7 ms·
What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.
by cracker_jacks 7y ago
What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.
- tptacek 7y agoIt's not. It's an unalloyed good thing. The concern is with configurations that make it hard to use anything but Cloud Flare. There are alternatives.
- regecks 7y agoWhat do you think about Paul Vixie's views on DoH? On the face of it, it seems like we're going to end up with a bunch of black box devices (from Google, Amazon etc) in our homes that are totally immune to most forms of network policing because between DoH, ESNI, TLS and CDN fronting, you can't see anything.
- tptacek 7y agoPaul Vixie has been one of the Internet's most dedicated proponents of DNSSEC, a technology that essentially escrows keys with governments. If DNSSEC and DANE had progressed according to Vixie's preferred schedule, Muammar Gaddafi would have owned BIT.LY's CA. Vixie operates a company that relies on passive DNS observation to generate telemetry for corporations. Smart dude. Would not weight his privacy opinions heavily.
- tialaramex 7y agoDNSSEC doesn't "essentially escrow keys with governments". It's exactly as true to say that DANE gave Gaddafi ownership of bit.ly's CA as to say that today Boris Johnson owns the CA for slither.io - and as ridiculous. Back when you first started claiming this the Ten Blessed Methods weren't even a thing. You're complaining about the inadequate back door lock on a house that has the front door propped open. I work for an outfit that buys passive DNS data (among other things) and all our suppliers agree that DoH makes no difference to their roadmaps - because they don't care who asked, only what the query and answer are. Is Vixie doing something vastly different? Maybe so but you've offered no evidence what that could be.
- tptacek 7y agoYou haven't offered a rebuttal other than saying this argument is "ridiculous". I'm obviously not coming out of nowhere with it. Can you do better than "nuh-uh"?
- tialaramex 7y agoIf you don't agree that it's ridiculous to say Boris Johnson controls the CA for slither.io then... I guess we just have a very different definition of what it means to be ridiculous. I can live with that.
- tptacek 7y agoIf my iPhone honored my passphrase, but also a second secret passphrase held by Apple in iCloud that I had no control over, what would you call that scheme? I would say that Apple had an escrowed passphrase. Well, that's precisely how DNSSEC works. I control my own key, sure, and never have to reveal it, but that doesn't matter, because the roots can simply override that key with their own. You keep making these emotional appeals, but if I'm wrong, I don't see you actually rebutting me. "Your argument is so bad I will not deign to engage with it" is not a rebuttal.
- tialaramex 7y agoAt the risk of wasting my time with Humpty Dumpty: OK, so first up I guess the problem is you've no idea what "escrow" is and so you ended up confused as to what key escrow could be. So let's fix that first. Escrow is a service people or companies offer, the idea goes like this. Alice wants to do a deal with Bob, and Bob wants to make a deal with Alice, they're going to swap some of Alice's baseball cards for Bob's antique vase, but they don't trust each other. Fortunately they both trust Trent, a Third Party. Trent offers an Escrow service, both Alice and Bob agree with Trent that the baseball cards and the antique vase go to Trent, and then when he's got both things he'll send them to their new owners. If anything goes wrong, Trent gives back anything he received to the person who sent it and the deal is off. In the tech industry the most likely set up you'll see is that investors are worried all the stuff they're spending a lot of money on at a startup is not material that a bunch of burly guys can pick up and put in a truck if the firm fails - instead it's in Git repos or Google Drives and if it falls apart they know it has residual value that could be realised but they're not technical people, they're money people. So an escrow firm says fine, pay us a bunch of money and make the startup sign this data escrow agreement, and then if they fail you activate this clause and we give you a bunch of USB drives full of source code and whatever else. The escrow firm has IT people who can do stuff like send over keys for access to a GitHub, who know the difference between an S3 bucket and a SD card, which the investors don't want to have to learn about. In key escrow _your_ keys are held by a third party on your behalf. You can do end-to-end encryption if you want, but you're obliged to use this escrowed key. If the third party releases the key (e.g. because of a warrant, or an NSL, or because they're corrupt) then whoever gets it can now decrypt everything you've sent, or impersonate you seamlessly. If your iPhone honors a secret Apple passphrase that's a _backdoor_. If instead Apple insists on keeping a copy of your passphrase in a safe at Apple HQ that Tim Cook promises not to open _that_ would be escrow. Your objection that in DNSSEC "the roots can simply override that key with their own" also applies to any PKI, the whole _point_ of a PKI is that the trusted third party binds identity to keys, and if trust is misplaced they might falsely bind an identity to the wrong key. So the problem is - as I illustrated - that objections on the basis of DNSSEC being a PKI work just as well against the Web PKI. As a reason to prefer the Web PKI over DNSSEC they're ineffective.
- minusf 7y agomy impression from his latest talk at eurobsdcon this weekend was that he promotes dns over tls first and foremost. you can see for yourself when the videos go up.
- pingyong 7y agoIf the device is a black box, you don't even need key exchanges though? You can just send encrypted data with a pre-configured, unique, randomly generated (for the device) key to a hard-coded IP-address. And even if you don't want to use a hard-coded IP-address, there are about a million ways to have some sort of custom encrypted "address resolution" through IRC or whatever else. In fact you could also just send the data to some Tor node or even base64 encoded through IRC. And a million other ways. It's not like DoH is really going to make a difference here. I mean you can even just send pings with what seems like randomly generated payloads that actually contain encrypted data. Really not sure what DoH is supposed to change about that. All it does is make spying with zero effort very slightly more difficult to detect.
- tialaramex 7y agoIt's really common for "security" products to assume bad guys will meekly obey conventions like telling the truth. "Are you a bad guy?" "No". Ok then, test passed. Plenty of anti-TLS 1.3 stuff for example says that they "need" the plaintext Certificate message which in TLS 1.3 is now encrypted. But that message is literally just some public data - an X.509 certificate, if you're using it to "verify" anything your security is broken because a bad guy can send someone else's cert. They can't send a working CertificateVerify for it, but you don't know that because that message was never plaintext.
- 3xblah 7y agoWill there be any alternatives to those black box devices from Google, Amazon, etc.?
- mike_d 7y agoFrom a security and privacy standpoint I think DoH is a good thing. I wish it didn't have the overhead of TCP/HTTP (which is why I was a bigger fan of DNSCrypt). Anyone can stand up a resolver that can handle 50k UDP requests a second and operate a public resolver. It starts to get operationally dicey to stand up infrastructure that can do 50k HTTP requests a second. As a result you end up with a small handful of players who can operate medium to large scale public resolvers.
- tptacek 7y agoI don't buy it. At 50k requests per second, you're servicing a lot of users. Cost of customer acquisition dominates cost of serving the marginal 1000 HTTP requests. UDP doesn't make that business any more viable.
- mike_d 7y agoWhy does it need to be a business? A network of decentralized recursive resolvers operated by a number of different parties is preferable in almost every way to CloudFlare running a single endpoint. The NTP pool works quite well on this model. It would be a much larger commitment for participants had to manage stateful connections.
- bzbz 7y agoI don't think parent commenter is implying it has to be a commercial application. Imagine something released with little-to-no cost, with community-driven support and users that organically find the page. Not all services are commercial.
- denton-scratch 7y ago"Unalloyed" is a strong claim - you are saying effectively that it is pure, flawless gold.
- tptacek 7y agoI can't think of anything bad about it. One popular strain of criticism is clearly bogus, that it removes a measure of visibility from network operators (that's the point). Another is that it centralizes DNS services at companies like Cloud Flare, which, no, you can run your own DoH resolver server (and probably shouldn't use Cloud Flare regardless). Finally, people say that it's clunky compared to datagram-based alternatives; from my perspective, DNS has been hampered by the UDP service model for decades, and revisiting it so that, at least at the retail level, it's TCP/HTTPS like everything else is an opportunity, not a problem.
- axaxs 7y agoSerious question - why do you prefer DoH vs say, DNS over TLS? The former always seemed rather hacky to me.
- tptacek 7y agoI don't think there's anything wrong with DoT, but DoH is deliberately more difficult to block, which is a sensible design goal for a privacy and anti-censorship protocol. Both are better than directly using legacy plaintext DNS.
- juped 7y ago>you can run your own DoH resolver server How does this work in your mind?
- tptacek 7y agoI don't understand your question. The first Google SERP will give you a multiplicity of tutorials on setting up a DoH server.
- robertcope 7y agoIt makes it very hard to control your network. I have a DNS setup at home that I want all my equipment using. It blocks ads and other sites I don't want accessed. With DoH, I can't really be sure that browsers, devices, etc aren't using an alternative DNS system.
- pingyong 7y agoYou can't be sure anyway though? The only thing that router controls are standard DNS queries, probably sent through a standard port. If they're using anything different at all, the router won't catch it, even if it's not encrypted.
- LinuxBender 7y agoYou could null route or firewall all the open resolvers, or at least the most common ones. If your router is linux, that might look like /sbin/ip route add blackhole 9.9.9.9 2>/dev/null /sbin/ip route add blackhole 1.1.1.1 2>/dev/null /sbin/ip route add blackhole 1.0.0.1 2>/dev/null /sbin/ip route add blackhole 8.8.8.8 2>/dev/null /sbin/ip route add blackhole 8.8.4.4 2>/dev/null I'm probably leaving many of them off. There is probably a RBL for those by now. Here is one [1] and here is a list of them. [2] [1] - https://github.com/bambenek/block-doh https://github.com/bambenek/block-doh [2] - https://github.com/curl/curl/wiki/DNS-over-HTTPS https://github.com/curl/curl/wiki/DNS-over-HTTPS
- heavenlyblue 7y agoBut the plain DNS makes you absolutely unable to control your DNS queries outside your network. Nothing stops anyone in the middle intercepting your queries and returning whatever they want, including your provider.