceezy 8y agoThat s just a feature. You can choose not to use it. Why so much noise?
- Vinnl 8y agoAs I understand it that's even the default choice, and CloudFlare is just the provider they're currently testing this with for those who do choose and do not configure their own provider.
- telmich 8y agoThe point is though that users won't change their defaults. When Mozilla sets the default to Cloudflare, > 99.9% of the users will use it.
- Vinnl 8y agoSo the default is that this is off. If and when that changes, the question that should be relevant is whether the majority of those users is better served with CloudFlare than their ISP, given their threat model.
- jillesvangurp 8y agoDNS over HTTPS is a great idea. There's nothing wrong with the protocol or Mozilla's implementation of it. This article is all about Mozilla's default choice for a DNS provider. I think Cloudflare is actually a reasonable choice though I'm not a big fan of their annoying captchas that I get served whenever I use vpns. There's nothing sneaky going on here; which the article seems to imply. Currently there is no UI to configure any of this yet (other than about:config) but you can trivially select any DNS provider that implements this in the same place where you turn this on. The relevant setting is network.trr.uri. Also, you need to opt in to this to turn it on so you'd be reviewing this setting as well. Also you can configure how this is used, how and when it falls back to normal DNS, etc. You can run your own server if you want; or use the one from your provider if/when they implement this. For obvious reasons, there are not a lot of usable servers yet but it seems Google has implemented this as well. So I assume they plan to roll this out for Chrome at some point. The premise of this article seems to be that you should trust your provider to do DNS and do it well. I'm sorry to say but for the vast majority of providers I have experience with the opposite is the case. I've had providers redirect dns failures to advertising pages in the past, shitty performance (600 ms or worse), and generally trying to rip me off with bad network infrastructure related outages while charging me a premium for bandwidth clearly not delivered via obviously very congested infrastructure. I have no reason whatsoever to trust them, at all. The less they can learn from my traffic the better.
- dingo_bat 8y agoI have configured my network settings to use a particular set of DNS servers. The issue is Firefox going out of the way to use something else.
- wild_preference 8y agoHorrible seems like a pretty melodramatic word here compared to your explanation.
- oxymoron 8y agoThe feature is opt-in. Firefox will use your system configured DNS servers unless you explicitly enable DOH. In that case you can still change Cloudfare for some other server if you’d like.
- some_account 8y agoI think it's a great option for people who can't trust their isp. I've been using it in nightly for a month or so and it works nicely. Making it default would be controversial though. Right now it's opt in.
- telmich 8y agoIf you agree and think it's dangerous, help us to spread the word on twitter https://twitter.com/ungleich/status/1026041643340845057 https://twitter.com/ungleich/status/1026041643340845057 - maybe it helps to make Mozilla rethink this "feature".
- cptskippy 8y agoThink what is dangerous? Encrypted DNS? Choosing a DNS provider you don't like for an experimental feature because the support that feature? Trying to make the web safer and less creepy? I think you have a fundamental misunderstanding of what is this experiment is configured the way it is and you're just being a Chicken Little.
- Proven 8y agoOkay let's admit it, Mozilla is a privacy destroying non-profit.
- kingofhdds 8y agoThere are many countries where ISPs are obliged by law to spy on users, and retain logs for many years. DNS manipulation also used as a cheap censorship mechanism. So Cloudflare easily can be a better option for hundreds of millions if not billions of people. As a rule, local actors present way more serious threat compared to US agencies for majority of the planet's population. That said, Mozilla, of course, must be very transparent with such big changes, and explain them to users not using just "more secure" wording.
- _Codemonkeyism 8y agoSo data is safest in the country with the largest spying budget and the most spies. Not convinced.
- kingofhdds 8y agoYou are refuting the statement I never made. There's no such thing as general threat. So who's data? If you are Julian Assange you should be afraid of US spying agencies, but if you are an Uzbekistani dissident it's your gov't repressive machine you should care about, and tracking possibilities of your direct adversary will be diminished with the discussed Mozilla's move. If you are an average Joe in a small town you may find it safer to trust faraway commercial entity rather then your neighbor's nephew who works in a local ISP.
- YouAreGreat 8y agoWhy would Google's own Mozilla do this... unless Google is planning to buy Cloudflare.
- _Codemonkeyism 8y agoMost important point from the article "Let's stop here for the moment and repeat: With Mozilla's change, any (US) government agency can basically trace you down." - with ease I might add.
- Hnrobert42 8y agoDoes anyone know about this website? I am skeptical of a .ch domain criticizing something that would make censorship harder.
- _Codemonkeyism 8y agoThe US has the largest spying budget and the most spies. And FF thinks it makes it more secure for me if the transfer all my browsing meta data to the US. I don't think so.
- mcny 8y agoSorry if this is off topic but where does DNS over https leave my pi hole? Is it possible (in the future) to do dns over https from my router to the pihole and then dns over https from the pihole to Google or Cisco open DNS? How would it work? Wouldn’t the router need to trust the https certificate that my pihole presents? Thank you!
- telmich 8y agoThat would work. DoH is "just" a replacement for UDP in this context. However when Mozilla changes the default to DoH of Cloudflare, you will need to manually change all firefox installations.
- crtasm 8y agoOther posters on this thread point out that Firefox has no plans to make it a default.
- angry_octet 8y agoI know my ISP is required by govt to log all meta data (websites, IPs, email headers). If I'm not using a VPN, it's all logged. Encrypted SNI is coming, but without encrypted DNS it's all still logged. So it seems like a net win, even if cloudflare is logging everything. Too bad dnscurve hasn't taken off more.
- the8472 8y agoBut you don't need to depend on cloudflare here. If you have a VPN you can also tunnel your DNS lookups to a custom resolver through the VPN.
- Mister_Snuggles 8y agoI'm not looking forward to this. I use internal DNS for stuff I'm running at home (e.g., a NAS, Home Assistant, etc). I don't want to go back to the bad old days of having to remember what IP addresses go with what service. My girlfriend is not going to like it when Pi-Hole magically stops working because Firefox doesn't respect the DNS settings that are served by DHCP. My employer uses internal DNS for internal services. The helpdesk is going to have a fun time as Firefoxes across the organization get updated. It also doesn't help that a large number of users are BYOD users, so enforcing certain Firefox settings is a no-go. Sure, there's instructions to fix it, but it should never be broken like this in the first place. EDIT: The article has been updated - it now shows a screenshot from Mozilla's blog[0] which says: > We’ll use the default resolver, as we do now, but we’ll also send the request to Cloudflare’s DoH resolver. Then we’ll compare the two to make sure that everything is working as we expect. Cloudflare is going to have a huge list of internal stuff used by Firefox Nightly users, and Mozilla is going to have huge insights into how many people use things like Pi-Hole, internal DNS servers, split DNS servers (e.g., BIND Views), etc. And they're going to be analyzing this data in order to determine how well DNS-over-HTTPS works. I'm not sure if this is better or worse than I initially thought it was. [0] https://hacks.mozilla.org/2018/05/a-cartoon-intro-to-dns-over-https/ https://hacks.mozilla.org/2018/05/a-cartoon-intro-to-dns-ove...
- bzbarsky 8y ago> Cloudflare is going to have a huge list of internal stuff used by Firefox Nightly users By Firefox Nightly users who agree to be in the study, yes?
- _Codemonkeyism 8y agoUpdated: "We wrote in a previous version that "the next Mozilla patch in September" will enable DoH by default. We corrected that part as it is not clearly stated on Mozilla's blog, as can be seen in the screenshot below."
- nobleach 8y agoWhile developing, I hack my /etc/hosts to point at a local dev environment. Is this to say that Firefox would ignore that as well?
- the8472 8y agoIf you don't trust local ISPs the solution is not to put your eggs into the cloudflare basket which could then be plundered by the NSA fox. Instead tunnel all traffic to some rented box in a jurisdiction of your choice and then run your own DNS resolver either in your home network or on that box.
- hoppelhase 8y agoThis proposal introduces a lot of complexity. It requires JSON parsing, HTTP and TLS. A bug in one of these components could is likely to occur. In contrast, DNS is very simple and can be implemented with a lot less code.
- Gaelan 8y agoThe JSON/HTTP protocol may be more complex than DNS, but Firefox is likely to already have a very good implementation. TLS is new, but important.
- Pyxl101 8y ago> The Domain Name System (DNS) is a service used in converting a computer’s host name or a Top-Level Domain (TLD) into an IP address Hostnames and TLDs are different concepts in DNS. It is a mistake to conflate them. TLDs are the top level (rightmost) part of domain names, such as specifically “com” in “example.com”.
- deleted 8y ago[deleted]
- yellowapple 8y agoI imagine this has a lot of potential to break things on corporate intranets. Or does TRR have some kind of mechanism to check for that?
- ferongr 8y agoSeems like my decision to migrate off Firefox was the right one.
- msravi 8y agoThe article is incorrect. 1. TRR is not turned on by default. To turn it on, you need to go to about:config and set network.trr.mode to something other than 0 or 5. 2. Even if trr.mode is turned on, you need to go in and set the DOH server at network.trr.uri. The default is blank. You can set it to any publicly known DOH server (https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-available-servers https://github.com/curl/curl/wiki/DNS-over-HTTPS#publicly-av...), or even your own. 3. The article doesn't talk about how your ISP can use DNS to censor your result - very common, for example, in a country like India where the court orders certain sites taken down. Mozilla's DOH solves this.
- orbital-decay 8y agoThe first sentence of the article is about TRR/DOH being turned on by default in the next patch.
- rmdoss 8y agoYes, that's the big issue. Plus, changing to a different resolver is not very simple and most users won't even know.
- teddyfrozevelt 8y agoIt would be a big issue, if it was true.
- msravi 8y agoCan you point to a Mozilla announcement that says they'll turn on DOH by default in a regular non-experimental non-nightly release? This is what Mozilla says in their DOH blog: Our second effort focuses on building a default configuration for DoH servers that puts privacy first. We are running a shield study where some Nightly users will participate in one or more experiments to help us build out a secure, cloud-based service that handles DoH requests. All Nightly users will receive an in-product notification about these studies. Cloudflare is our partner for these experiments. When a shield study is active, Nightly Firefox will automatically use Cloudflare’s secure DNS over HTTPS service (though we aren’t using the famous 1.1.1.1 address). The first study will test whether DoH’s performance is up to the task.
- jchw 8y agoWell, you have to trust some third party. Personally, I think Cloudflare's DNS is pretty trustworthy based on what we know. It's WAY better than sending unencrypted DNS requests to arbitrary network-dependent third parties, in my opinion. If you gravely fear Cloudflare for some reason, Google also provides a DNS over HTTPS server, along with a couple others. You can probably set Firefox to use that. But if we we're OK treating this as insensitive data not needing encryption before, worrying about trusting third parties is not even the beginning of the problem.
- peterwwillis 8y agoJust because what you're doing is private doesn't mean it's secure. Just because what you're doing is secure doesn't mean it's private. No whistleblower should ever just expect that doing things the normal way is private or safe for them. If you wear a tinfoil hat, you need an entirely different operational language than typical users have, because your needs are totally different.
- mrob 8y agoPrivacy improves security for everybody. If an attacker can read all your DNS lookups then it's easier for them to target a spear-phishing attack against you.
- peterwwillis 8y agoPrivacy may improve security, but usually not. It is a sometimes unintended consequence. If I want to tell you a secret, I will bring you into a private room. Now we have privacy. If someone wants to listen in on our conversation, they will plant a bug in that room, or listen through the wall. To remain secure, I must add security countermeasures to prevent the bugs from transmitting, or extra noise to make being overheard difficult. Your ISP's DNS might be more private, but if an attacker can poison your ISP's DNS cache (it has happened to me on my ISP) you won't be more secure. It's more secure to use a hardened DNS service, which is usually not local. But yes, this could be a minor privacy concern with a big enough attacker. Just because you add privacy does not mean you added security. Just like because you add security does not mean you have privacy. So please be honest about the motives for things like this. If you want more privacy, say so. Don't say it's a security problem when it's not.
- nykolasz 8y agoFirst, I have to say that I love cloudflare, but the last thing we need is the centralization of all our DNS resolution to them. Please Mozilla, don't give anyone too much power. And if DNS over HTTPS is the way to go (which might be), give the user a choice. There are 3 public resolvers already offering DNS over HTTPS: Google[1] (was the first one to support it) CloudFlare[2] CleanBrowsing[3] (for security and/or adult filtering) And hopefully Quad9 will join the list soon. I hope this doesn't become a "search engine" war that the company that pays more becomes the chosen DNS. Please Mozilla, don't do that. * 1: https://developers.google.com/speed/public-dns/docs/dns-over-https https://developers.google.com/speed/public-dns/docs/dns-over... * 2: https://developers.cloudflare.com/1.1.1.1/dns-over-https/ https://developers.cloudflare.com/1.1.1.1/dns-over-https/ * 3: https://cleanbrowsing.org/dnsoverhttps https://cleanbrowsing.org/dnsoverhttps
- kiriakasis 8y agoThe only point in this is that mozzilla will apply it as a default, which then is retracted at the end. As of now this only serve to start a flamewars over all the drama people have with mozzilla
- octosphere 8y agoTo be honest I think it's great news. I would much rather trust Cloudflare to handle my (encrypted) DNS than my ISP. I'm based in the U.K and there are very few ISPs that have private DNS - you often hear stories of (U.K) ISPs selling data out the backdoor to comply with things like the Investigatory Powers Act[1]. [1] https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016 https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016 But besides Mozilla's efforts, I am careful not to browse anything political using a vanilla ISP. Anything sensitive is browsed with Tor for anonymity. I only use a VPN for routing traffic over hostile networks like public wifi hotspots / Starbucks wifi. A VPN is not inherently private but a VPN does have its uses, like for viewing geo-locked content (Like the 'This video is unavailable in your country' scenario). Also for further research if you want to know more about 'trusted' Internet: https://www.youtube.com/watch?v=a4UXnZaunJQ https://www.youtube.com/watch?v=a4UXnZaunJQ
- ezoe 8y agoI was thinking about this issue. Once this feature is on by default, all Firefox DNS query goes through the Cloudflare, a for-profit company which resides on US whose government is infamous for spying everything. My conclusion is, what's the difference? Currently, Cloudflare is one of the major CDN in the world and most traffics goes through them. Even worse, by it's nature, Cloudflare and most of the CDNs are practically doing MITM attack so they can cache the data. For that, HTTPS isn't that secure the most browser vendor want us believe to be. The rise of CDN cause serious single point of failure but most of us don't worry about it like DNS. To solve this problem, we need to invent completely decentralized new network that doesn't relies on the current Internet even at the physical layer. Probably fallback to the level such that we carry storage by foot or pickup dead drops.
- alphaaurigae 8y agodont touch my dns settings, srsly!
- deleted 8y ago[deleted]
- jplayer01 8y agoI don't understand why so many people are critical of people being wary about how a company deals with our data, especially one in Mozilla's position. Did all of you sleep through the past twenty years?