3 ms·
TBH mozilla is right about that though. There's better ways than using /etc/hosts. I run DNSCrypt and Unbound on my router: https://wiki.alpinelinux.org/wiki/L
by dngray 7y ago
TBH mozilla is right about that though.
There's better ways than using /etc/hosts. I run DNSCrypt and Unbound on my router: https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a_Raspberry_Pi#Unbound_DNS_forwarder_with_dnscrypt https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
then I simply point my DNS at my router IP. All DNS lookups are then done over DNSCrypt and over the VPN regardless of software, platform, or application. If I want to block a site I simply add it to filter.conf, ie https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a_Raspberry_Pi#Blocking_Microsoft_Telemetry_on_the_network_by_domain https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
local-zone: "example.com" redirect
local-data: "example.com A 0.0.0.1"
- Karunamon 7y agoI’m not clear on how this is “better”. I also run my own DNS server at home- sometimes I want to override resolution for a handful of addresses on a single client, and now (soon) I can’t do that anymore without some likely-convoluted workaround. It would be nice if Mozilla would stop breaking my shit and stop dishonoring my settings. This dread GNOME disease of knowing better than the user needs to stop.
- o-__-o 7y agoBecause DoH is meant to work on the application level, not OS level. You are trying to do something based on libc's resolver. If you use'd e.g. GoLang's resolver you would have similar behavior. This is "better" because it's following the spirit of domain separation. In fact, if Mozilla's application based resolver started mucking with /etc/hosts it would, in fact, be breaking your shit. Calm down.
- andrerm 7y agoHow can someone defending DoH talk about the spirit of domain separation? This is so absurdv IMHO
- Karunamon 7y ago>Because DoH is meant to work on the application level, not OS level. And thus, we arrive at the crux of the issue, as stated in my original post. It is not the job of everyday applications to be making decisions about name resolution. >In fact, if Mozilla's application based resolver started mucking with /etc/hosts Mozilla's application doesn't even need to know about /etc/hosts. It needs to ask the system name resolution interface to resolve a name for it, and then run with what it is given, rather than Mozilla deciding that their baby is too important to use that interface and then proceed to implement one on their own.
- chmod775 7y agoYou can have that. Don't turn DoH in FF on if you don't like it (or turn it off). You're acting like mozilla is deciding this for you without giving you a say. They're not. They're offering you something you don't even have to accept - because they care about your privacy online and they're not happy about little governments dabbling in the censorship game either. I'm pretty sure the TOR browser is using its own name resolution too - as a privacy feature. This isn't very different.
- Karunamon 7y agoGreat, another obnoxious Firefox feature I have to disable - and that's assuming they deign to allow me to do this once it hits mainstream. I'd like it if there were less of those.
- LinuxBender 7y agoAre we certain they will never change from opt-in to opt-out?
- cmroanirgo 7y ago> It needs to ask the system name resolution interface to resolve a name for it, and then run with what it is given Despite me agreeing with your need for hosts to work, your suggestion here wont. As the others have mentioned the hosts integration is down way down deep in the code (libc and kernell.dll as far as I know) and is basically an automated part of getting the address of a name, which does a proper DNS lookup automatically (if not found in hosts), meaning DoH wont get a chance. This means that FFox will need to independantly look up and parse the hosts file as part of it's DoH lookup, basically mimicking what libc is doing on 'nix boxes. It's what the other GPs are mentioning as a no-go/non-starter, whereas I suggest it's not hard to parse a text file.
- cmroanirgo 7y agoThere are more than one platform that are affected by this, as windows uses it's own hosts file too, so it's not just a libc thing. Every sysadmin and homebrew hacker knows of the hosts file that I'm aware of, regardless of the platform. FFox has no need to be 'mucking' (which I understand to mean to 'write to') with hosts: it needs to read it and parse it. Failure to do so will always generate an endless stream of "hosts file isn't being honoured" style bug reports. I think you would agree with me that the FFox maintainers & dev's have got better things to do than to answer WONTFIX on the same fault again and again.