4 ms·
On Firefox moving DNS to a third party
- LinuxBender 8y agoHave Mozilla figured out how they are going to handle corp users enabling this and not breaking corporate DNS?
- ahubert 8y agobest response I've had to that is 1) they'll retry queries internally if they don't work externally (leaking everything first) 2) people should not have internal only domains, everything to the cloud!
- LinuxBender 8y agoThat seems very leaky to me. It would be a shame if we had to block CF's DNS IP's.
- protomyth 8y agoI would rather CF (or any other company) not get a list of all our internal domain names.
- supakeen 8y agoIt's likely that the assumption is that in 'enterprise' or large organizations software installation and configuration is managed or that they fall back if they can't (but as the blog post says; DNS over HTTPS is hard to block).
- ahubert 8y agoWith BYOD that is less and less likely to be true..
- supakeen 8y agoAnd Android P is already gearing up to DNS over HTTPS as well with Android itself going with DNS over TLS. Don't know what the iOS stance on this is.
- LinuxBender 8y agoI've not seen many orgs manage FF settings. Typically AD policies apply to MSIE/Edge. Has this changed?
- Arelius 8y agoAs a single data point, my current and quite large company manages firefox settings. I discovered this when they turned off the search in address bar feature...
- LinuxBender 8y agoCool. I hope this is becoming more prevalent. A coworker gave me a link to the policy (for windows) [1] [1] - https://support.mozilla.org/en-US/kb/customizing-firefox-using-group-policy https://support.mozilla.org/en-US/kb/customizing-firefox-usi...
- reitanqild 8y agoIf anyone wonders why anyone would do that it might be because the autocomplete in search bar leaks metadata not only about what you search but also about what sites you visit.
- fulafel 8y agoIt seems many orgs manage to shoot themselves in the foot quite badly with centrally managed browser. In all the environments I've seen, IT have managed to disable auto-update on Chrome or Firefox and break the centrally managed updates for a long time, creating an easy avenue for malware or worse to get in.
- supakeen 8y agoAn update is that on Reddit a Firefox employee has responded on my crosspost to reddit: https://www.reddit.com/r/firefox/comments/9cx8hk/on_firefox_moving_dns_to_a_third_party/ https://www.reddit.com/r/firefox/comments/9cx8hk/on_firefox_... Clarifying that this is just an A/B test and there are no plans to continue using CloudFlare for all users.
- kodablah 8y agoTo clarify, only in nightly and previously disclosed [0] (results at [1]). The article is right to be fearful that FF is pondering a default change, but until that is even on the table, I'm not worried. Now if they wanted to make it really really easy for regular users to change from your default ISP DNS to CloudFlare, I'd actually be OK with that, but I'd expect it to be implemented like search engine providers where anyone could just as easily be the DNS provider chosen (ideally without any CloudFlare favoritism). And it would be clear who your DNS provider is maybe via an icon (if there is real estate for it). 0 - https://blog.nightly.mozilla.org/2018/06/01/improving-dns-privacy-in-firefox/ https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr... 1 - https://blog.nightly.mozilla.org/2018/08/28/firefox-nightly-secure-dns-experimental-results/ https://blog.nightly.mozilla.org/2018/08/28/firefox-nightly-...
- sp332 8y agoThey have a contract with CloudFlare with stronger privacy protections for FF users. This goes beyond the normal CloudFlare privacy policy. https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/firefox/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... They're not just picking providers at random.
- kodablah 8y agoI am a bit naive. Who is paying who in this contract? What is either side getting out of it? Why can it not just be a pluggable DNS provider situation and let CloudFlare compete with anyone else for opt-in (including extra privacy features if so desired)? Also curious, why would CloudFlare offer stronger privacy protections for one type of user and not another...what is CloudFlare getting out of the lesser-protected users since it is clear everyone is not given the same treatment?
- brians 8y agoThis seems well-intentioned but incredibly dangerous. There's no promise CF can make that justifies trusting them to receive a stream of every request from every FF browser, with all this trackable metadata. In particular, I think it would be unsurprising if CF's lines were tapped upstream. CF and Mozilla staff have a history of treating TLS as if it protects all content, rather than as a tool for keeping narrowly defined secrets. I explain further at https://weblog.evenmere.org/posts/2014-05-16-tls-is-not-for-privacy.html https://weblog.evenmere.org/posts/2014-05-16-tls-is-not-for-... .
- partiallypro 8y agoDoes Google do this with their own DNS service in Chrome...or would this open the door for them to do so? I don't like the implications.
- sp332 8y agoBut since there's already a high risk of ISPs sniffing or even redirecting this traffic, you'd have to show that the risk for the average user is higher with CF.
- Coding_Cat 8y agoIt funnels all _firefox_ requests through CF, as opposed to all _$ISP_ requests. Which one is worse for the user I find hard to say, but they'd definetely generate two completely different datasets. (for example, CF's set would be international).
- Xylakant 8y agoAt the moment, this is an A/B test to see if DNS over HTTPS can keep up with regular DNS in term of performance in a real-world setting. It’s an opt-in study. That’s about the extend of it. You can explicitly enable DNS over HTTPs on recent FF versions if you want to, then you need to pick a provider. There are a few available choices out there. There’s a list on the cURL docs IIRC. Due to the standard being finalized right now, the list is understandably quite short, by there’s no particular reason you ISP shouldn’t offer a suitable DNS server in the future.
- RcouF1uZ4gsC 8y agoThe big issue with Mozilla, is that they are dependent on outside revenue (which for the most part ultimately comes from advertising). A big chunk of their revenue comes from Google. If CloudFlare were to offer Mozilla a lot of money to use CloudFlare DNS, they would likely do it.
- reitanqild 8y ago> The big issue with Mozilla, is that they are dependent on outside revenue While this is technically true it is kind of misleading to single Mozilla out as depending on a certain large sponsor given who owns Chrome (and who owns Edge, IE and possibly less problematic, Safari).
- dschuetz 8y agoThis is just like when Facebook wanted to handle all of your iOS traffic via a VPN app for "secure Internet" reasons. "Trust us, you have nothing to worry about, your traffic is safe with us" and then they were caught analyzing traffic data of all apps other than Messenger or Facebook. Yeah. "Trust"
- MasterScrat 8y ago> they were caught analyzing traffic data of all apps Source?
- iancarroll 8y agoOnavo has been a critical part of Facebook's recent startup acquisitions, and the data they had was very powerful. "The tool shaped Facebook's decision to buy WhatsApp and informed its live-video strategy, they say. Facebook used Onavo to build its early-bird tool that tips it off to promising services and that helped Facebook home in on Houseparty." https://www.engadget.com/2017/08/13/facebook-knew-about-snap-struggles-through-app-tracking/ https://www.engadget.com/2017/08/13/facebook-knew-about-snap... https://www.foxbusiness.com/features/the-new-copycats-how-facebook-squashes-2 https://www.foxbusiness.com/features/the-new-copycats-how-fa...
- sp332 8y agoIn this case they do actually have a contract in place. So there could be real penalties if they violate the privacy agreement.
- buckminster 8y agoA friend of mine has a simple static hobby website on his own .net domain. It isn't reachable through CloudFlare DNS. This has been true for over two months. Google DNS can see it, as can my ISP's. I recently noticed that his self-hosted email is sometimes being flagged as spam because it lacks spf. Is CloudFlare filtering their DNS results, maybe against a spam blacklist?
- ryanlol 8y agoPerhaps his DNS servers just wont talk to 1.1.1.1 for $reasons?
- Habbie 8y agoCan you share the domain name so we can investigate?
- buckminster 8y agoI can't share the domain name but its DNS servers are: ns3.cisws.nl ns6.cis-websolutions.nl
- mnordhoff 8y agoSharing the domain is usually critical. Picking a random domain hosted on those nameservers, mdfs.net, it looks like, of the 4 IPs, 2 are down and 1 of the remaining ones doesn't support TCP. http://dnsviz.net/d/mdfs.net/W48OcQ/dnssec/ http://dnsviz.net/d/mdfs.net/W48OcQ/dnssec/ https://ednscomp.isc.org/ednscomp/4040283963 https://ednscomp.isc.org/ednscomp/4040283963 1.1.1.1 is less tolerant than some resolvers of that level of breakage. https://community.cloudflare.com/t/ipv6-timeouts-appear-to-be-racey/30682 https://community.cloudflare.com/t/ipv6-timeouts-appear-to-b...
- buckminster 8y agoThanks for having a look. If I understand that correctly the DNS servers are returning IPv6 addresses for themselves, which aren't functioning. So he needs to get his host to stop returning the IPv6 addresses (or to fix IPv6).
- zaarn 8y agoThat title is a hell of a lot misleading considering this is for an early A/B test and there are no plans to enable this for all users.
- justinzollars 8y agoIs there any easy way to change/update the DNS lookup server? I do not trust Cloudflare or Google or anyone for that matter.
- _4xjr 8y agoCloudflare's 1.1.1.1 DNS already censors torrent/piracy focused domains, for example rarbg and thepiratebay. On the other hand, they resolve websites which are considered illegal in my country, which would normally be censored by my ISP (e.g. not approved betting websites).
- eastdakota 8y agoThis is absolutely false.
- _4xjr 8y agoI state my results for when I tested your DNS (related [1]) [1] https://www.reddit.com/r/Piracy/comments/8aa0ba/cloudflare_dns_blocking_scihub/ https://www.reddit.com/r/Piracy/comments/8aa0ba/cloudflare_d...
- jgrahamc 8y agoThat's a load of crap. Actually it's a bucket of crap.
- deleted 8y ago[deleted]
- sudhirj 8y agoGiven that my ISP currently tracks DNS and blocks whatever they feel like at that level, I actually think this is a good move. The measure I'm looking at is that of sensible defaults: is this default more sensible for a majority of the user base than the existing default? For anyone outside the rule of GDPR using a regular ISP, this option is far better. The joint privacy policy Mozilla + Cloudflare is much better than a regular ISP. And given that we all go and change the DNS of every computer we and our extended families own to 8.8.8.8, 8.8.4.4 or 1.1.1.1, I don't see why we'd think Mozilla doing it by default is a bad thing.
- calimac 8y agoCloudflare is too big and to much of an activist culture to be a stewardif such traffic as it has now let alone firefox's chuck of traffic.
- originalsimba 8y agoCloudflare wants to control the entire internet. WAKE UP. When is enough enough? We've seen what happens to these companies in Google and Facebook. They have to be stopped.