5 ms·
Even worse, corporate intranet addresses get leaked. Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or
by cremp 7y ago
Even worse, corporate intranet addresses get leaked.
Everyone on this article saying it's FUD is either a framework junky, isn't seeing the bigger picture, or just focus on one wrong thing in the article.
- jamespo 7y agoCorporations concerned about that should be blocking DoH anyway
- isostatic 7y agoAny device at home an go to http://nas http://nas and get on my nas, "http://desktop" http://desktop", "http://router" http://router", and "http://shed" http://shed" and get on those. How does that work in this bold new future? I'll have to register a domain name and add a bunch of A records for 192.168.0.1, but then it still won't work -- I'll have to do "http://desktop.mydomain.com" http://desktop.mydomain.com". Worse, while going to "shed" will work in chrome, it will fail in firefox. My guest network captive portal may well break too if someone visits with firefox.
- Gaelan 7y agoFirefox claims they will detect this situation and disable DoH.
- Tharkun 7y agoDetect it, how? By forwarding the request to a local resolver after DoH fails, and thus leaking information?
- ripdog 7y agoDo you... really care if someone outside you network knows the domain you chose for an internal network service? That's not sensitive information. Also, there's basically no way for cloudflare, even if they were being malicious about it, to collect and use that information. What would they do with it?
- userbinator 7y agoIt's definitely sensitive information --- useful for attackers to find out the structure of the LAN.
- Tharkun 7y agoYes, I care. Why don't you? I work for Tier 1 banks. They are paranoid, and rightly so. One of their many paranoid rules is that hostnames can never betray the machine's purpose. You could easily analyze DoH stats and deduce certain machines' functions. Leaking information is bad.
- roelschroeven 7y agoI don't know why you're downvoted, because that is a very good question. What you have to do is add an entry in your local nameserver for domain use-application-dns.net and set it to NXDOMAIN. See https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https https://support.mozilla.org/en-US/kb/configuring-networks-di.... Hopefully Google will use the same method for disabling DoH in Chrome. But I won't be surprised if they're going to force DoH even harder, and make it even more difficult to turn off.
- cremp 7y agoHow can you block it, if the browser itself is doing the communication, over https no-less? DoH was made to stop censorship, which includes blocking; if you could just block it, then whats the point of DoH?
- profmonocle 7y agoDoH uses regular DNS to get the IP address of the DoH server. So they could just block queries for the most popular DoH servers.
- telmich 7y agoHappy to see someone understands the real problem here!
- m-p-3 7y agoIt's actually FUD, because it's missing some important points > For starters, Mozilla said that after it turns on DoH by default for US users, Firefox will contain a mechanism to detect the presence of any local parental control software or enterprise configurations. > Additionally, Mozilla is also working with ISPs to make sure users won't use DoH as a way to bypass legally-set blocklists. > The organization said it's been asking ISPs and providers of network-based parental control solutions to add a "canary domain" to their blocklists. When Firefox will detect that this canary domain is blocked, it will disable DoH to prevent the feature to be used as a filter-bypassing solution. https://www.zdnet.com/article/mozilla-to-gradually-enable-dns-over-https-for-firefox-us-users-later-this-month/ https://www.zdnet.com/article/mozilla-to-gradually-enable-dn...
- Crinus 7y ago> When Firefox will detect that this canary domain is blocked, it will disable DoH to prevent the feature to be used as a filter-bypassing solution. ...then what is the point of having DoH in the first place? Anyone who wants to intercept your DNS traffic will use the canary domain and force Firefox to disable DoH.
- cremp 7y agoI hardly see how the OP is FUD. What the article states is true; just because you can opt-out doesn't mean it's wrong. Where you are drawing the line is the opt-out to disable it, as opposed to the convention of opt-in. Think about companies in the 50-200 employee range; As a sysadmin, I have to purposefully go out of my way to put that domain (use-application-dns.net)[1] in my root resolver, and point it to NXDOMAIN. I can't do it if another provider is managing my DNS (ISP, cloud service...); it also doesn't actually guarantee that it is off. > If a user has chosen to manually enable DoH, the signal from the network will be ignored and the user’s preference will be honored. The basic IT mantra has been 'If it aint broke, don't fix it.' Mozilla itself is moving fast and breaking things; which is why we have standards in the first place. For god sake, there isn't even a proper RFC to select yes or no to DoH. I, as a sysadmin, must not only implement the domain in my resolver, but I also must keep in my mind that if a user is using Firefox, that there are things it does internally that are not right, and it is easier for me to have my users on Chrome, because it is less of a headache for me. [1] https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https https://support.mozilla.org/en-US/kb/configuring-networks-di...