6 ms·
Because they should! Think a corporate network. If I as a sysadmin set our DHCP options to give out our own resolvers, I expect that every machine on the domai
by cremp 7y ago
Because they should!
Think a corporate network. If I as a sysadmin set our DHCP options to give out our own resolvers, I expect that every machine on the domain to use ours.
DoH breaks that completely; and hence the network operator should have the final say.
As a sysadmin myself, if browsers are overriding the basic model of top down, and it hurts me, because when something is wrong, I cant just look on my machine, I have to check which browser they use... that is the antithesis of the problem, because when DoH doesn't work but normal DNS does, then I'm flat out of options.
This is why I choose not to use Firefox or any of the DoH mainline providers (Cloudflare,) and I go out of my way to make sure users cant do it.
- pas 7y agoA corp network should set up their own DoH resolver anyway. And/or simply install a cert on their workstations and MITM every TLS connection. Even better corps should only allow TLS that they can successfully MITM. It's basic security. If the endpoint/host can do whatever due to lack of firewall/enforcement, then it doesn't really matter what the network operator wants.
- deleted 7y ago[deleted]
- cremp 7y ago> A corp network should set up their own DoH resolver anyway What good is that is the browser uses their own list? Literally that's what the article is saying. Firefox will force users to use ones that break the top-down approach on how software works. If I set a DHCP option for DoH, and setup my own DoH resolver, Firefox wont care, they will jsut use their list. This also opens up possibilities for selling positions on the trusted list, because we've seen that happen before (adblock, or the firefox Mr Robot extension.) Firefox itself, with plays like this are trying to make a decision about the whole, when they are completely forgetting the corporate side.
- wbl 7y agoYou can still administer the machine and change firefox's settings.
- vetinari 7y agoMost people roam among multiple networks. Are you going to change the settings manually after each connection in different network? Most people won't. We already have an automation for that, called DHCP, setting up network specific config system-wide... which Mozilla decided to ignore.
- wbl 7y agoSo whose device is it anyway? I don't want to use my ISP's lying DNS resolver.
- vetinari 7y agoOn your router, you can configure whatever you want to use for the DNS. You were able to do that for years. But I want all the devices and apps to use whatever the local network tells them. I don't want to reconfigure the browser every time I connect at home/work/customer place/etc. P.S. My ISP's DNS doesn't lie. Maybe you should vote with your money and choose better.
- Spivak 7y ago"Network operators should be able to set DNS servers for client devices." "You can configure your router, a client device, to use whatever DNS server you want in defiance of your ISP, a network operator." Which one do you want?
- vetinari 7y agoIf you configure your router, you are the network operator (of the network that the router handles). Mozilla or other app vendors are not. No dichotomy there.
- raxxorrax 7y agoI am no sysadmin but working closely with some. I have never seen any case where HTTPS-MITM helps. Yes, theoretically it does allow us to scan for malicious content in a secured connection. Brilliant, but that are not the attack vectors they are concerned about. So what is left is that breaking up TLS just infringes on privacy and allows for tighter control. The security aspect is laughable. Users are angry that their internet got slower, an it creates an enormous administrative cost, because you need countless exceptions to the rules. Most developers break out of it in a few days...
- dogecoinbase 7y agoI am no sysadmin but working closely with some. Some of your best friends, eh? The point of MITMing HTTPS in an enterprise setting is not inbound content scanning (though that's pretty useful to), it's to prevent outbound transfer of secrets/HIPAA or PII data/financial data, and it's a regulatory requirement for some industries. Besides, the point of DoH is to move DNS into the browser, which Google also controls, to prevent pihole-like DNS-based ad blocking. Cloudflare supports it because it allows them to lock down one of the few remaining actual distributed systems powering the internet. These companies are not your friends, and you should think harder about their incentives.
- Spivak 7y ago> it's a regulatory requirement for some industries. It won't be when it's functionally impossible, which seems to be the point. You do see the light at the end of the tunnel, right? Browsers shipping their own unmodifiable CA stores and disrespecting 3rd-party CAs signatures for public DNS names.
- pas 7y agoIt seems you don't understand that there's Firefox ESR and other browsers too. The law very likely won't change just because consumer-friendly browsers by default are not enterprise-friendly. Big corps provision and manage their machines themselves, they modify the packages' built in configuration (they either create a new install package, or do it after install with scripts, or - if the application supports some kind of "group policy" then they use that). Cost of compliance is a real thing, and making the workstations secure and compliant with their own policy is their responsibility in those industries. It's not fun, but it's perfectly doable.
- DDub 7y agoSysadmins should concentrate on managing and securing the devices and not the network. This is advantageous with todays mobile workforce where users expect the same experience at the office, coffee shop or home.
- tremon 7y agoGreat deflection, but what should network operators do then? And specifically, network security specialists?
- DDub 7y agoSecurity isn't just about intrusion prevention, it is also about ensuring that the resource is available to the people who need it when they need it. So, carry on with keeping bad actors off the network and ensuring that there is sufficient capacity and resilience in the network.
- phicoh 7y agoI don't like software defaulting to sending all DNS queries to a large cloud provider. That strikes me as bad for privacy. But I don't understand the network argument. If you are perfectly fine with TLS traffic then insisting on seeing DNS traffic sounds weird to me. At the same time, if you force TLS traffic to go through a proxy then that will immediately restore visibility of DNS as well. I guess network operators still have to come to terms with the idea that in the future all traffic will be encrypted. Yes, it is annoying if you can't see anything in wireshark. But plain text is just a thing of the past.
- vetinari 7y agoThe GP isn't arguing against TLS; he is arguing against random apps ignoring network-wide settings. When such app breaks, he cannot diagnose the problem, he has to diagnose first that the problem is caused by an app that ignores a setting it shouldn't ignore.
- phicoh 7y agoIt is always the case that an app can break due to something in the app itself. An app may for example link with a different TLS implementation that breaks. Or an app may use the local DNS resolvers but do DNSSEC local validation. With QUIC (HTTP3) a large part of the network stack will be part of the application. So you lose that visibility as well.
- cortesoft 7y agoDo you feel the same way about a user running a local resolver with caching, or modifying their hosts file to bypass dns?