4 ms·
I can think of something worse: sending all your DNS queries to an unregulated third party.
by ndidi 7y ago
I can think of something worse: sending all your DNS queries to an unregulated third party.
- lousken 7y agoaren't you still sending your data to unregulated third party with any ISP? (i dont live in the US so i am not aware if they're regulated in this regard)
- Grimm665 7y agoThis is already what happens. Your DNS queries have to go somewhere, and unless you control the DNS servers, there's a third party in the loop somewhere.
- apexalpha 7y agoNot really, my DNS requests go to my ISP's DNS server. And the ISP sees the requests anyway since they are the one forwarding all the packets. Now, Cloudfare will see them too. (if this would come to my country).
- SAI_Peregrinus 7y agoBut your ISP won't see them. They'll see that some requests are being made to Cloudflare, but not anything about the content.
- apexalpha 7y agoNo I mean in my current situation if my ISP is also my DNS provider they will get the requests. But they can already see what sites I visit because they are my ISP and carry my packets. In Mozilla's new default implementation Cloudflare will also see them, without me ever knowing (as an average user).
- codedokode 7y agoWith TLS1.3, encrypted SNI, encrypted DNS the ISP can only see the IP address you are connecting to, not a domain name. For Google's resources it only sees that you are connecting to Google's network, but is it Youtube or Gmail or Maps, they cannot tell (which is awesome by the way).
- avmich 7y agoWith Tor ISP can't even see the final address, but maybe Tor has its own solutions for DNS?
- yjftsjthsd-h 7y agoOnion sites use a keypair as their "name"
- ldng 7y agoAnd down the toilet goes the (distributing and caching) Inter-Net. Long live to the new Cloud-Net. Cloudfare and Google are achieving what Compuserve and AOL could not. Exaggerating slightly ... but not that much really. And all in the good name of privacy and security. It is also amazing how people (Americans ?) are not willing to admit I want MY jurisdiction to apply. Not an American one. I want the choice.
- yjftsjthsd-h 7y agoCaching died with insecure HTTP, and that's okay. > I want the choice. Then turn it off. But the default protects more people than it harms.
- ldng 7y agoWell, it's not really a choice if for security I must give up on jurisdiction ? I don't doubt the intentions of Mozilla. But, I expect Mozilla to set the bar much higher. > But the default protects more people than it harms. Sorry, not good enough for me. They should not be promoting a private company centralized solution. They really should be pushing for a decentralized and distributed solution that is yet secure for everyone involve and promote that.
- deleted 7y ago[deleted]
- codedokode 7y agoISP and government are that "unregulated third party".
- tannhaeuser 7y agoISPs are highly regulated, as opposed to Cloudflare and Google. The only effect here is that Google closes another "loophole" in their view where web visit signals are send to another party (other than Google), and Cloudflare wanting their share of the cake as well. Has Mozilla disclosed what Cloudflare is paying them for being listed as default DoH provider?
- pixl97 7y agoISP's are highly regulated when it comes to DNS? Not here in the US they are not.
- tannhaeuser 7y agoWell to buy a domain you need to go to an accredited registrar for the respective TLD. And DNS registrations, renewals, etc. are standardized (and have TLD-specific policies). Also, you're entitled to transfer your domain name to another registratr, etc., also with a public and transparent protocol. The registrar will then arrange for their nameserver being registered as authoritative for your domain on the TLD's root domain server, etc. What's the problem with US ISPs here? That they're selling DNS query records (with your IP) against their nameservers? That's in the same territory as Cloudflare and Google, and will only stop with proper privacy laws; certainly not by giving up on the decentralized nature of DNS and giving all traffic/signals to Cloudflare/Google.