25 ms·
It says in the link that Mozilla was nominated "for their proposed approach to introduce DNS-over-HTTPS in such a way as to bypass UK filtering obligations and
by readyp1 7y ago
It says in the link that Mozilla was nominated "for their proposed approach to introduce DNS-over-HTTPS in such a way as to bypass UK filtering obligations and parental controls, undermining internet safety standards in the UK".
So... for circumventing censorship, then?
- nullwasamistake 7y agoHah! This is the most insane justification I've seen in a while. Even better than when all the tech giants smash competition because "security". Cloudflare (which has somewhat shady ties to us govt maybe) is pushing hard for DNS over secure channel and it's pissing off ISP's. Because they won't be able to sell personalized browsing history if is catches on.... Control/view of DNS requests is worth A LOT of money to advertisers/ISP's because it's currently immune to ad blockers and ties a user directly to their IP and real info. It's even better than browsing history because it includes everything a user does outside the browser as well, protocol agnostic, cross device. It's the perfect example of "metadata" that various companies and agencies collect for all sorts of shitty reasons. It's the last cleartext frontier of activity monitoring.
- Analemma_ 7y agoThis doesn’t make any sense. Your ISP still knows your browsing history even if they can’t see your DNS requests.
- perfmode 7y agohow? wouldn’t they just see TCP packets?
- derefr 7y agoThey see the destinations of those packets, so they know what sites (IP addresses) you're interacting with, on what ports. They don't get the domain names, but for the very popular web properties that all these analytics care about calculating your relationship to, they don't need them; the IP is enough to discern which site you're visiting.
- GauntletWizard 7y agoYes, and the IP addresses there are public, and reverse DNS entries are easy to find. There's some ambiguity, but not much. Your isp doesn't care about the difference between fbcdn.net and Facebook.com when selling your traffic history.
- nathanaldensr 7y agoNot if your traffic is HTTPS+TLS. They will only know--if they are the target DNS server--what IP you are connecting to. The secure channel protects against them knowing more than that.
- ianlevesque 7y agoSNI leaks the domain name you are requesting. It's pretty shocking.
- nullwasamistake 7y agoNo they don't. TLS has encrypted sites for a long time. And with encrypted SNI they get no info about browsing history. This is a blatant attempt to stymie the last cleartext protocol that can be used to record browsing history.
- yholio 7y agoBut if Cloudflare is the point of aggregation and the ISP can no longer distinguish between what, according to UK law, is legal and illegal traffic, then... surely the legal onus of performing the filtering will fall on Cloudflare? When they are providing internet content to UK customers, they must respect UK law. It's a dangerous chicken game to think UK will not be able to enforce it's laws against Cloudflare. The villain here is the UK govt. ISPs should applaud the technical developments with all their hearts since they are legally off the hook.
- munk-a 7y agoI would be okay with showing all of the UK a "Sorry it doesn't appear your government supports modern common sense. Please consider upgrading your government for full site functionality."
- HeWhoLurksLate 7y agoMan, I would hate to block off support for a bunch of the things that people need for their daily work, but if it makes things obvious to everyone who's at fault, then it might just work, and I'd be willing to take a hit for that to happen.
- t34543 7y agoIt appears that way - I cannot fathom the mentality that actively supports censorship. The internet was beautiful, information open and available for all. That idea became so powerful it’s now a threat. Sigh.
- CodeMage 7y ago> The internet was beautiful, information open and available for all. "Was" is the correct word to use. Here's a fun example: try explaining to someone non-technical why you can't simply download your e-mails. I went through that exercise this morning, when my wife asked me to download a bunch of e-mails and send them to her in a "folder", which she can then send to someone else. So then I had to explain that GMail allows me to download a single message -- no bulk downloads, of course -- but it saves it in .eml format, which you can't open with programs that come installed on a typical Windows box. And even if you could, there's no guarantee that the guy you're sending them to can. Of course, she thought that was stupid: why offer saving e-mails in an "obscure" format? So I had to explain why the Internet is now a bunch of walled gardens and closed services, all built on top of open and standardized protocols and formats. And, of course, those open standards can't improve and evolve easily, because each player in the game wants to lock users and their data inside their own walled garden. So yeah, the takeaway in a nutshell is that the Internet was once open, but then it became lucrative. EDIT: I think a lot of people replying here might be missing the point. Like I stated above, I was trying to explain the situation to a non-technical person. Yes, I'm aware of POP and IMAP support. Yes, I know RFC5322 is not an obscure format. But I'm talking about people who don't know or care what these things are. Try downloading a bunch of messages in RFC5322 format, zipping them and sending them to your average lawyer and see how they react.
- realshowbiz 7y agoAnd ease of surveillance
- donmcronald 7y agoIt’s a double edged sword. DoH will enable unblock-able ads.
- dredmorbius 7y agoDNSMasq, the resolver used by many adblock tools, supports DNS-over-HTTPS.
- throw0101a 7y agoThis assumes the web browser talks to your DNSmasq server. Currently Mozilla is making a straight run to Cloudflare.
- dredmorbius 7y agoIf your (on-LAN or otherwise under-your-control) DNS server talks DNS-over-HTTPS, Mozilla can just talk directly to it. That's the point. The browser-specific option can be used where that's not viable or reliable (mobile devices, third-party networks). And devices are handed DNS servers (with the option to opt out) via DHCP when they connect to the LAN.
- throw0101a 7y agoOkay, and if malware uses DoH to figure out how to connect to its C&C server, how do I stop that DoH request (given it looks like any other HTTPS request)? If Cloudflare starts serving DNS traffic from HTTPS on its CDN, the malware can use Cloudflare for DNS. Am I supposed to block all of Cloudflare's IPs because they can be used to circumvent DNS query monitoring?
- ubercow13 7y agoDoes this really matter? I am sure there are other ways malware could work around DNS blocking if it was motivated to
- Solvitieg 7y agoWhich is ironic because they also nominated Article 13 for "threatening freedom of expression"
- rayiner 7y agoPresumably it takes just a small number of people to submit a nomination, so you’re seeing different nominees from different factions.
- api 7y agoFor circumventing ISP data collection on user browsing habits.
- sdfin 7y agoIs there any disadvantage about activating it? Is the default (https://mozilla.cloudflare-dns.com/dns-query https://mozilla.cloudflare-dns.com/dns-query) adequate?
- snek 7y agoMake sure you have a resolver mode (trr.mode) that matches your comfort! 0 = use whatever the default is (one of the below) 1 = race DoH and regular dns and use whichever replies first 2 = try DoH and then fall back to regular dns 3 = only DoH 4 = unused 5 = explicitly off The default resolver is identical to 1.1.1.1 except it collects less data: https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/firefox/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
- dcow 7y agoRequests take orders of magnitude more data because you have to negotiate TLS each time. Not the end of the world obviously but you will generate more traffic and observe slightly reduced performance.
- icebraining 7y ago> you have to negotiate TLS each time It's not so bad, because HTTPS supports keep-alive, so you can make a bunch of queries with a single TLS handshake.
- tialaramex 7y agoYou get to do session resumption or even re-use an existing session if it hasn't closed yet. For a random third party that might still be slow but Mozilla and Cloudflare have every reason to do every trick that's safe to speed this up, including 0RTT TLS because replaying DNS queries isn't a problem.
- the8472 7y agoIt would contribute to the centralization of the internet, by making cloudflare more important.
- 7y ago
- ehsankia 7y agoAren't Google and many others looking at it too? Also DNS-over-TLS is also being looked at by Cloudflare, Quad9 and more. I don't see why Mozilla is being called out here.
- 15characterslon 7y agoMost major public (non-ISP) DNS resolvers support DNS-over-TLS today. (This includes Google, Cloudflare and Quad9.) The problem for the ISP is that switching to those resolvers would mean users would no longer use their DNS resolvers. I guess they're selling the data and that's why they're so mad about it. Mozilla is AFAIK the first one to include support for it in a browser. Chrome doesn't support it yet but will do so soon.
- pbhjpbhj 7y agoAnd default logging all your lookups with a third-party, I gather.
- throw0101a 7y ago> So... for circumventing censorship, then? I don't know about ISPs, but as someone in IT, DoH could be a mess. If Firefox ignores resolve.conf how is split-horizon going to work? Wait until malware starts using it and it can't be blocked with blacklisting, e.g., entire CDN IP ranges. Paul Vixie has strong views on DoH: * https://twitter.com/paulvixie https://twitter.com/paulvixie I'd be okay if they at least used DNS-over-TLS (DoT): privacy and it can at least be handled by firewalls for us corporate types.
- tialaramex 7y agoPeople should cut it out with the split horizon DNS. Like NAT this was always a nasty hack, of course things will break if you do it. If you need malware to be nice and use your configured security systems or else it'll cause problems I have bad news for you: the malware authors aren't on your side. Everything DoH, eSNI, TLS 1.3 and QUIC and a dozen other protocols are doing was already trivial for malware to do if it wanted. If your defences begin by assuming bad guys are only doing things that obey all your rules you've fundamentally misunderstood what "bad guys" even are.
- throw0101a 7y ago> People should cut it out with the split horizon DNS. We have a bunch of internal-only 10.x hosts and services. Why would we put them in our external DNS? > If you need malware to be nice and use your configured security systems or else it'll cause problems I have bad news for you: the malware authors aren't on your side. I don't. But if I see DNS traffic flowing from systems that are not our internal DNS servers, I know to look at them. It's the same reason SMTP traffic was bottlenecked: everything goes through relays so it can be monitored. > If your defences begin by assuming bad guys are only doing things that obey all your rules you've fundamentally misunderstood what "bad guys" even are. Defences begin with observation. With DoH you can't tell what's going on with regards to queries. I'd much rather have DoT: still gives privacy, but since it has its own port, then it can be dealt with more easily. Of course having an IANA-assigned port allows for ISP/government filtering.
- dcow 7y agoI love Mozilla. I respect DoT/DoH. I support the adoption of private DNS for mature, independent, internet users. I personally value freedom of access to information over censorship. All these things should be protected by governments and the software we build. I do not, however, dismiss the UK’s argument that society needs a practical way to for parents to monitor and potentially filter what type of content their children are encountering online. I do not believe a child deserves the same privacy as a grown adult. It’s not even really arguable: it’s a parent’s responsibility to parent their children. The only practical way for a parent to do so if everything uses global/e2e DNS privacy is to give children “managed” devices with non-administrator accounts, or physically hovering over their shoulder all the time (yes children can earn more privacy as they build more trust and mature, but that’s for a parent to decide). It’s much easier and more effective to manage this at a network level. Furthermore, a consenting adult, without needing justification but common ones include: security, & ad-block, may choose to sacrifice a small amount of privacy (either because they don’t care or because they trust someone with the information) to enter into a relationship where they delegate filtering and monitoring to a third party. If someone wants to build a DNS resolver that doesn't resolve queries to companies run by assholes, then so be it. Browser mandated DNS privacy prevents all of this (unless you have administrative access to install and configure DNS resolvers on all the devices you own—but you don’t: thanks Apple and the cloud-based internet of shit). And even then if vendors pin keys or certs then have fun. Mozilla certainly isn’t the devil and doesn’t deserve this assessment, but the controversy surrounding fast-tracking proliferation of vendor-controlled DNS “privacy” is warranted. There’s a final point that often gets overlooked. If Mozilla or Google start shipping browsers that use their own DNS privacy resolvers, it’s a power play (whether intentional or not). They now control DNS, not you, not independent third parties. They now have more data about you. And they can start deploying nefarious things that only work in their vertically integrated web. I don’t think it’s that much of a stretch to say blindly and hastily pushing DNS privacy without standards in place to defend interoperability of software and internet systems and prevent even deeper vertical integration is bad for the internet. I am happy we have started exploring ways to extend privacy to the DNS. But I should be able to manage my network in my own home in whatever way I see fit. I do not wish to concede control of such a fundamental system so hastily to browser vendors, of all people.
- 7y ago
- DonHopkins 7y agoIt's like being on Nixon's or Trump's enemies list: a badge of honor! They should pass out top hats and stick-on curly waxed mustaches to all Mozilla employees, to celebrate. https://en.wikipedia.org/wiki/Villain https://en.wikipedia.org/wiki/Villain