6 ms·
His main argument seems to be that the network operator should have control over DNS requests for safety reasons. Control and monitoring. This is the antithesis
by flarex 7y ago
His main argument seems to be that the network operator should have control over DNS requests for safety reasons. Control and monitoring. This is the antithesis of privacy and encryption. I wouldn't be surprised if he was pro http over https either.
- DaniloDias 7y agoIf an iot device in your home network is exfiltraring data about you, it becomes much harder to identify with dns over https. Dns over https creates more problems than it solves for 99% of end users.
- flarex 7y agoThe argument that because encryption can be used for nefarious purposes it should not be offered by DNS providers at all does not add up. ISPs can block, redirect and sell DNS traffic and many are already doing some or all of these.
- JohnFen 7y agoI don't think anybody is arguing that DNS lookups shouldn't be encrypted. The issue is doing DNS lookups via HTTPS.
- DaniloDias 7y agoI’m specifically arguing that dns lookups should not be encrypted. Dns can be descriptive: ntp.example.com sounds like an Ntp server. Oh- this pcap shows an ntp flow afterwards. Probably synchronizing time. Oh- adnetwork.example.com. Probably serving up ads. Oh Agrrvxdrgkndzzzvbbhydsxxjjj.net.org.com. Probably botnet related. Vs I need to look at every protocol flow and sort by IP? Who in their right mind blindly trusts all computers like this? If you ever want to troubleshoot your network, your job becomes way more tedious if dns requests are encrypted.
- cremp 7y agoBecause they should! Think a corporate network. If I as a sysadmin set our DHCP options to give out our own resolvers, I expect that every machine on the domain to use ours. DoH breaks that completely; and hence the network operator should have the final say. As a sysadmin myself, if browsers are overriding the basic model of top down, and it hurts me, because when something is wrong, I cant just look on my machine, I have to check which browser they use... that is the antithesis of the problem, because when DoH doesn't work but normal DNS does, then I'm flat out of options. This is why I choose not to use Firefox or any of the DoH mainline providers (Cloudflare,) and I go out of my way to make sure users cant do it.
- pas 7y agoA corp network should set up their own DoH resolver anyway. And/or simply install a cert on their workstations and MITM every TLS connection. Even better corps should only allow TLS that they can successfully MITM. It's basic security. If the endpoint/host can do whatever due to lack of firewall/enforcement, then it doesn't really matter what the network operator wants.
- deleted 7y ago[deleted]
- cremp 7y ago> A corp network should set up their own DoH resolver anyway What good is that is the browser uses their own list? Literally that's what the article is saying. Firefox will force users to use ones that break the top-down approach on how software works. If I set a DHCP option for DoH, and setup my own DoH resolver, Firefox wont care, they will jsut use their list. This also opens up possibilities for selling positions on the trusted list, because we've seen that happen before (adblock, or the firefox Mr Robot extension.) Firefox itself, with plays like this are trying to make a decision about the whole, when they are completely forgetting the corporate side.
- wbl 7y agoYou can still administer the machine and change firefox's settings.
- stupidthrottle 7y ago> His main argument seems to be that the network operator should have control over DNS requests And why is that an unreasonable position for a network operator to hold?
- judge2020 7y agoThe issue comes from network operators wanting to control DNS from being a middleman in the connection, but there is no way to ensure the people acting as middlemen in the connection are authorized to be in the middle or authorized to change those DNS requests. If a network operator can change DNS, then the ISP, network hops, or a malicious twin AP can as well.
- stupidthrottle 7y ago> If a network operator can change DNS The network operator provides an IP through the DHCP response, which also includes proper DNS-settings for that network. How is this malicious or replacing “your” DNS? The DNS belongs to the network.
- judge2020 7y agoISPs also provide "their" DNS rr's. That does not mean you have to use ISPs' DNS RR to access the DNS. > The DNS belongs to the network. This is the question - should the network really be able to tell the client what IP corresponds with a DNS name? if no, then there's no good solution to blocking websites where you can't install things on the client's device. Meanwhile, if you say yes, then you must also say yes to ISPs being able to tell the client what IP corresponds to a DNS name. The only solution in an enterprise context is to buy new hardware (or install a software update if Cisco is feeling benevolent) that runs a DoH server. In a school-bocking-porn context, you could ban the biggest offenders via IP (mindgeek sites have a dedicated IP space I think, and you could cron your own DNS lookups for other non-CDN sites) and use SNI whitelist until eSNI is added to iOS.
- topranks 7y agoThe main argument should be that the OS controls what DNS is used. The user of the OS can then set their own DNS. If applications just ignore this and use their own it takes away power from the user. Sure Firefox lets you turn it off, but a lot of people won’t bother.