12 ms·
No, the other viable option is not enabling DoH by default.
by ndidi 7y ago
No, the other viable option is not enabling DoH by default.
- m-p-3 7y agoprivacy-wise, plaintext is the worst option possible.
- ndidi 7y agoI can think of something worse: sending all your DNS queries to an unregulated third party.
- lousken 7y agoaren't you still sending your data to unregulated third party with any ISP? (i dont live in the US so i am not aware if they're regulated in this regard)
- Grimm665 7y agoThis is already what happens. Your DNS queries have to go somewhere, and unless you control the DNS servers, there's a third party in the loop somewhere.
- apexalpha 7y agoNot really, my DNS requests go to my ISP's DNS server. And the ISP sees the requests anyway since they are the one forwarding all the packets. Now, Cloudfare will see them too. (if this would come to my country).
- SAI_Peregrinus 7y agoBut your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.
- apexalpha 7y agoNo I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).
- codedokode 7y agoWith TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).
- avmich 7y agoWith Tor ISP can't even see the final address, but maybe Tor has its own solutions for DNS?
- yjftsjthsd-h 7y agoOnion sites use a keypair as their "name"
- ldng 7y agoAnd down the toilet goes the (distributing and caching) Inter-Net. Long live to the new Cloud-Net. Cloudfare and Google are achieving what Compuserve and AOL could not. Exaggerating slightly ... but not that much really. And all in the good name of privacy and security. It is also amazing how people (Americans ?) are not willing to admit I want MY jurisdiction to apply. Not an American one. I want the choice.
- yjftsjthsd-h 7y agoCaching died with insecure HTTP, and that's okay. > I want the choice. Then turn it off. But the default protects more people than it harms.
- codedokode 7y agoISP and government are that "unregulated third party".
- tannhaeuser 7y agoISPs are highly regulated, as opposed to Cloudflare and Google. The only effect here is that Google closes another "loophole" in their view where web visit signals are send to another party (other than Google), and Cloudflare wanting their share of the cake as well. Has Mozilla disclosed what Cloudflare is paying them for being listed as default DoH provider?
- pixl97 7y agoISP's are highly regulated when it comes to DNS? Not here in the US they are not.
- tannhaeuser 7y agoWell to buy a domain you need to go to an accredited registrar for the respective TLD. And DNS registrations, renewals, etc. are standardized (and have TLD-specific policies). Also, you're entitled to transfer your domain name to another registratr, etc., also with a public and transparent protocol. The registrar will then arrange for their nameserver being registered as authoritative for your domain on the TLD's root domain server, etc. What's the problem with US ISPs here? That they're selling DNS query records (with your IP) against their nameservers? That's in the same territory as Cloudflare and Google, and will only stop with proper privacy laws; certainly not by giving up on the decentralized nature of DNS and giving all traffic/signals to Cloudflare/Google.
- huhtenberg 7y agoPlaintext doesn't route every god damn request through Google or Cloudfare.
- m-p-3 7y agoIf you have a Chromecast, it's already sending the DNS requests to 8.8.8.8 unless you specifically block the IP.
- southerntofu 7y ago> If you have a Chromecast Why the hell would anyone buy hardware from an evil spyware company such as Google? Of course you can never trust a private corporation to do stuff in the public interest.
- Youden 7y agoI disagree, at least in my situation. My DNS requests traverse my ISP's network to my ISP's DNS server (or my employer's ISP's DNS server if I'm at work). I live in a country where I have very strong privacy protections and what my ISP can and can't do with my DNS requests is extremely limited. If my DNS requests are sent to CloudFlare or Google instead, my DNS requests are under American jurisdiction, where I have no rights and both American businesses and the American government can do whatever they please with no real recourse.
- o-__-o 7y agoCouldn’t your isp watch traffic to pull out SNI information?
- wp381640 7y agothe next step is eSNI and judging by the DoH rollout that will also be a new level of controversy advocating against it
- ithkuil 7y agoWhat are the arguments against eSNI?
- ti_ranger 7y ago> What are the arguments against eSNI? Institutions providing internet access, but with an obligation or operational requirement to block certain kinds of content (e.g. insufficient network capacity on the free WiFi at a hospital to allow streaming video for all visitors) would not be able to do it at all. Privacy proponents seem to forget that there are sometimes reasonable reasons to allow traffic to be blocked, and instead of looking for a real solution, are imposing ridiculous "solutions" on all Firefox users.
- codedokode 7y agoSo it depends on the country. In my country (Russia) all Internet traffic is being recorded by the ISP for the last month and sites are blocked on political reasons. For me having DoH with Cloudflare is better.
- wruza 7y agoI think you mistook it. I was talking about doh providers, not all options, and responded to a line completely tangential, if not unrelated to what you try to bring here. An answer looking for a question, I guess?
- tannhaeuser 7y agoAnd that should surely be the default. What's Mozilla's intent to send DNS queries to Cloudflare by default, and require regular DNS resolution to be configured manually?
- eps 7y agoYes, that's exactly their plan at the moment. Hence the whole brouhaha.