6 ms·
> Firefox decided to stop using my DNS server In an ideal world, your probably want some sort of encrypted connection to your own DNS server (unless your LAN i
by s_tec 7y ago
> Firefox decided to stop using my DNS server
In an ideal world, your probably want some sort of encrypted connection to your own DNS server (unless your LAN is 100% trusted). Maybe something like HTTPS would work... oh wait.
Most people don't have their own DNS server, so their DNS traffic is already who-knows-what server with who-knows-what monetization in place (plus its in plaintext, so the rest of the internet gets it too).
DNS over HTTPS seems like a net win for both types of users. Power users like you get way to encrypt your DNS traffic, and non-technical users get an encrypted connection to a potentially less-hostile DNS server. It sucks that there is now a second place to configure things, but hopefully seeing this work well will put pressure on the OS to adopt DNS over HTTPS natively, bringing the experiment to its final goal (at least, I assume this is the endgame).
- throw0101a 7y agoAnd how the hell is split-horizon DNS supposed to work if resolve.conf is ignored? This may be "fine" for (some) home users, but most organizations have a whole bunch of internal-only records. And even a lot of residences have things like printers and such that live under .local: how is the browser supposed to connect to those? Who the fsck is Mozilla that they get to dictate policy in my IT organization about how DNS "should" work?
- s_tec 7y agoThis attitude always amazes me. You have obviously mastered a set of system administration skills over several years, and you are comfortable with a particular way of doing things. When somebody points out a weakness with the status quo and tries to offer something better, though, you react with hostility. Why do you think that is? I understand that their solution is not perfect (nothing ever starts out that way), but the amount of aggression in your comment suggests that something deeper is going on. Do you feel threatened? I suspect it's fear of change. As people realize that plain-text DNS is a gaping security hole, they are going to start demanding encryption. This means you, the administrator, will have to learn more skills and do more work to keep things running. Things like `.local:` printers may break, and you may have to upgrade your internal DNS servers to RFC8484 so you can keep your split-horizon stuff working. Security is never free. Or not. None of this is mandatory, and you can just switch it off (and Mozilla will automatically switch it off if they detect an environment like yours, as it says in TFA). The threat isn't Mozilla "deciding policy" for you (they aren't), the threat is that they are calling the industry out for running old & vulnerable DNS standards, and we all know deep inside that they are right.
- xg15 7y agoI think the underlying issue is absolutely a power struggle. Until recently, the general understanding was that each network operator was responsible for the clients inside their network - and therefore also had the ability to set the network's configuration. In 99.99% of the cases, this included access to nonlocal sites on other, public network's, aka "the web", but this was nowhere technically required. Browsers and other DNS-consuming apps were perfectly capable of working within other networks. What a DNS name resolved to was technically a property of the network. By now, this model is shifted towards the Web as a platform with browsers and DNS as clear parts of it - a platform that is incidentally pay-to-play and centrally controlled by the US because at the very least you need recurring payments for your domain and you need to give companies and institutions located in the US control over your machine. This shift has been going on for a long time, but I believe HTTPS-everywhere and DoH have served to make this unignorably obvious because those bring the concept of the web platform into the technology stack itself. To make the tired old car analogy again: In the vast majority of cases, you will drive your car on the public road network and nowhere else. However your car is technically capable of driving off-road or performing highly questionable maneuvers in your backyard because the car itself doesn't have any concept of "public roads", "private roads" or "non-roads". DoH would be adding a device that turns off the engine as soon as you're not on a public road. What exactly constitutes as a "public road" is determined by the car manufacturer. I do agree that in the long run it might be better for ensuring that "the web" is the same no matter from where you visit, but I think it's definitely more than a simple technical change. I also think all the heuristics, opt-outs and special rules for corporate network's don't cut it, because they relegate the current default case to an uncommon special case - and developers have a habit of ignoring uncommon special cases. I wouldn't be surprised if we see a lot of non-browser apps and devices in the future that use DoH by default and that an administrator would have to reconfigure by hand for each single installation - or that are simply hardwired to some set of DoH servers without any way to configure them at all.
- s_tec 7y agoWow, I had not considered the deeper power shifts from this perspective. The root the problem, I suppose, lies with public-key cryptography. We all know encryption is a good thing (unless you want to broadcast private information to the world), but encryption is useless unless you know who you are talking to. When someone comes to you in a ski mask and says, "It's me, your best friend", you probably want to see their face before you tell them any secrets - they could be anybody. Online, though, how do we know who anybody is? The current answer, for better or worse, is TLS with pay-to-play domain registration and certificate authorities. Decentralized, peer-to-peer systems like PGP have never been easy for consumers to use. You can "off-road" encrypted DNS by running your own DoH server & installing self-signed certificates on your client devices, but that's not an easy option. "My LAN is my castle" may work for some cases, but most of us conduct business with people all over the world, thanks to the internet. This is the primary use-case for most networks & computer systems. I'm afraid individuals will continue losing the power struggle as long as decentralized identity systems remain obscure. We need something that's as easy and compelling to use as our current centralized systems. It needs to be something consumers can use it to secure their every-day communications, as easy as visiting an HTTPS web site or chatting with a friend on Facebook. I just don't know how we get from here to there.
- lordlimecat 7y agoIt's amazing that you have such strong opinions about an article you didn't even bother to read. First, they detect split horizon situations and explain how. Second, if you as an admin want to force disable DoH across the network, they've provided a DNS-based way to do so. Third, if this really bothers you, Mozilla provides GPO templates (and JSON based methods for other OSes) to configure all of these settings at an application level. Maybe focus that outrage energy on reading the article before posting?
- throw0101a 7y agoMozilla may be kind enough to have those settings, but that doesn't mean other software will do the same thing. It's nice that Mozilla may allow setting other DNS servers for DoH, and perhaps will eventually use OS-level settings, but what happens when some dumb ass developer does not? Perhaps if they implemented DNS-over-TLS (DoT) instead/as well, then we could have encrypted DNS that is still monitorable. I'm waiting for the day when malware will start using DoH and use Cloudflare as the DNS server. As someone who works in IT, will I have to block CF to prevent that possibility? How many bots have been taken down over the years because their C&C domains were taken over?
- OBLIQUE_PILLAR 7y agoIt should be Opt-In. Not Opt-Out.
- yencabulator 7y agoThe silly assumption being made here is that "DoH" = "talk HTTPS to Cloudflare". I want DoH, but I need private domains. I would like to talk DoH to a thing I control.
- xg15 7y ago> Most people don't have their own DNS server, so their DNS traffic is already who-knows-what server with who-knows-what monetization in place (plus its in plaintext, so the rest of the internet gets it too). I know perfectly well who operates my DNS server: My ISP. If they are doing shady stuff, I can sue them, raise awareness or switch providers. I can't do the same with hardwired DoH endpoints.
- dagenix 7y agoIt's easier to switch ISPs than it is to just configure FireFox to use some other DoH provider?
- orev 7y agoSo now we need to worry about making custom DNS config for every single app on a computer?! It’s absurd.
- Spivak 7y agoI feel like that’s a slippery slope that will probably never happen. Most likely you’ll have to configure your browser(s) and that’s it.
- Faark 7y agoDoes your OS allow you to configure global DNS-over-HTTPS settings? Then you can hardly blame apps for not importing them. Yes, getting rid of shitty old standards means we have to live with multiple in parallel for a while and in the mean time bear additional complexity/work. Otherwise civilization will never advance.
- Jenda_ 7y agoMy OS (glibc, specifically) provides a way to resolve names (gethostbyname) using various means (hosts file, mDNS, DNS, directory service) configured by nsswitch.conf. Some distributions (e.g. Ubuntu) even move this to a separate daemon (systemd-resolved) which does stuff like DNSSEC validation and DNS-over-TLS (DNS-over-HTTPS is not (yet) supported natively, you need an extra program for this). I don't think moving common functionality from the OS into individual applications is "getting rid of shitty old standards", we will end up with multiple duplicated implementations.
- josteink 7y ago> unless your LAN is 100% trusted For 99% of the people out there, it is. Can Mozilla stop interfering with my network and get back to doing useful things with Firefox now?
- userbinator 7y agoNo kidding. Bypassing all the ad/malware domains in my HOSTS file, which practically all other applications on the system respect, feels disturbingly shady. Where's my privacy now!?!? If Mozilla wants to, they are more than welcome to work on encrypted DNS or VPNs or whatever else, but those should be at the OS level. Disrepecting configured OS settings borders on actively malicious behaviour.
- MauranKilom 7y agoHow exactly do you expect Mozilla to "work on encrypted DNS at the OS level"? How does Mozilla make Microsoft/Apple/Google implement it?
- userbinator 7y agoHow do you think people write VPN clients? Encrypted DNS is very much within that category of software. How does Mozilla make Microsoft/Apple/Google implement it? It doesn't need to, the same way it doesn't need to (nor should it) make Microsoft/Apple/Google ship Firefox as the default browser.
- bzbarsky 7y ago> For 99% of the people out there, it is. 99% of the people out there never connect to wifi in coffeeshops? I'm not even sure you hit the 99% mark if you measure by time spent connected, though I would love to see some data. (Disclaimer: I work for Mozilla, but have not really been involved with DoH.)